首页    期刊浏览 2024年10月06日 星期日
登录注册

文章基本信息

  • 标题:Cryptanalysis and improvement of a Multi-Server Authenticated Key Agreement by Chen and Lee’s Scheme
  • 本地全文:下载
  • 作者:Irshad, Azeem ; Naqvi, Husnain ; Ashraf Chaudhary, Shehzad
  • 期刊名称:Engineering Economics
  • 印刷版ISSN:2029-5839
  • 出版年度:2018
  • 卷号:47
  • 期号:3
  • 页码:431-446
  • DOI:10.5755/j01.itc.47.3.17361
  • 语种:English
  • 出版社:Kaunas University of Technology
  • 摘要:Multi-server authentication makes convenient to benefit from services of various service providers on the basis of one-time registration through a trusted third party. Since, the users are reluctant to register themselves separately from all servers due to the hassle of remembering many passwords and other cost constraints. The multi-server authentication enables the immediate provision of services by the real-time verification of users on an insecure channel. The literature for multi-server oriented authenticated key agreement could be traced back to Li et al. and Lee et al., in 2000. Since then, numerous multi-server authentication techniques have been put forth. Nonetheless, the research academia looks for more secure and efficient authentication protocols. Recently, Chen and Lee’s scheme presented a two-factor multi-server key agreement protocol, which is found to be prone to impersonation, stolen smart card, key-compromise impersonation attack, and trace attacks. Besides, the scheme is also found to have the inefficient password modification procedure. We propose an improved protocol that counters the above limitations in almost an equivalent computation cost. Moreover, our protocol is supplemented with formal security analysis using BAN logic along with performance analysis and evaluation.
  • 其他摘要:Multi-server authentication makes convenient to benefit from services of various service providers on the basis of one-time registration through a trusted third party. Since, the users are reluctant to register themselves separately from all servers due to the hassle of remembering many passwords and other cost constraints. The multi-server authentication enables the immediate provision of services by the real-time verification of users on an insecure channel. The literature for multi-server oriented authenticated key agreement could be traced back to Li et al. and Lee et al., in 2000. Since then, numerous multi-server authentication techniques have been put forth. Nonetheless, the research academia looks for more secure and efficient authentication protocols. Recently, Chen and Lee’s scheme presented a two-factor multi-server key agreement protocol, which is found to be prone to impersonation, stolen smart card, key-compromise impersonation attack, and trace attacks. Besides, the scheme is also found to have the inefficient password modification procedure. We propose an improved protocol that counters the above limitations in almost an equivalent computation cost. Moreover, our protocol is supplemented with formal security analysis using BAN logic along with performance analysis and evaluation. DOI: http://dx.doi.org/10.5755/j01.itc.47.3.17361
  • 关键词:Multi-server authentication; cryptanalysis; biometrics; remote authentication; attack
  • 其他关键词:Multi-server authentication; cryptanalysis; biometrics; remote authentication; attack
国家哲学社会科学文献中心版权所有