Cryptanalysis of Anonymous Three Factor-Based Authentication Schemes for Multi-server Environment

被引:1
|
作者
Mo, Jiaqing [1 ]
Chen, Hang [1 ]
Shen, Wei [1 ]
机构
[1] Zhaoqing Univ, Sch Comp Sci & Software, Zhaoqing 526061, Peoples R China
基金
中国国家自然科学基金;
关键词
Authentication; Three-factor security; Offline password guessing attack; Multi-server environment; PROTOCOL; SECURITY; IMPROVEMENT; EFFICIENT; DESIGN;
D O I
10.1007/978-3-030-16946-6_36
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Cryptanalyzing the security weaknesses of authentication protocols is extremely important to propose countermeasures and develop a truly secure protocol. Over last few years, many three factor-based authentication schemes with key agreement have been proposed for multi-server environment. In 2017, Ali and Pal developed a three-factor authentication scheme in multi-server environment using elliptic curve cryptography (ECC) to remedy the security flaws in Li et al.'s scheme and claimed their improved version can withstand the passive and active attacks. In this paper, we prove that Ali-Pal's scheme is subject to offline password guessing attack, replay attack, and known session-specific temporary information (KSSTI) attack. In the same year, Feng et al. examined Kumari et al.'s biometrics-based authentication scheme for multi-server environment and found that their scheme was vulnerable to several attacks. To fix these weaknesses, Feng et al. proposed an enhanced three-factor authentication scheme with key distribution for mobile multi-server environment and claimed that their scheme can satisfy the security and functional requirements. However, we show that Feng et al.'s scheme fails to resist offline password guessing attack, and suffers from replay attack. In addition to point out the security defects, we put forward countermeasures to eliminate the security risks and secure the three factor-based authentication schemes for multi-server environment.
引用
收藏
页码:456 / 468
页数:13
相关论文
共 50 条
  • [21] Cryptanalysis and Improvement of an Advanced Anonymous and Biometrics-Based Multi-server Authentication Scheme Using Smart Cards
    Quan, Chunyi
    Lee, Hakjun
    Kang, Dongwoo
    Kim, Jiye
    Cho, Seokhyang
    Won, Dongho
    [J]. ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, 2018, 593 : 62 - 71
  • [22] Cryptanalysis and Improvement of a Biometrics-based Multi-server Authentication Protocol
    Gu, Yi
    Li, Shengqiang
    [J]. 2018 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2018, : 16 - 20
  • [23] Anonymous biometrics-based authentication scheme with key distribution for mobile multi-server environment
    Feng, Qi
    He, Debiao
    Zeadally, Sherali
    Wang, Huaqun
    [J]. FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 84 : 239 - 251
  • [24] Remote Three-Factor Authentication Protocol with Strong Robustness for Multi-Server Environment
    Zhang, Min
    Zhang, Jiashu
    Tan, Wenrong
    [J]. CHINA COMMUNICATIONS, 2017, 14 (06) : 126 - 136
  • [25] Remote Three-Factor Authentication Protocol with Strong Robustness for Multi-Server Environment
    Min Zhang
    Jiashu Zhang
    Wenrong Tan
    [J]. China Communications, 2017, 14 (06) : 126 - 136
  • [26] A new three-factor authentication and key agreement protocol for multi-server environment
    T. Sudhakar
    V. Natarajan
    [J]. Wireless Networks, 2020, 26 : 4909 - 4920
  • [27] A new three-factor authentication and key agreement protocol for multi-server environment
    Sudhakar, T.
    Natarajan, V.
    [J]. WIRELESS NETWORKS, 2020, 26 (07) : 4909 - 4920
  • [28] TAMA: Three-Factor Authentication for Multi-server Architecture
    Amintoosi, Haleh
    Nikooghadam, Mahdi
    Kumari, Saru
    Kumar, Sachin
    Chen, Chien-Ming
    [J]. Human-centric Computing and Information Sciences, 2021, 11
  • [29] TAMA: Three-Factor Authentication for Multi-server Architecture
    Amintoosi, Haleh
    Nikooghadam, Mandi
    Kumari, Sam
    Kumar, Sachin
    Chen, Chien-Ming
    [J]. HUMAN-CENTRIC COMPUTING AND INFORMATION SCIENCES, 2021, 11
  • [30] Cryptanalysis of a Smartcard-Based User Authentication Scheme for Multi-Server Environments
    He, Debiao
    Hu, Hao
    [J]. IEICE TRANSACTIONS ON COMMUNICATIONS, 2012, E95B (09) : 3052 - 3054