A secure dynamic identity based authentication protocol for multi-server architecture

被引:182
|
作者
Sood, Sandeep K. [1 ]
Sarje, Anil K. [1 ]
Singh, Kuldip [1 ]
机构
[1] Indian Inst Technol, Dept Elect & Comp Engn, Roorkee, Uttar Pradesh, India
关键词
Authentication protocol; Smart card; Dynamic identity; Password; Multi-server architecture; PASSWORD AUTHENTICATION; SCHEME;
D O I
10.1016/j.jnca.2010.11.011
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Most of the password based authentication protocols rely on single authentication server for the user's authentication. User's verification information stored on the single server is a main point of susceptibility and remains an attractive target for the attacker. In 2009, Hsiang and Shih improved Liao and Wang's dynamic identity based smart card authentication protocol for multi-server environment. However, we found that Hsiang and Shih's protocol is susceptible to replay attack, impersonation attack and stolen smart card attack. Moreover, the password change phase of Hsiang and Shih's protocol is incorrect. This paper presents a secure dynamic identity based authentication protocol for multi-server architecture using smart cards that resolves the aforementioned security flaws, while keeping the merits of Hsiang and Shih's protocol. It uses two-server paradigm in which different levels of trust are assigned to the servers and the user's verifier information is distributed between these two servers known as the service provider server and the control server. The service provider server is more exposed to the clients than the control server. The back-end control server is not directly accessible to the clients and thus it is less likely to be attacked. The user's smart card uses stored information in it and random nonce value to generate dynamic identity. The proposed protocol is practical and computationally efficient because only nonce, one-way hash functions and XOR operations are used in its implementation. It provides a secure method to change the user's password without the server's help. In e-commerce, the number of servers providing the services to the user is usually more than one and hence secure authentication protocols for multi-server environment are required. (C) 2010 Elsevier Ltd. All rights reserved.
引用
收藏
页码:609 / 618
页数:10
相关论文
共 50 条
  • [31] On the security of an authentication scheme for multi-server architecture
    He, D. (hedebiao@163.com), 1600, Inderscience Publishers, 29, route de Pre-Bois, Case Postale 856, CH-1215 Geneva 15, CH-1215, Switzerland (05): : 3 - 4
  • [32] A Novel Multi-server Environment Authentication Protocol
    Li Haixia
    Lu Chuiwei
    Sun Sheng
    PROCESSING OF 2014 INTERNATIONAL CONFERENCE ON MULTISENSOR FUSION AND INFORMATION INTEGRATION FOR INTELLIGENT SYSTEMS (MFI), 2014,
  • [33] SSO password-based multi-server authentication protocol
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2012, 9 (1-2) : 161 - 180
  • [34] On the security of an authentication scheme for multi-server architecture
    He, Debiao
    Chen, Jianhua
    Shi, Wenbo
    Khan, Muhammad Khurram
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2013, 5 (3-4) : 288 - 296
  • [35] Robust Secure Dynamic ID Based Remote User Authentication Scheme for Multi-server Environment
    Toan-Thinh Truong
    Minh-Triet Tran
    Anh-Duc Duong
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2013, PT V, 2013, 7975 : 502 - 515
  • [36] Robust secure dynamic ID based remote user authentication scheme for multi-server environment
    Truong, Toan-Thinh
    Tran, Minh-Triet
    Duong, Anh-Duc
    Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), 2013, 7971 : 502 - 515
  • [37] A more secure dynamic id based remote user authentication scheme for multi-server environment
    Guo, Dianli
    Wen, Fengtong
    Journal of Computational Information Systems, 2013, 9 (02): : 407 - 414
  • [38] An Anonymous Authentication with Key-Agreement Protocol for Multi-Server Architecture Based on Biometrics and Smartcards
    Reddy, Alavalapati Goutham
    Das, Ashok Kumar
    Yoon, Eun-Jun
    Yoo, Kee-Young
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2016, 10 (07): : 3371 - 3396
  • [39] An Improved Secure Dynamic ID Based Remote User Authentication Scheme for Multi-Server Environment
    Lee, Cheng-Chi
    Lai, Yan-Ming
    Li, Chun-Ta
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2012, 6 (02): : 203 - 210
  • [40] Improvement of the secure dynamic ID based remote user authentication scheme for multi-server environment
    Hsiang, Han-Cheng
    Shih, Wei-Kuan
    COMPUTER STANDARDS & INTERFACES, 2009, 31 (06) : 1118 - 1123