An improved and secure multiserver authentication scheme based on biometrics and smartcard

被引:25
|
作者
Kumar, Ashish [1 ]
Om, Hari [1 ]
机构
[1] Indian Inst Technol ISM, Dept Comp Sci & Engn, Dhanbad 826004, Jharkhand, India
关键词
Smartcard; Password; Security; Authentication; Multi-server; Biometric; ProVerif; KEY-AGREEMENT PROTOCOL; EFFICIENT; ROBUST; CARDS;
D O I
10.1016/j.dcan.2017.09.004
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
With the advancement in internet technologies, the number of servers has increased remarkably to provide more services to the end users. These services are provided over the public channels, which are insecure and susceptible to interception, modification, and deletion. To provide security, registered entities are authenticated and then a session key is established between them to communicate securely. The conventional schemes allow a user to access services only after their independent registration with each desired server in a multiserver system. Therefore, a user must possess multiple smartcards and memorize various identities and passwords for obtaining services from multiple servers. This has led to the adoption of multiserver authentication in which a user accesses services of multiple servers after registering himself at only one central authority. Recently, Kumar and Om discussed a scheme for multiserver environment by using smartcard. Since the user-memorized passwords are of low entropy, it is possible for an attacker to guess them. This paper uses biometric information of user to enhance the security of the scheme by Kumar and Om. Moreover, we conducted rigorous security analyses (informal and formal) in this study to prove the security of the proposed scheme against all known attacks. We also simulated our scheme by using the automated tool, ProVerif, to prove its secrecy and authentication properties. A comparative study of the proposed scheme with the existing related schemes shows its effectiveness.
引用
收藏
页码:27 / 38
页数:12
相关论文
共 50 条
  • [1] An improved and secure multiserver authentication scheme based on biometrics and smartcard
    Ashish Kumar
    Hari Om
    Digital Communications and Networks, 2018, 4 (01) : 27 - 38
  • [2] A Provably Secure Biometrics-Based Authentication Scheme for Multiserver Environment
    Wang, Feifei
    Xu, Guoai
    Wang, Chenyu
    Peng, Junhao
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [3] An improved and robust biometrics-based three factor authentication scheme for multiserver environments
    Chaudhry, Shehzad Ashraf
    Naqvi, Husnain
    Farash, Mohammad Sabzinejad
    Shon, Taeshik
    Sher, Muhammad
    JOURNAL OF SUPERCOMPUTING, 2018, 74 (08): : 3504 - 3520
  • [4] An improved and robust biometrics-based three factor authentication scheme for multiserver environments
    Shehzad Ashraf Chaudhry
    Husnain Naqvi
    Mohammad Sabzinejad Farash
    Taeshik Shon
    Muhammad Sher
    The Journal of Supercomputing, 2018, 74 : 3504 - 3520
  • [5] Robust Biometrics-Based Authentication Scheme for Multiserver Environment
    He, Debiao
    Wang, Ding
    IEEE SYSTEMS JOURNAL, 2015, 9 (03): : 816 - 823
  • [6] An improved lightweight multiserver authentication scheme
    Irshad, Azeem
    Chaudhry, Shehzad Ashraf
    Kumari, Saru
    Usman, Muhammad
    Mahmood, Khalid
    Faisal, Muhammad Shahzad
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (17)
  • [7] On the Security of a Smartcard-Based Authentication System for Multiserver Environments
    Mao, Xianping
    Li, Xuefeng
    Wu, Xiaochuan
    Zhao, Jing
    Ma, Huanyu
    Liu, Qiushan
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON COMMUNICATION AND INFORMATION PROCESSING (ICCIP 2017), 2017, : 345 - 349
  • [8] Cryptanalysis of 'An Improved Remote Password Authentication Scheme with Smartcard'
    Khan, Muhammad Khurram
    He, Debiao
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 1708 - 1710
  • [9] Remote User Authentication Scheme A comparative analysis and improved behavioral biometrics based authentication scheme
    Kumar, Pramod
    Rauthan, Manmohan Singh
    2016 INTERNATIONAL CONFERENCE ON MICRO-ELECTRONICS AND TELECOMMUNICATION ENGINEERING (ICMETE), 2016, : 311 - 313
  • [10] A Secure User Anonymity-Preserving Biometrics and PUF-Based Multiserver Authentication Scheme With Key Agreement in 5G Networks
    Xu, Deqin
    Bian, Weixin
    Li, Qingde
    Xie, Dong
    Zhao, Jun
    Hu, Yao
    IEEE INTERNET OF THINGS JOURNAL, 2025, 12 (05): : 5170 - 5184