A more secure digital rights management authentication scheme based on smart card

被引:10
|
作者
Kumari, Saru [1 ]
Khan, Muhammad Khurram [2 ]
Li, Xiong [3 ]
机构
[1] Dr BRA Univ, Agra Coll, Dept Math, Agra, Uttar Pradesh, India
[2] King Saud Univ, POB 92144, Riyadh 11653, Saudi Arabia
[3] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China
基金
中国国家自然科学基金;
关键词
Digital rights management; Authentication; Cryptanalysis; Forward secrecy; Secure password changing facility; DRM;
D O I
10.1007/s11042-014-2361-z
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital rights management (DRM) system is a technology based mechanism to ensure only authorized access and legal distribution/consumption of the protected digital content. DRM system deals with the whole lifecycle of the digital content including production, management, distribution and consumption. DRM schemes are effective means for the transfer of digital content and safeguard the intellectual property. Recently, Yang et al. proposed a smart-card based DRM authentication scheme providing mutual authentication and session key establishment among all the participants of the DRM environment. We show that their scheme does not resist threats like smart card attack; fails to provide proper password update facility; and does not follow forward secrecy. To overcome these weaknesses, we propose an improvement of Yang et al.'s scheme. The security of our scheme remains intact even if the smart card of the user is lost. In our scheme, user's smart card is capable of verifying the correctness of the inputted identity and password and hence contributes to achieve an efficient and user- friendly password update phase. In addition, the session keys established between the participating entities are highly secure by virtue of forward secrecy property. We conduct security analysis and comparison with related schemes to evaluate our improved scheme. During comparison, we also highlight the computational cost/time complexity at the user and the server side in terms of the execution time of various operations. The entire analysis shows that the design of the improved scheme is robust enough for the for DRM environment.
引用
收藏
页码:1135 / 1158
页数:24
相关论文
共 50 条
  • [1] A more secure digital rights management authentication scheme based on smart card
    Saru Kumari
    Muhammad Khurram Khan
    Xiong Li
    Multimedia Tools and Applications, 2016, 75 : 1135 - 1158
  • [2] Enhanced digital rights management authentication scheme based on smart card
    Yang, Hung-Wen
    Yang, Chou-Chen
    Lin, Woei
    IET INFORMATION SECURITY, 2013, 7 (03) : 189 - 194
  • [3] Provable Secure and Efficient Digital Rights Management Authentication Scheme Using Smart Card Based on Elliptic Curve Cryptography
    Zhang, Yuanyuan
    Khan, Muhammad Khurram
    Chen, Jianhua
    He, Debiao
    MATHEMATICAL PROBLEMS IN ENGINEERING, 2015, 2015
  • [4] Smart card based secure password authentication scheme
    Wang, SJ
    Chang, JF
    COMPUTERS & SECURITY, 1996, 15 (03) : 231 - 237
  • [5] An Efficient and Secure Smart Card Based Authentication Scheme
    Chen, Chien-Ming
    Xiang, Bin
    Wang, King-Hang
    Zhang, Yong
    Wu, Tsu-Yang
    JOURNAL OF INTERNET TECHNOLOGY, 2019, 20 (04): : 1113 - 1123
  • [6] Breaking a smart card based secure password authentication scheme
    Yoon, Eun-Jun
    Yoo, Kee-Young
    PROCEEDINGS OF THE SECOND INTERNATIONAL CONFERENCE ON INFORMATION SECURITY AND ASSURANCE, 2008, : 83 - +
  • [7] SECURE SMART CARD BASED PASSWORD AUTHENTICATION SCHEME WITH USER ANONYMITY
    Li, Chun-Ta
    INFORMATION TECHNOLOGY AND CONTROL, 2011, 40 (02): : 157 - 162
  • [8] Cryptanalysis of an Efficient and Secure Smart Card Based Password Authentication Scheme
    Liu, Chi-Wei
    Tsai, Cheng-Yi
    Hwang, Min-Shiang
    RECENT DEVELOPMENTS IN INTELLIGENT SYSTEMS AND INTERACTIVE APPLICATIONS (IISA2016), 2017, 541 : 188 - 193
  • [9] More secure smart card-based remote user password authentication scheme with user anonymity
    Kumari, Saru
    Khan, Muhammad Khurram
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (11) : 2039 - 2053
  • [10] An improved mutual authentication scheme for smart card secure messaging
    Dang, LJ
    Koi, WD
    Xiao, YX
    PROCEEDINGS OF THE IEEE INTERNATIONAL CONFERENCE ON E-COMMERCE TECHNOLOGY FOR DYNAMIC E-BUSINESS, 2004, : 261 - 264