Improved multi-server authentication protocol

被引:5
|
作者
Huang, Chun-Hui [1 ]
Chou, Jue-Sam [1 ]
Chen, Yalin [2 ]
Wun, Siang Yu [1 ]
机构
[1] Nanhua Univ, Dept Informat Management, Chiayi 622, Taiwan
[2] Natl Tsing Hua Univ, Inst Informat Syst & Applicat, Hsinchu, Taiwan
关键词
multi-server; password authentication protocol; smart card; impersonation attack; server-spoofing attack; SCHEME;
D O I
10.1002/sec.332
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In a multi-server environment, a user only needs to register at the registration center once instead of repeatedly registering in each server. After registration, the user can access the resources of any of the servers in the system. Many protocols have been proposed for the same. Recently, GengZhang, Zhu et al., and YoonYoo each proposed a multi-server authentication scheme. They claimed that their schemes are secure and can withstand various attacks. However, after analyses, we found that their schemes are deficient. In this paper, we first demonstrate the deficiencies of these three protocols in turn and then show our improvement on GengZhang's protocol. Our improvement makes use of both the user's and the server's secrecy to achieve mutual authentication. This results in a two-pass multi-server authentication scheme. We have analyzed its security with respect to several factors such as mutual authentication, perfect forward and backward secrecy, and prevention of smart-card-lost attack. Moreover, almost all of the parameters required for a user to log on to a server can be pre-computed. This is very important for a low-energy mobile computing device. That is, our improvement is not only one of the most efficient and secure schemes in this area but also suitable for mobile device. Copyright (C) 2011 John Wiley & Sons, Ltd.
引用
收藏
页码:331 / 341
页数:11
相关论文
共 50 条
  • [1] Anonymous and Authentication Protocol for Multi-Server
    Kuo, Wen-Chung
    Shih, Po-Wei
    Huang, Yu-Chih
    Wuu, Lih-Chyau
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2017, 46 (02): : 235 - 245
  • [2] A Novel Multi-server Environment Authentication Protocol
    Li Haixia
    Lu Chuiwei
    Sun Sheng
    [J]. PROCESSING OF 2014 INTERNATIONAL CONFERENCE ON MULTISENSOR FUSION AND INFORMATION INTEGRATION FOR INTELLIGENT SYSTEMS (MFI), 2014,
  • [3] An improved authentication protocol-based dynamic identity for multi-server environments
    Cui, Jianming
    Zhang, Xiaojun
    Cao, Ning
    Zhang, Dexue
    Ding, Jianrui
    Li, Guofu
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2018, 14 (05):
  • [4] A Threshold Multi-Server Protocol for Password-Based Authentication
    Guan, Mengxiang
    Song, Jiaxing
    Liu, Weidong
    [J]. 2016 IEEE 3RD INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (CSCLOUD), 2016, : 108 - 118
  • [5] SSO password-based multi-server authentication protocol
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2012, 9 (1-2) : 161 - 180
  • [6] A multi-server architecture authentication protocol using smart card
    Yu, Jie
    Pei, Qingqi
    [J]. PROCEEDINGS OF THE 2012 EIGHTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS 2012), 2012, : 511 - 515
  • [7] Novel Multi-Server Authentication Protocol using Secret Sharing
    Nimmy, K.
    [J]. PROCEEDINGS OF 2016 INTERNATIONAL CONFERENCE ON DATA MINING AND ADVANCED COMPUTING (SAPIENCE), 2016, : 214 - 219
  • [8] An Improved Biometric Multi-Server Authentication Scheme for Chang et al.'s Protocol
    Irshad, Azeem
    Chaudhry, Shehzad Ashraf
    Shafiq, Muhammad
    Usman, Muhammad
    Asif, Muhammad
    Ali, Sajid
    Kumari, Saru
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2019, 48 (02): : 211 - 224
  • [9] A Robust Authentication Protocol for Multi-Server Architecture without Smart Cards
    Hsiang, Han-Cheng
    [J]. PROCEEDINGS OF THE 2013 INTERNATIONAL CONFERENCE ON INFORMATION, BUSINESS AND EDUCATION TECHNOLOGY (ICIBET 2013), 2013, 26 : 132 - 135
  • [10] Efficient hierarchical multi-server authentication protocol for mobile cloud computing
    Kou, Jiangheng
    He, Mingxing
    Xiong, Ling
    Ge, Zihang
    Xie, Guangmin
    [J]. Computers, Materials and Continua, 2020, 64 (01): : 297 - 312