Cryptanalysis of Anonymous Three Factor-Based Authentication Schemes for Multi-server Environment

被引:1
|
作者
Mo, Jiaqing [1 ]
Chen, Hang [1 ]
Shen, Wei [1 ]
机构
[1] Zhaoqing Univ, Sch Comp Sci & Software, Zhaoqing 526061, Peoples R China
基金
中国国家自然科学基金;
关键词
Authentication; Three-factor security; Offline password guessing attack; Multi-server environment; PROTOCOL; SECURITY; IMPROVEMENT; EFFICIENT; DESIGN;
D O I
10.1007/978-3-030-16946-6_36
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Cryptanalyzing the security weaknesses of authentication protocols is extremely important to propose countermeasures and develop a truly secure protocol. Over last few years, many three factor-based authentication schemes with key agreement have been proposed for multi-server environment. In 2017, Ali and Pal developed a three-factor authentication scheme in multi-server environment using elliptic curve cryptography (ECC) to remedy the security flaws in Li et al.'s scheme and claimed their improved version can withstand the passive and active attacks. In this paper, we prove that Ali-Pal's scheme is subject to offline password guessing attack, replay attack, and known session-specific temporary information (KSSTI) attack. In the same year, Feng et al. examined Kumari et al.'s biometrics-based authentication scheme for multi-server environment and found that their scheme was vulnerable to several attacks. To fix these weaknesses, Feng et al. proposed an enhanced three-factor authentication scheme with key distribution for mobile multi-server environment and claimed that their scheme can satisfy the security and functional requirements. However, we show that Feng et al.'s scheme fails to resist offline password guessing attack, and suffers from replay attack. In addition to point out the security defects, we put forward countermeasures to eliminate the security risks and secure the three factor-based authentication schemes for multi-server environment.
引用
收藏
页码:456 / 468
页数:13
相关论文
共 50 条
  • [31] Cryptanalysis and improvement of a biometric-based authentication scheme for multi-server architecture
    Wan, Tao
    Liu, Xiaochang
    Liao, Weichuan
    Jiang, Nan
    [J]. International Journal of Network Security, 2020, 22 (03) : 492 - 503
  • [32] Anonymous biometrics-based authentication with key agreement scheme for multi-server environment using ECC
    Mingping Qi
    Jianhua Chen
    [J]. Multimedia Tools and Applications, 2019, 78 : 27553 - 27568
  • [33] Anonymous biometrics-based authentication with key agreement scheme for multi-server environment using ECC
    Qi, Mingping
    Chen, Jianhua
    [J]. MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (19) : 27553 - 27568
  • [34] Three-Factor-Based Confidentiality-Preserving Remote User Authentication Scheme in Multi-server Environment
    Ali, Rifaqat
    Pal, Arup Kumar
    [J]. ARABIAN JOURNAL FOR SCIENCE AND ENGINEERING, 2017, 42 (08) : 3655 - 3672
  • [35] Three-Factor-Based Confidentiality-Preserving Remote User Authentication Scheme in Multi-server Environment
    Rifaqat Ali
    Arup Kumar Pal
    [J]. Arabian Journal for Science and Engineering, 2017, 42 : 3655 - 3672
  • [36] Understanding security failures of multi-factor authentication schemes for multi-server environments
    Wang, Ding
    Zhang, Xizhe
    Zhang, Zijian
    Wang, Ping
    [J]. COMPUTERS & SECURITY, 2020, 88
  • [37] A taxonomy of user authentication schemes for multi-server environments
    Yang, Hung-Wei
    Pan, Hsieh-Tsen
    Chen, Yung-Hsing
    Hwang, Min-Shiang
    [J]. International Journal of Network Security, 2020, 22 (03): : 365 - 372
  • [38] Cryptanalysis and Improvement of an Anonymous Multi-server Authenticated Key Agreement Scheme
    Shipra Kumari
    Hari Om
    [J]. Wireless Personal Communications, 2017, 96 : 2513 - 2537
  • [39] Authentication scheme based on smart card in multi-server environment
    Simin Zhou
    Qingqing Gan
    Xiaoming Wang
    [J]. Wireless Networks, 2020, 26 : 855 - 863
  • [40] Cryptanalysis and Improvement of an Anonymous Multi-server Authenticated Key Agreement Scheme
    Kumari, Shipra
    Om, Hari
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (02) : 2513 - 2537