Cryptanalysis of Anonymous Three Factor-Based Authentication Schemes for Multi-server Environment

被引:1
|
作者
Mo, Jiaqing [1 ]
Chen, Hang [1 ]
Shen, Wei [1 ]
机构
[1] Zhaoqing Univ, Sch Comp Sci & Software, Zhaoqing 526061, Peoples R China
基金
中国国家自然科学基金;
关键词
Authentication; Three-factor security; Offline password guessing attack; Multi-server environment; PROTOCOL; SECURITY; IMPROVEMENT; EFFICIENT; DESIGN;
D O I
10.1007/978-3-030-16946-6_36
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Cryptanalyzing the security weaknesses of authentication protocols is extremely important to propose countermeasures and develop a truly secure protocol. Over last few years, many three factor-based authentication schemes with key agreement have been proposed for multi-server environment. In 2017, Ali and Pal developed a three-factor authentication scheme in multi-server environment using elliptic curve cryptography (ECC) to remedy the security flaws in Li et al.'s scheme and claimed their improved version can withstand the passive and active attacks. In this paper, we prove that Ali-Pal's scheme is subject to offline password guessing attack, replay attack, and known session-specific temporary information (KSSTI) attack. In the same year, Feng et al. examined Kumari et al.'s biometrics-based authentication scheme for multi-server environment and found that their scheme was vulnerable to several attacks. To fix these weaknesses, Feng et al. proposed an enhanced three-factor authentication scheme with key distribution for mobile multi-server environment and claimed that their scheme can satisfy the security and functional requirements. However, we show that Feng et al.'s scheme fails to resist offline password guessing attack, and suffers from replay attack. In addition to point out the security defects, we put forward countermeasures to eliminate the security risks and secure the three factor-based authentication schemes for multi-server environment.
引用
收藏
页码:456 / 468
页数:13
相关论文
共 50 条
  • [41] Authentication scheme based on smart card in multi-server environment
    Zhou, Simin
    Gan, Qingqing
    Wang, Xiaoming
    [J]. WIRELESS NETWORKS, 2020, 26 (02) : 855 - 863
  • [42] A Novel Multi-server Environment Authentication Protocol
    Li Haixia
    Lu Chuiwei
    Sun Sheng
    [J]. PROCESSING OF 2014 INTERNATIONAL CONFERENCE ON MULTISENSOR FUSION AND INFORMATION INTEGRATION FOR INTELLIGENT SYSTEMS (MFI), 2014,
  • [43] Cryptanalysis and Improvement of a Biometric-Based Multi-Server Authentication and Key Agreement Scheme
    Wang, Chengqi
    Zhang, Xiao
    Zheng, Zhiming
    [J]. PLOS ONE, 2016, 11 (02):
  • [44] Cryptanalysis and Improvement of a Biometrics-Based Multi-server Authentication with Key Agreement Scheme
    Kim, Hakhyun
    Jeon, Woongryul
    Lee, Kwangwoo
    Lee, Yunho
    Won, Dongho
    [J]. COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2012, PT III, 2012, 7335 : 391 - 406
  • [45] Cryptanalysis of Biometric-based Multi-server Authentication Scheme Using Smart Card
    Mun, Jongho
    Kim, Jiye
    Lee, Donghoon
    Won, Dongho
    [J]. PROCEEDINGS OF THE 11TH EAI INTERNATIONAL CONFERENCE ON HETEROGENEOUS NETWORKING FOR QUALITY, RELIABILITY, SECURITY AND ROBUSTNESS, 2015, : 56 - 59
  • [46] Cryptanalysis of a Robust Smart Card Authentication Scheme for Multi-server Architecture
    Li, Xiong
    Kumari, Saru
    Khan, Muhammad Khurram
    Liao, Junguo
    Liang, Wei
    [J]. 2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 120 - 123
  • [47] Cryptanalysis of design and analysis of a provably secure multi-server authentication scheme
    Mohan, Naresh Babu Muthu
    Chakravarthy, Ardhani Sathya Narayana
    Ravindranath, Cherukuri
    [J]. International Journal of Network Security, 2018, 20 (02) : 217 - 224
  • [48] Cryptanalysis of Efficient Dynamic ID Based Remote User Authentication Scheme in Multi-server Environment Using Smart Card
    Pan, Hsieh-Tsen
    Tsaur, Shyh-Chang
    Hwang, Min-Shiang
    [J]. PROCEEDINGS OF 2016 12TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2016, : 590 - 593
  • [49] Cryptanalysis and improvement of a smart card based authentication scheme for multi-server architecture using ECC
    Wan, Tao
    Liu, Xiaochang
    Liao, Weichuan
    Jiang, Nan
    [J]. International Journal of Network Security, 2019, 21 (06) : 993 - 1002
  • [50] Cryptanalysis and improvement of a biometrics-based authentication and key agreement scheme for multi-server environments
    Yang, Li
    Zheng, Zhiming
    [J]. PLOS ONE, 2018, 13 (03):