Cryptanalysis and improvement on anonymous three-factor authentication scheme for mobile networks

被引:18
|
作者
Xie, Qi [1 ]
Tang, Zhixiong [1 ]
Chen, Kefei [1 ]
机构
[1] Hangzhou Normal Univ, Key Lab Cryptog & Network Secur, Hangzhou 311121, Zhejiang, Peoples R China
关键词
Three-factor; Authentication; Mobile networks; Anonymity; PRIVACY; SECURE;
D O I
10.1016/j.compeleceng.2016.11.038
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
User authentication protocol is an important security mechanism for mobile networks. Recently, Wu et al. proposed a biometrics-based three-factor user authentication scheme using elliptic curve cryptography for mobile networks. However, in this paper, we find out that their scheme is vulnerable to the impersonation attack, because de/encryption key of the server and the user can be computed by an adversary. And then an improved three factor authentication scheme for mobile client-server networks is proposed to overcome the weakness. The proposed scheme uses a random nonce to decrypt and encrypt messages without using the server's public key for reducing computation cost and avoiding the key management problem, and it also achieves user's anonymity. In addition, we apply the pi calculus-based formal verification tool ProVerif for security evaluations, and compare our scheme with some related schemes to show that the proposed scheme is both secure and efficient. (C) 2016 Elsevier Ltd. All rights reserved.
引用
收藏
页码:218 / 230
页数:13
相关论文
共 50 条
  • [41] Design of a Secure Three-Factor Authentication Scheme for Smart Healthcare
    Km. Renuka
    Saru Kumari
    Xiong Li
    [J]. Journal of Medical Systems, 2019, 43
  • [42] Cryptanalysis and Improvement of an Anonymous Batch Verification Scheme for Mobile Healthcare Crowd Sensing
    Wang, Wenming
    Huang, Haiping
    Wu, Yuhan
    Huang, Qinglong
    [J]. IEEE ACCESS, 2019, 7 : 165842 - 165851
  • [43] Remote three-factor authentication scheme based on Fuzzy extractors
    Zhang, Min
    Zhang, Jiashu
    Zhang, Ying
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (04) : 682 - 693
  • [44] Cryptanalysis and improvement of an authentication scheme for IoT
    Kumar, Rahul
    Gupta, Mridul Kumar
    Kumari, Saru
    [J]. INTERNATIONAL JOURNAL OF INFORMATION AND COMPUTER SECURITY, 2022, 19 (1-2) : 73 - 87
  • [45] TFPPASV: A Three-Factor Privacy Preserving Authentication Scheme for VANETs
    Duan, Zongtao
    Mahmood, Jabar
    Yang, Yun
    Berwo, Michael Abebe
    Yassin, Abd al Kader Ahmed
    Bhutta, Muhammad Nasir Mumtaz
    Chaudhry, Shehzad Ashraf
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [46] Design of a Secure Three-Factor Authentication Scheme for Smart Healthcare
    Renuka, Km
    Kumari, Saru
    Li, Xiong
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2019, 43 (05)
  • [47] TFPPASV: A Three-Factor Privacy Preserving Authentication Scheme for VANETs
    Duan, Zongtao
    Mahmood, Jabar
    Yang, Yun
    Berwo, Michael Abebe
    Yassin, Abd Al Kader Ahmed
    Mumtaz Bhutta, Muhammad Nasir
    Chaudhry, Shehzad Ashraf
    [J]. Security and Communication Networks, 2022, 2022
  • [48] A Physically Secure, Lightweight Three-Factor and Anonymous User Authentication Protocol for IoT
    Liu, Zhenhua
    Guo, Changbo
    Wang, Baocang
    [J]. IEEE ACCESS, 2020, 8 : 195914 - 195928
  • [49] A novel and provably secure biometrics-based three-factor remote authentication scheme for mobile client-server networks
    Wu, Fan
    Xu, Lili
    Kumari, Saru
    Li, Xiong
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2015, 45 : 274 - 285
  • [50] A robust biometrics based three-factor authentication scheme for Global Mobility Networks in smart city
    Li, Xiong
    Niu, Jianwei
    Kumari, Saru
    Wu, Fan
    Choo, Kim-Kwang Raymond
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 83 : 607 - 618