Security Enhancement of Biometric-Based Authentication Systems Using Smart Card

被引:0
|
作者
Kim, Hyunseok [1 ]
机构
[1] ICT Polytech Inst Korea, Dept Informat & Secur, Gwangju Si 12777, Gyeonggi Do, South Korea
来源
IEEE ACCESS | 2024年 / 12卷
关键词
Servers; Protocols; Authentication; Passwords; Smart cards; Biometrics; Impersonation attacks; Biological system modeling; Wireless sensor networks; Reviews; Password based authentication; biometrics; BPR model; fomal verification; AVISPA tool; REMOTE USER AUTHENTICATION; KEY AGREEMENT SCHEME; E-HEALTH SYSTEMS;
D O I
10.1109/ACCESS.2024.3502632
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Remote authentication has been extensively studied over the past few decades, with password-based authentication being a common approach since Lamport's 1981 proposal of a password-based remote authentication scheme. Despite numerous advancements, including the introduction of biometric and smart card-based schemes by Li and Hwang, as well as Chen et al.'s claims of robustness against various attacks, these protocols continue to exhibit vulnerabilities. These weaknesses include susceptibility to attacks such as replay, man-in-the-middle, user impersonation, and offline password guessing, among others. In this study, we conduct a comprehensive analysis of several existing biometric-based authentication protocols, identifying critical vulnerabilities and areas for improvement. To address these issues, we propose a novel authentication protocol that leverages the biometrics of mobile devices. Our protocol incorporates a collision-free one-way hash function to enhance security. We conduct a thorough security analysis of the proposed protocol using the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool, alongside both formal and informal security evaluations. The results of these analyses indicate that our proposed scheme significantly improves security by effectively mitigating common attacks that have compromised previous protocols. Additionally, our protocol demonstrates superior computational efficiency, making it practical for real-world applications. By addressing the security flaws inherent in existing protocols and optimizing for performance, our scheme provides a robust and efficient solution for secure remote authentication using mobile device biometrics.
引用
收藏
页码:174053 / 174065
页数:13
相关论文
共 50 条
  • [41] Biometric-Based Authentication in Internet of Things (IoT): A Review
    Singh, Vijender
    Kant, Chander
    ADVANCES IN INFORMATION COMMUNICATION TECHNOLOGY AND COMPUTING, AICTC 2021, 2022, 392 : 309 - 317
  • [42] An Enhanced Biometric-Based Authentication Scheme for Telecare Medicine Information Systems Using Elliptic Curve Cryptosystem
    Lu, Yanrong
    Li, Lixiang
    Peng, Haipeng
    Yang, Yixian
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
  • [43] MultiLock: Biometric-Based Graded Authentication for Mobile Devices
    Aras, Shravan
    Gniady, Chris
    Venugopalan, Hari
    PROCEEDINGS OF THE 16TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS'19), 2019, : 100 - 109
  • [45] An Enhanced Biometric-Based Authentication Scheme for Telecare Medicine Information Systems Using Elliptic Curve Cryptosystem
    Yanrong Lu
    Lixiang Li
    Haipeng Peng
    Yixian Yang
    Journal of Medical Systems, 2015, 39
  • [46] Improved Biometric-Based Mutual Authentication and Key Agreement Scheme Using ECC
    Sahoo, Shreeya Swagatika
    Mohanty, Sujata
    Majhi, Banshidhar
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 111 (02) : 991 - 1017
  • [47] Security Enhancement on Li-Lee's Remote User Authentication Scheme Using Smart Card
    Martinez-Pelaez, Rafael
    Rico-Novella, Francisco
    Velarde-Alvarado, Pablo
    COMPUTACION Y SISTEMAS, 2014, 18 (04): : 709 - 717
  • [48] Improved Biometric-Based Mutual Authentication and Key Agreement Scheme Using ECC
    Shreeya Swagatika Sahoo
    Sujata Mohanty
    Banshidhar Majhi
    Wireless Personal Communications, 2020, 111 : 991 - 1017
  • [49] A Biometric based Remote User Authentication Technique Using Smart Card in Multi-Server Environment
    Shyamalendu Kandar
    Sumit Pal
    Bibhas Chandra Dhara
    Wireless Personal Communications, 2021, 120 : 1003 - 1026
  • [50] A Biometric based Remote User Authentication Technique Using Smart Card in Multi-Server Environment
    Kandar, Shyamalendu
    Pal, Sumit
    Dhara, Bibhas Chandra
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 120 (02) : 1003 - 1026