Enhancing security and efficiency in cloud computing authentication and key agreement scheme based on smart card

被引:0
|
作者
Mariem Bouchaala
Cherif Ghazel
Leila Azouz Saidane
机构
[1] University of Manouba,CRISTAL Laboratory, ENSI
来源
关键词
Cloud computing; Smart cards; Authentication; Key agreement; Elliptic curve cryptography; Security; Scyther tool;
D O I
暂无
中图分类号
学科分类号
摘要
The password-based authentication mechanism is considered as the oldest and the most used method. It is easy to implement, and it does not require any particular configuration or devices. Yet, this solution does not ensure a high level of security when it is used in a large and remote environment such as cloud computing. In such an environment, the cloud user and the authentication remote server use an insecure communication channel to authenticate each other. Consequently, various attacks such as insider attack, password-guessing attack, user impersonation attack, and others can be launched. Smart cards are an alternative to improve this single authentication model by strengthening security and improving the communication process. In our work, we study the Huang et al. proposal. The authors have proposed a smart card-based authentication and key agreement scheme. They have used the elliptic curve to improve security. However, same related work shows that this solution does not resist to impersonation attacks and does not ensure perfect anonymity. Consequently, it does not protect users’ privacy. Thus, we propose an extension of the Huang et al. scheme in order to enforce security requirements. We implement an anonymous, mutual, and secure two-factor authentication and key agreement scheme applied to the cloud computing environment. We use elliptic curve cryptography and a fuzzy verifier to strengthen security. The solution is lightweight and optimizes performance. To prove the safety of the proposed protocol, formal security analysis with random oracle model and Scyther tool is provided. To evaluate its efficiency, a performance evaluation is prepared.
引用
收藏
页码:497 / 522
页数:25
相关论文
共 50 条
  • [1] Enhancing security and efficiency in cloud computing authentication and key agreement scheme based on smart card
    Bouchaala, Mariem
    Ghazel, Cherif
    Saidane, Leila Azouz
    JOURNAL OF SUPERCOMPUTING, 2022, 78 (01): : 497 - 522
  • [2] Smart Card Based Remote User Authentication Scheme for Cloud Computing
    Madhusudhan, R.
    Hegde, Manjunath
    2019 IEEE 10TH ANNUAL UBIQUITOUS COMPUTING, ELECTRONICS & MOBILE COMMUNICATION CONFERENCE (UEMCON), 2019, : 905 - 910
  • [3] Security Enhancements of Smart Card-Based Remote User Password Authentication Scheme with Session Key Agreement
    An, Young-Hwa
    2015 17TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2015, : 669 - 674
  • [4] Cryptanalysis and Improvement of a Smart Card Based Mutual Authentication Scheme in Cloud Computing
    Jiang, Qi
    Li, Bingyan
    Ma, Jianfeng
    Tian, Youliang
    Yang, Yuanyuan
    CLOUD COMPUTING AND SECURITY, ICCCS 2016, PT I, 2016, 10039 : 311 - 321
  • [5] An Exquisite Mutual Authentication Scheme with Key Agreement Using Smart Card
    Liao, Chiu-Hsiung
    Chen, Ho-Chan
    Wang, Ching-Te
    INFORMATICA-JOURNAL OF COMPUTING AND INFORMATICS, 2009, 33 (02): : 117 - 124
  • [6] An Exquisite Mutual Authentication Scheme with Key Agreement Using Smart Card
    Chiu-Hsiung, Liao
    Hon-Chan, Chen
    Ching-Te, Wang
    Informatica (Ljubljana), 2009, 33 (02) : 125 - 132
  • [7] A Robust Smart Card based Authentication and Key Agreement Scheme for WSN using Fuzzy Extractor
    Rituparna Paul
    Shanvendra Rai
    Subhasish Banerjee
    Preetisudha Meher
    Peer-to-Peer Networking and Applications, 2024, 17 : 432 - 450
  • [8] A Secure Authentication and Key Agreement Scheme for IoT-Based Cloud Computing Environment
    Yu, Yicheng
    Hu, Liang
    Chu, Jianfeng
    SYMMETRY-BASEL, 2020, 12 (01):
  • [9] A Robust Smart Card based Authentication and Key Agreement Scheme for WSN using Fuzzy Extractor
    Paul, Rituparna
    Rai, Shanvendra
    Banerjee, Subhasish
    Meher, Preetisudha
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2024, 17 (01) : 432 - 450
  • [10] A Secure Smart-Card Based Authentication and Key Agreement Scheme for Telecare Medicine Information Systems
    Tian-Fu Lee
    Chuan-Ming Liu
    Journal of Medical Systems, 2013, 37