A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards

被引:309
|
作者
Odelu, Vanga [1 ]
Das, Ashok Kumar [2 ]
Goswami, Adrijit [1 ]
机构
[1] IIT Kharagpur, Dept Math, Kharagpur 721302, W Bengal, India
[2] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
关键词
Security; authentication; smart card; revocation and re-registration; BAN logic; AVISPA; KEY AGREEMENT; PASSWORD AUTHENTICATION; SCHEME; IMPROVEMENT; PRIVACY; CRYPTANALYSIS; EFFICIENT; ROBUST;
D O I
10.1109/TIFS.2015.2439964
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang's scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user's anonymity. Furthermore, He-Wang's scheme cannot provide the user revocation facility when the smart card is lost/stolen or user's authentication parameter is revealed. Apart from these, He-Wang's scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang's scheme.
引用
收藏
页码:1953 / 1966
页数:14
相关论文
共 50 条
  • [1] A secure biometrics-based authentication key exchange protocol for multi-server TMIS using ECC
    Qi, Mingping
    Chen, Jianhua
    Chen, Yitao
    [J]. COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2018, 164 : 101 - 109
  • [2] Cryptanalysis and Improvement of an Advanced Anonymous and Biometrics-Based Multi-server Authentication Scheme Using Smart Cards
    Quan, Chunyi
    Lee, Hakjun
    Kang, Dongwoo
    Kim, Jiye
    Cho, Seokhyang
    Won, Dongho
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 62 - 71
  • [3] Cryptanalysis and Improvement of a Biometrics-based Multi-server Authentication Protocol
    Gu, Yi
    Li, Shengqiang
    [J]. 2018 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2018, : 16 - 20
  • [4] An Improvement of Robust Biometrics-Based Authentication and Key Agreement Scheme for Multi-Server Environments Using Smart Cards
    Moon, Jongho
    Choi, Younsung
    Jung, Jaewook
    Won, Dongho
    [J]. PLOS ONE, 2015, 10 (12):
  • [5] Security Improvement on a Biometrics-Based Authentication Protocol for Multi-server Environment
    Gu, Yi
    Li, Shengqiang
    [J]. 2017 17TH IEEE INTERNATIONAL CONFERENCE ON COMMUNICATION TECHNOLOGY (ICCT 2017), 2017, : 1322 - 1327
  • [6] An Enhanced Secure Anonymous Authentication Scheme Based on Smart Cards and Biometrics for Multi-Server Environments
    Kuo, Wen-Chung
    Wei, Hong-Ji
    Chen, Yu-Hui
    Cheng, Jiin-Chiou
    [J]. 2015 10TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS), 2015, : 1 - 5
  • [7] A Secure Dynamic Identity Based Authentication Protocol with Smart Cards for Multi-Server Architecture
    Li, Chun-Ta
    Lee, Cheng-Chi
    Weng, Chi-Yao
    Fan, Chun-I
    [J]. JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2015, 31 (06) : 1975 - 1992
  • [8] Robust biometrics-based multi-server authentication with key agreement scheme for smart cards on elliptic curve cryptosystem
    Yoon, Eun-Jun
    Yoo, Kee-Young
    [J]. JOURNAL OF SUPERCOMPUTING, 2013, 63 (01): : 235 - 255
  • [9] An Enhanced Smart Card and Biometrics-Based Authentication Scheme in Multi-server Environment
    Xiao Haiyan
    Wang Lifang
    [J]. COMPLEX, INTELLIGENT, AND SOFTWARE INTENSIVE SYSTEMS, 2019, 772 : 770 - 779
  • [10] Robust biometrics-based multi-server authentication with key agreement scheme for smart cards on elliptic curve cryptosystem
    Eun-Jun Yoon
    Kee-Young Yoo
    [J]. The Journal of Supercomputing, 2013, 63 : 235 - 255