Security Enhanced Anonymous Multiserver Authenticated Key Agreement Scheme Using Smart Cards and Biometrics

被引:6
|
作者
Choi, Younsung [1 ]
Nam, Junghyun [2 ]
Lee, Donghoon [1 ]
Kim, Jiye [1 ]
Jung, Jaewook [1 ]
Won, Dongho [1 ]
机构
[1] Sungkyunkwan Univ, Dept Comp Engn, Suwon 440746, Gyeonggido, South Korea
[2] Konkuk Univ, Dept Comp Engn, Chungju 380701, Chungcheongbukd, South Korea
来源
基金
新加坡国家研究基金会;
关键词
PASSWORD AUTHENTICATION; USER; EFFICIENT; CRYPTANALYSIS; IMPROVEMENT; PROTOCOL;
D O I
10.1155/2014/281305
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
An anonymous user authentication scheme allows a user, who wants to access a remote application server, to achieve mutual authentication and session key establishment with the server in an anonymous manner. To enhance the security of such authentication schemes, recent researches combined user's biometrics with a password. However, these authentication schemes are designed for single server environment. So when a user wants to access different application servers, the user has to register many times. To solve this problem, Chuang and Chen proposed an anonymous multiserver authenticated key agreement scheme using smart cards together with passwords and biometrics. Chuang and Chen claimed that their scheme not only supports multiple servers but also achieves various security requirements. However, we show that this scheme is vulnerable to a masquerade attack, a smart card attack, a user impersonation attack, and a DoS attack and does not achieve perfect forward secrecy. We also propose a security enhanced anonymous multiserver authenticated key agreement scheme which addresses all the weaknesses identified in Chuang and Chen's scheme.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] Robust biometrics-based key agreement scheme with smart cards towards a new architecture
    Zhu, Hongfeng
    Jiang, Man
    Hao, Xin
    Zhang, Yan
    Journal of Information Hiding and Multimedia Signal Processing, 2015, 6 (01): : 81 - 98
  • [22] On the Security of an Anonymous Batch Authenticated and Key Agreement Scheme for Value-Added Services in VANETs
    Wang, Huaqun
    Zhang, Yuqing
    2012 INTERNATIONAL WORKSHOP ON INFORMATION AND ELECTRONICS ENGINEERING, 2012, 29 : 1735 - 1739
  • [23] Security Analysis of an Anonymous Authentication Scheme Based on Smart Cards and Biometrics for Multi-server Environments
    Pan, Jeng-Shyang
    Tso, Raylin
    Wu, Mu-En
    Chen, Chien-Ming
    GENETIC AND EVOLUTIONARY COMPUTING, VOL II, 2016, 388 : 59 - 69
  • [24] A privacy-preserving biometrics based authenticated key agreement scheme using ECC
    Qi, Mingping
    Chen, Jianhua
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2020, 33 (11)
  • [25] An Efficient Authenticated Key Agreement Scheme Without Using Smart Card
    Li, Chun-Ta
    Hwang, Min-Shiang
    Huang, Pin-Chieh
    IMETI 2011: 4TH INTERNATIONAL MULTI-CONFERENCE ON ENGINEERING AND TECHNOLOGICAL INNOVATION, VOL II, 2011, : 78 - 82
  • [26] Efficient multi-server password authenticated key agreement using smart cards
    Juang, WS
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (01) : 251 - 255
  • [27] An Effective and Robust Secure Remote User Authenticated Key Agreement Scheme Using Smart Cards in Wireless Communication Systems
    Vanga Odelu
    Ashok Kumar Das
    Adrijit Goswami
    Wireless Personal Communications, 2015, 84 : 2571 - 2598
  • [28] An Effective and Robust Secure Remote User Authenticated Key Agreement Scheme Using Smart Cards in Wireless Communication Systems
    Odelu, Vanga
    Das, Ashok Kumar
    Goswami, Adrijit
    WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (04) : 2571 - 2598
  • [29] An Anonymous User Authentication with Key Agreement Scheme without Pairings for Multiserver Architecture Using SCPKs
    Jiang, Peng
    Wen, Qiaoyan
    Li, Wenmin
    Jin, Zhengping
    Zhang, Hua
    SCIENTIFIC WORLD JOURNAL, 2013,
  • [30] An Enhanced Secure Anonymous Authentication Scheme Based on Smart Cards and Biometrics for Multi-Server Environments
    Kuo, Wen-Chung
    Wei, Hong-Ji
    Chen, Yu-Hui
    Cheng, Jiin-Chiou
    2015 10TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS), 2015, : 1 - 5