Security Enhancement of Biometric-Based Authentication Systems Using Smart Card

被引:0
|
作者
Kim, Hyunseok [1 ]
机构
[1] ICT Polytech Inst Korea, Dept Informat & Secur, Gwangju Si 12777, Gyeonggi Do, South Korea
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Servers; Protocols; Authentication; Passwords; Smart cards; Biometrics; Impersonation attacks; Biological system modeling; Wireless sensor networks; Reviews; Password based authentication; biometrics; BPR model; fomal verification; AVISPA tool; REMOTE USER AUTHENTICATION; KEY AGREEMENT SCHEME; E-HEALTH SYSTEMS;
D O I
10.1109/ACCESS.2024.3502632
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Remote authentication has been extensively studied over the past few decades, with password-based authentication being a common approach since Lamport's 1981 proposal of a password-based remote authentication scheme. Despite numerous advancements, including the introduction of biometric and smart card-based schemes by Li and Hwang, as well as Chen et al.'s claims of robustness against various attacks, these protocols continue to exhibit vulnerabilities. These weaknesses include susceptibility to attacks such as replay, man-in-the-middle, user impersonation, and offline password guessing, among others. In this study, we conduct a comprehensive analysis of several existing biometric-based authentication protocols, identifying critical vulnerabilities and areas for improvement. To address these issues, we propose a novel authentication protocol that leverages the biometrics of mobile devices. Our protocol incorporates a collision-free one-way hash function to enhance security. We conduct a thorough security analysis of the proposed protocol using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool, alongside both formal and informal security evaluations. The results of these analyses indicate that our proposed scheme significantly improves security by effectively mitigating common attacks that have compromised previous protocols. Additionally, our protocol demonstrates superior computational efficiency, making it practical for real-world applications. By addressing the security flaws inherent in existing protocols and optimizing for performance, our scheme provides a robust and efficient solution for secure remote authentication using mobile device biometrics.
引用
收藏
页码:174053 / 174065
页数:13
相关论文
共 50 条
  • [1] An Improved Biometric-based Multi-server Authentication Scheme Using Smart Card
    Baruah, Khanjan Ch.
    Banerjee, Subhasish
    Dutta, Manash P.
    Bhunia, Chandan T.
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (01): : 397 - 408
  • [2] Cryptanalysis of Biometric-based Multi-server Authentication Scheme Using Smart Card
    Mun, Jongho
    Kim, Jiye
    Lee, Donghoon
    Won, Dongho
    PROCEEDINGS OF THE 11TH EAI INTERNATIONAL CONFERENCE ON HETEROGENEOUS NETWORKING FOR QUALITY, RELIABILITY, SECURITY AND ROBUSTNESS, 2015, : 56 - 59
  • [3] Oblivious Extractors and Improved Security in Biometric-Based Authentication Systems
    Nunes, Ivan De Oliveira
    Rindal, Peter
    Shirvanian, Maliheh
    COMPUTER SECURITY - ESORICS 2023, PT I, 2024, 14344 : 290 - 312
  • [4] Improving Biometric-Based Authentication Schemes with Smart Card Revocation/Reissue for Wireless Sensor Networks
    Moon, Jongho
    Lee, Donghoon
    Lee, Youngsook
    Won, Dongho
    SENSORS, 2017, 17 (05):
  • [5] Security Analysis and Enhancements of an Effective Biometric-Based Remote User Authentication Scheme Using Smart Cards
    An, Younghwa
    JOURNAL OF BIOMEDICINE AND BIOTECHNOLOGY, 2012,
  • [6] Secure biometric-based authentication scheme with smart card revocation/reissue for wireless sensor networks
    Park, YoHan
    Lee, SungYup
    Kim, ChangKyun
    Park, YoungHo
    INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2016, 12 (07) : 1 - 11
  • [8] Privacy Preserving Biometric-based User Authentication Protocol using Smart Cards
    Park, Minsu
    Kim, Hyunsung
    Lee, Sung-Woon
    2014 IEEE 17TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE), 2014, : 1541 - 1544
  • [9] Biometric-Based Security System for Smart Riding Clubs
    Jarraya, Islem
    Ben Said, Fatma
    Hamdani, Tarek M.
    Neji, Bilel
    Beyrouthy, Taha
    Alimi, Adel M.
    IEEE ACCESS, 2022, 10 : 132012 - 132030
  • [10] Security bound enhancement of remote user authentication using smart card
    Madhusudhan, R.
    Hegde, Manjunath
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 36 : 59 - 68