Security Enhanced Anonymous Multiserver Authenticated Key Agreement Scheme Using Smart Cards and Biometrics

被引:6
|
作者
Choi, Younsung [1 ]
Nam, Junghyun [2 ]
Lee, Donghoon [1 ]
Kim, Jiye [1 ]
Jung, Jaewook [1 ]
Won, Dongho [1 ]
机构
[1] Sungkyunkwan Univ, Dept Comp Engn, Suwon 440746, Gyeonggido, South Korea
[2] Konkuk Univ, Dept Comp Engn, Chungju 380701, Chungcheongbukd, South Korea
来源
基金
新加坡国家研究基金会;
关键词
PASSWORD AUTHENTICATION; USER; EFFICIENT; CRYPTANALYSIS; IMPROVEMENT; PROTOCOL;
D O I
10.1155/2014/281305
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
An anonymous user authentication scheme allows a user, who wants to access a remote application server, to achieve mutual authentication and session key establishment with the server in an anonymous manner. To enhance the security of such authentication schemes, recent researches combined user's biometrics with a password. However, these authentication schemes are designed for single server environment. So when a user wants to access different application servers, the user has to register many times. To solve this problem, Chuang and Chen proposed an anonymous multiserver authenticated key agreement scheme using smart cards together with passwords and biometrics. Chuang and Chen claimed that their scheme not only supports multiple servers but also achieves various security requirements. However, we show that this scheme is vulnerable to a masquerade attack, a smart card attack, a user impersonation attack, and a DoS attack and does not achieve perfect forward secrecy. We also propose a security enhanced anonymous multiserver authenticated key agreement scheme which addresses all the weaknesses identified in Chuang and Chen's scheme.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Cryptanalysis of An Anonymous Multi-Server Authenticated Key Agreement Scheme Using Smart Cards and Biometrics
    Li, Chun-Ta
    Lee, Cheng-Chi
    Chen, Hua-Hsuan
    Syu, Min-Jie
    Wang, Chun-Cheng
    2015 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN), 2015, : 498 - 502
  • [2] An Improved Anonymous Multi-Server Authenticated Key Agreement Scheme Using Smart Cards and Biometrics
    Lin, Hao
    Wen, Fengtong
    Du, Chunxia
    WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (04) : 2351 - 2362
  • [3] An Improved Anonymous Multi-Server Authenticated Key Agreement Scheme Using Smart Cards and Biometrics
    Hao Lin
    Fengtong Wen
    Chunxia Du
    Wireless Personal Communications, 2015, 84 : 2351 - 2362
  • [4] Security Enhanced Anonymous User Authenticated Key Agreement Scheme Using Smart Card
    Jaewook Jung
    Donghoon Lee
    Hakjun Lee
    Dongho Won
    Journal of Electronic Science and Technology, 2018, 16 (01) : 45 - 49
  • [5] An anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards and biometrics
    Chuang, Ming-Chin
    Chen, Meng Chang
    EXPERT SYSTEMS WITH APPLICATIONS, 2014, 41 (04) : 1411 - 1418
  • [6] A Key Agreement Scheme for Smart Cards Using Biometrics
    Mondal, Bhaskar
    Bhowmick, Anirban
    Choudhury, Tanupriya
    Mandal, Tarni
    2016 IEEE INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND AUTOMATION (ICCCA), 2016, : 1011 - 1015
  • [7] Security of efficient password authenticated key agreement using smart cards
    Shieh, Wen-Gong
    WSEAS Transactions on Information Science and Applications, 2006, 3 (01): : 187 - 191
  • [8] Biometrics authenticated key agreement scheme
    Yoon, Eun-Jun
    Yoo, Kee-Young
    NEXT GENERATION INFORMATION TECHNOLOGIES AND SYSTEMS, PROCEEDINGS, 2006, 4032 : 345 - 349
  • [9] Enhanced Security for the Modified Authenticated Key Agreement Scheme
    Kim, Minho
    Koc, Cetin Kaya
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2006, 6 (7B): : 164 - 169
  • [10] Anonymous Password-based Authenticated Key Agreement Scheme with Non-tamper Resistant Smart Cards
    Lee, Yunghee
    Kim, Hyunsung
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (11): : 419 - 428