Design of a user anonymous password authentication scheme without smart card

被引:28
|
作者
Kumari, Saru [1 ]
Khan, Muhammad Khurram [2 ]
Li, Xiong [3 ]
Wu, Fan [4 ]
机构
[1] Dr BRA Univ, Agra Coll, Dept Math, Agra 282002, Uttar Pradesh, India
[2] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
[3] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China
[4] Huaqiao Univ, Xiamen Inst Technol, Dept Comp Sci & Engn, Xiamen 361021, Peoples R China
基金
中国国家自然科学基金;
关键词
authentication; user anonymity; common storage device; forward secrecy; ineffective login; IMPROVEMENT; SECURITY; CRYPTANALYSIS; NONCE;
D O I
10.1002/dac.2853
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Recently, Jiang et al. and He et al. independently found security problems in Chen et al.'s remote user authentication scheme for non-tamper-proof storage devices like Universal Serial Bus stick and proposed improvements. Nonetheless, we detect that the schemes proposed by Jiang et al. and He et al. overlook a user's privacy. We also observe that Jiang et al.'s scheme is vulnerable to insider attack and denial of service attacks and lacks forward secrecy. We point out that the password changing facility in He et al.' s scheme is equivalent to undergoing registration, whereas in Jiang et al.' s scheme, it is unsuitable. Moreover, the login phase of both the schemes is incapable to prevent the use of wrong password leading to the computation of an unworkable login request. Therefore, we design a new scheme with user anonymity to surmount the identified weaknesses. Without adding much in communication/computational cost, our scheme provides more security characteristics and keeps the merits of the original schemes. As compared with its predecessor schemes, the proposed scheme stands out as a more apt user authentication method for common storage devices. We have also presented a formal proof of security of the proposed scheme based on the logic proposed by Burrows, Abadi and Needham (BAN logic). Copyright (c) 2014 John Wiley & Sons, Ltd.
引用
收藏
页码:441 / 458
页数:18
相关论文
共 50 条
  • [1] Cryptanalysis of a User Anonymous Password Authentication Scheme Without Smart Card
    Lin, Hao
    Wen, Feng-Tong
    Du, Chun-Xia
    [J]. 2016 INTERNATIONAL CONFERENCE ON SERVICE SCIENCE, TECHNOLOGY AND ENGINEERING (SSTE 2016), 2016, : 293 - 298
  • [2] Notes on "A Password-Based Remote User Authentication Scheme without Smart Card"
    Kumari, Saru
    Li, Xiong
    Khan, Muhammad Khurram
    Kumar, Rahul
    [J]. 2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 116 - 119
  • [3] An enhanced smart card based remote user password authentication scheme
    Li, Xiong
    Niu, Jianwei
    Khan, Muhammad Khurram
    Liao, Junguo
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2013, 36 (05) : 1365 - 1371
  • [4] SECURE SMART CARD BASED PASSWORD AUTHENTICATION SCHEME WITH USER ANONYMITY
    Li, Chun-Ta
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2011, 40 (02): : 157 - 162
  • [5] Improvements of a Remote User Password Authentication Scheme using Smart Card
    Shin, Kwang Cheul
    Huh, Won Whoi
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (04): : 119 - 126
  • [6] An Improved Password Authentication Scheme for Smart Card
    Tsai, Cheng-Yi
    Pan, Chiu-Shu
    Hwang, Min-Shiang
    [J]. RECENT DEVELOPMENTS IN INTELLIGENT SYSTEMS AND INTERACTIVE APPLICATIONS (IISA2016), 2017, 541 : 194 - 199
  • [7] Robust smart-card-based remote user password authentication scheme
    Chen, Bae-Ling
    Kuo, Wen-Chung
    Wuu, Lih-Chyau
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (02) : 377 - 389
  • [8] Cryptanalysis of a Sensor Smart Card Based Password Authentication Scheme with User Anonymity
    Cao, Tianjie
    Huang, Shi
    [J]. SENSOR LETTERS, 2013, 11 (11) : 2149 - 2151
  • [9] Robust password and smart card based authentication scheme with smart card revocation
    Xie Q.
    Liu W.-H.
    Wang S.-B.
    Hu B.
    Dong N.
    Yu X.-Y.
    [J]. Journal of Shanghai Jiaotong University (Science), 2014, 19 (4) : 418 - 424
  • [10] AN IMPROVED REMOTE PASSWORD AUTHENTICATION SCHEME WITH SMART CARD
    Jing Chao
    [J]. Journal of Electronics(China), 2012, 29 (06) : 550 - 555