A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards

被引:312
|
作者
Odelu, Vanga [1 ]
Das, Ashok Kumar [2 ]
Goswami, Adrijit [1 ]
机构
[1] IIT Kharagpur, Dept Math, Kharagpur 721302, W Bengal, India
[2] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
关键词
Security; authentication; smart card; revocation and re-registration; BAN logic; AVISPA; KEY AGREEMENT; PASSWORD AUTHENTICATION; SCHEME; IMPROVEMENT; PRIVACY; CRYPTANALYSIS; EFFICIENT; ROBUST;
D O I
10.1109/TIFS.2015.2439964
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang's scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user's anonymity. Furthermore, He-Wang's scheme cannot provide the user revocation facility when the smart card is lost/stolen or user's authentication parameter is revealed. Apart from these, He-Wang's scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang's scheme.
引用
下载
收藏
页码:1953 / 1966
页数:14
相关论文
共 50 条
  • [21] A Secure and Efficient Dynamic Identity based Authentication Scheme for Multi-Server Environment using Smart Cards
    Xu, Chengbo
    Jia, Zhongtian
    Wen, Fengtong
    Ma, Yan
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2013, 6 (03): : 25 - 39
  • [22] New biometrics-based authentication scheme for multi-server environment in critical systems
    Shen, Han
    Gao, Chongzhi
    He, Debiao
    Wu, Libing
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2015, 6 (06) : 825 - 834
  • [23] Anonymous biometrics-based authentication with key agreement scheme for multi-server environment using ECC
    Qi, Mingping
    Chen, Jianhua
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (19) : 27553 - 27568
  • [24] A secure and efficient dynamic identity based authentication scheme for multi-server environment using smart cards
    Institute of Network Technology Research, Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    不详
    Int. J. Future Gener. Commun. Networking, 2013, 3 (25-40):
  • [25] Anonymous biometrics-based authentication with key agreement scheme for multi-server environment using ECC
    Mingping Qi
    Jianhua Chen
    Multimedia Tools and Applications, 2019, 78 : 27553 - 27568
  • [26] A Biometrics-Based Remote User Authentication Scheme Using Smart Cards
    Cui, Jianming
    Sui, Rongquan
    Zhang, Xiaojun
    Li, Hengzhong
    Cao, Ning
    CLOUD COMPUTING AND SECURITY, PT IV, 2018, 11066 : 531 - 542
  • [27] An efficient and security dynamic identity based authentication protocol for multi-server architecture using smart cards
    Li, Xiong
    Xiong, Yongping
    Ma, Jian
    Wang, Wendong
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2012, 35 (02) : 763 - 769
  • [28] An enhanced biometrics-based user authentication scheme for multi-server environments in critical systems
    Xiong Li
    Kaihui Wang
    Jian Shen
    Saru Kumari
    Fan Wu
    Yonghua Hu
    Journal of Ambient Intelligence and Humanized Computing, 2016, 7 : 427 - 443
  • [29] A secure dynamic ID based remote user authentication scheme for multi-server environment using smart cards
    Lee, Cheng-Chi
    Lin, Tsung-Hung
    Chang, Rui-Xiang
    EXPERT SYSTEMS WITH APPLICATIONS, 2011, 38 (11) : 13863 - 13870
  • [30] Anonymous biometrics-based authentication scheme with key distribution for mobile multi-server environment
    Feng, Qi
    He, Debiao
    Zeadally, Sherali
    Wang, Huaqun
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 84 : 239 - 251