A secure dynamic identity based authentication protocol for multi-server architecture

被引:182
|
作者
Sood, Sandeep K. [1 ]
Sarje, Anil K. [1 ]
Singh, Kuldip [1 ]
机构
[1] Indian Inst Technol, Dept Elect & Comp Engn, Roorkee, Uttar Pradesh, India
关键词
Authentication protocol; Smart card; Dynamic identity; Password; Multi-server architecture; PASSWORD AUTHENTICATION; SCHEME;
D O I
10.1016/j.jnca.2010.11.011
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Most of the password based authentication protocols rely on single authentication server for the user's authentication. User's verification information stored on the single server is a main point of susceptibility and remains an attractive target for the attacker. In 2009, Hsiang and Shih improved Liao and Wang's dynamic identity based smart card authentication protocol for multi-server environment. However, we found that Hsiang and Shih's protocol is susceptible to replay attack, impersonation attack and stolen smart card attack. Moreover, the password change phase of Hsiang and Shih's protocol is incorrect. This paper presents a secure dynamic identity based authentication protocol for multi-server architecture using smart cards that resolves the aforementioned security flaws, while keeping the merits of Hsiang and Shih's protocol. It uses two-server paradigm in which different levels of trust are assigned to the servers and the user's verifier information is distributed between these two servers known as the service provider server and the control server. The service provider server is more exposed to the clients than the control server. The back-end control server is not directly accessible to the clients and thus it is less likely to be attacked. The user's smart card uses stored information in it and random nonce value to generate dynamic identity. The proposed protocol is practical and computationally efficient because only nonce, one-way hash functions and XOR operations are used in its implementation. It provides a secure method to change the user's password without the server's help. In e-commerce, the number of servers providing the services to the user is usually more than one and hence secure authentication protocols for multi-server environment are required. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:609 / 618
页数:10
相关论文
共 50 条
  • [21] A secure and efficient authentication protocol for wireless applications in multi-server environment
    Pankaj Kumar
    Hari Om
    Peer-to-Peer Networking and Applications, 2022, 15 : 1939 - 1952
  • [22] Improved multi-server authentication protocol
    Huang, Chun-Hui
    Chou, Jue-Sam
    Chen, Yalin
    Wun, Siang Yu
    SECURITY AND COMMUNICATION NETWORKS, 2012, 5 (03) : 331 - 341
  • [23] Smart card-based secure authentication protocol in multi-server IoT environment
    Won-il Bae
    Jin Kwak
    Multimedia Tools and Applications, 2020, 79 : 15793 - 15811
  • [24] Anonymous and Authentication Protocol for Multi-Server
    Kuo, Wen-Chung
    Shih, Po-Wei
    Huang, Yu-Chih
    Wuu, Lih-Chyau
    INFORMATION TECHNOLOGY AND CONTROL, 2017, 46 (02): : 235 - 245
  • [25] A Robust Authentication Protocol for Multi-Server Architecture without Smart Cards
    Hsiang, Han-Cheng
    PROCEEDINGS OF THE 2013 INTERNATIONAL CONFERENCE ON INFORMATION, BUSINESS AND EDUCATION TECHNOLOGY (ICIBET 2013), 2013, 26 : 132 - 135
  • [26] A new dynamic identity-based authentication protocol for multi-server environment using elliptic curve cryptography
    Khan, Muhammad Khurram
    He, Debiao
    SECURITY AND COMMUNICATION NETWORKS, 2012, 5 (11) : 1260 - 1266
  • [27] A secure dynamic ID based remote user authentication scheme for multi-server environment
    Liao, Yi-Pin
    Wang, Shuenn-Shyang
    COMPUTER STANDARDS & INTERFACES, 2009, 31 (01) : 24 - 29
  • [28] A novel authentication protocol for multi-server architecture without smart cards
    Lee, Jung-San
    Chang, Ya-Fen
    Chang, Chin-Chen
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2008, 4 (06): : 1357 - 1364
  • [29] Cryptanalysis of Dynamic Identity Based on a Remote User Authentication Scheme for a Multi-server Environment
    Ling, Chung-Huei
    Chao, Wan-Yu
    Chen, Shih-Ming
    Hwang, Min-Shiang
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON ADVANCES IN MECHANICAL ENGINEERING AND INDUSTRIAL INFORMATICS, 2015, 15 : 981 - 986
  • [30] A Threshold Multi-Server Protocol for Password-Based Authentication
    Guan, Mengxiang
    Song, Jiaxing
    Liu, Weidong
    2016 IEEE 3RD INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (CSCLOUD), 2016, : 108 - 118