PASSWORD-BASED AUTHENTICATED KEY EXCHANGE PROTOCOL WITHOUT TRUSTED THIRD PARTY FOR MULTI-SERVER ENVIRONMENTS

被引:0
|
作者
Hsu, Chien-Lung [1 ,3 ]
Wu, Tzong-Sun [2 ]
Lin, Han-Yu [2 ]
机构
[1] Chang Gung Univ, Dept Informat Management, Tao Yuan 333, Taiwan
[2] Natl Taiwan Ocean Univ, Dept Comp Sci & Engn, Keelung 20224, Taiwan
[3] NTUST, Taiwan Informat Secur Ctr, Taipei 106, Taiwan
关键词
Authentication; Key exchange; Password; Multi-server; Smart card;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the rapid development of Internet, lots of transactions are conducted on-line without interactions face to face. A critical issue is to keep these transactions secure and confidential. Since the Internet is a virtual and insecure world, it is rather important to authenticate each other for providing a secure environment. A password-based authenticated key exchange protocol not only allows a user to login remote servers with an easily rememberable password, but also achieves mutual authentication as well. A shared session key is then established for subsequent communication. However, if such protocols are applied in multi-server environments, the system is often vulnerable to password guessing attacks and impersonation attacks. Besides, each user has to remember multiple passwords due to the security concern. In this paper, we propose an efficient password-based authenticated key exchange protocol with smart cards for multi-server environments. The proposed protocol enables a user to utilize a single password for registration and requesting services of different remote servers. Each server is also unnecessary to maintain a verification table. Moreover, our protocol can dynamically add or remove servers without the assistance of registration center. Compared with previous works, ours not only has better efficiency, but also provides more capabilities.
引用
收藏
页码:1541 / 1555
页数:15
相关论文
共 50 条