A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards

被引:312
|
作者
Odelu, Vanga [1 ]
Das, Ashok Kumar [2 ]
Goswami, Adrijit [1 ]
机构
[1] IIT Kharagpur, Dept Math, Kharagpur 721302, W Bengal, India
[2] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
关键词
Security; authentication; smart card; revocation and re-registration; BAN logic; AVISPA; KEY AGREEMENT; PASSWORD AUTHENTICATION; SCHEME; IMPROVEMENT; PRIVACY; CRYPTANALYSIS; EFFICIENT; ROBUST;
D O I
10.1109/TIFS.2015.2439964
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang's scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user's anonymity. Furthermore, He-Wang's scheme cannot provide the user revocation facility when the smart card is lost/stolen or user's authentication parameter is revealed. Apart from these, He-Wang's scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang's scheme.
引用
收藏
页码:1953 / 1966
页数:14
相关论文
共 50 条
  • [31] An enhanced biometrics-based user authentication scheme for multi-server environments in critical systems
    Li, Xiong
    Wang, Kaihui
    Shen, Jian
    Kumari, Saru
    Wu, Fan
    Hu, Yonghua
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2016, 7 (03) : 427 - 443
  • [32] Cryptanalysis and improvement of a biometrics-based authentication and key agreement scheme for multi-server environments
    Yang, Li
    Zheng, Zhiming
    PLOS ONE, 2018, 13 (03):
  • [33] A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
    Kumari, Saru
    Das, Ashok Kumar
    Li, Xiong
    Wu, Fan
    Khan, Muhammad Khurram
    Jiang, Qi
    Islam, S. K. Hafizul
    MULTIMEDIA TOOLS AND APPLICATIONS, 2018, 77 (02) : 2359 - 2389
  • [34] Smart card-based secure authentication protocol in multi-server IoT environment
    Bae, Won-il
    Kwak, Jin
    MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (23-24) : 15793 - 15811
  • [35] Smart card-based secure authentication protocol in multi-server IoT environment
    Won-il Bae
    Jin Kwak
    Multimedia Tools and Applications, 2020, 79 : 15793 - 15811
  • [36] A provably secure biometrics-based authenticated key agreement scheme for multi-server environments
    Saru Kumari
    Ashok Kumar Das
    Xiong Li
    Fan Wu
    Muhammad Khurram Khan
    Qi Jiang
    S. K. Hafizul Islam
    Multimedia Tools and Applications, 2018, 77 : 2359 - 2389
  • [37] An efficient biometrics-based remote user authentication scheme using smart cards
    Li, Chun-Ta
    Hwang, Min-Shiang
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2010, 33 (01) : 1 - 5
  • [38] User authentication scheme using smart cards for multi-server environments
    Fan, L
    Xu, CX
    Li, JH
    CHINESE JOURNAL OF ELECTRONICS, 2004, 13 (01): : 179 - 181
  • [39] An Enhanced Biometrics-based Remote User Authentication Scheme Using Smart Cards
    Lu, Jian-Zhu
    Chen, Ting
    Zhou, Jipeng
    Yang, Jinjin
    Jiang, Junhui
    2013 6TH INTERNATIONAL CONGRESS ON IMAGE AND SIGNAL PROCESSING (CISP), VOLS 1-3, 2013, : 1643 - 1648
  • [40] Design of a provably secure biometrics-based multi-cloud-server authentication scheme
    Kumari, Saru
    Li, Xiong
    Wu, Fan
    Das, Ashok Kumar
    Choo, Kim-Kwang Raymond
    Shen, Jian
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2017, 68 : 320 - 330