A secure dynamic identity based authentication protocol for multi-server architecture

被引:182
|
作者
Sood, Sandeep K. [1 ]
Sarje, Anil K. [1 ]
Singh, Kuldip [1 ]
机构
[1] Indian Inst Technol, Dept Elect & Comp Engn, Roorkee, Uttar Pradesh, India
关键词
Authentication protocol; Smart card; Dynamic identity; Password; Multi-server architecture; PASSWORD AUTHENTICATION; SCHEME;
D O I
10.1016/j.jnca.2010.11.011
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Most of the password based authentication protocols rely on single authentication server for the user's authentication. User's verification information stored on the single server is a main point of susceptibility and remains an attractive target for the attacker. In 2009, Hsiang and Shih improved Liao and Wang's dynamic identity based smart card authentication protocol for multi-server environment. However, we found that Hsiang and Shih's protocol is susceptible to replay attack, impersonation attack and stolen smart card attack. Moreover, the password change phase of Hsiang and Shih's protocol is incorrect. This paper presents a secure dynamic identity based authentication protocol for multi-server architecture using smart cards that resolves the aforementioned security flaws, while keeping the merits of Hsiang and Shih's protocol. It uses two-server paradigm in which different levels of trust are assigned to the servers and the user's verifier information is distributed between these two servers known as the service provider server and the control server. The service provider server is more exposed to the clients than the control server. The back-end control server is not directly accessible to the clients and thus it is less likely to be attacked. The user's smart card uses stored information in it and random nonce value to generate dynamic identity. The proposed protocol is practical and computationally efficient because only nonce, one-way hash functions and XOR operations are used in its implementation. It provides a secure method to change the user's password without the server's help. In e-commerce, the number of servers providing the services to the user is usually more than one and hence secure authentication protocols for multi-server environment are required. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:609 / 618
页数:10
相关论文
共 50 条
  • [1] A Secure Dynamic Identity Based Authentication Protocol with Smart Cards for Multi-Server Architecture
    Li, Chun-Ta
    Lee, Cheng-Chi
    Weng, Chi-Yao
    Fan, Chun-I
    JOURNAL OF INFORMATION SCIENCE AND ENGINEERING, 2015, 31 (06) : 1975 - 1992
  • [2] Cryptanalysis of Two Dynamic Identity Based Authentication Schemes for Multi-Server Architecture
    Wan Tao
    Jiang Nan
    Ma Jianfeng
    CHINA COMMUNICATIONS, 2014, 11 (11) : 125 - 134
  • [3] An improved authentication protocol-based dynamic identity for multi-server environments
    Cui, Jianming
    Zhang, Xiaojun
    Cao, Ning
    Zhang, Dexue
    Ding, Jianrui
    Li, Guofu
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2018, 14 (05):
  • [4] An efficient and security dynamic identity based authentication protocol for multi-server architecture using smart cards
    Li, Xiong
    Xiong, Yongping
    Ma, Jian
    Wang, Wendong
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2012, 35 (02) : 763 - 769
  • [5] Lightweight identity authentication protocol based on dynamic ID in multi-server environment
    Qi X.
    Li M.
    Du Y.
    Beijing Hangkong Hangtian Daxue Xuebao/Journal of Beijing University of Aeronautics and Astronautics, 2021, 47 (12): : 2632 - 2640
  • [6] A lightweight dynamic pseudonym identity based authentication and key agreement protocol without verification tables for multi-server architecture
    Xue, Kaiping
    Hong, Peilin
    Ma, Changsha
    JOURNAL OF COMPUTER AND SYSTEM SCIENCES, 2014, 80 (01) : 195 - 206
  • [7] Analysis and improvement of an authentication protocol for the multi-server architecture
    Wan, T. (wantao217@163.com), 2013, Science Press (40):
  • [8] A Secure Authentication Scheme for Teleservices Using Multi-Server Architecture
    Kumar, Sachin
    Agarwal, Kadambri
    Gupta, Amit Kumar
    Kumari, Saru
    Sain, Mangal
    ELECTRONICS, 2022, 11 (18)
  • [9] A Secure and Efficient Dynamic Identity based Authentication Scheme for Multi-Server Environment using Smart Cards
    Xu, Chengbo
    Jia, Zhongtian
    Wen, Fengtong
    Ma, Yan
    INTERNATIONAL JOURNAL OF FUTURE GENERATION COMMUNICATION AND NETWORKING, 2013, 6 (03): : 25 - 39
  • [10] A secure and efficient dynamic identity based authentication scheme for multi-server environment using smart cards
    Institute of Network Technology Research, Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    不详
    Int. J. Future Gener. Commun. Networking, 2013, 3 (25-40):