Abstract

With the security requirements of networks, biometrics authenticated schemes which are applied in the multi-server environment come to be more crucial and widely deployed. In this paper, we propose a novel biometric-based multi-server authentication and key agreement scheme which is based on the cryptanalysis of Mishra et al.’s scheme. The informal and formal security analysis of our scheme are given, which demonstrate that our scheme satisfies the desirable security requirements. The presented scheme provides a variety of significant functionalities, in which some features are not considered in the most of existing authentication schemes, such as, user revocation or re-registration and biometric information protection. Compared with several related schemes, our scheme has more secure properties and lower computation cost. It is obviously more appropriate for practical applications in the remote distributed networks.

Highlights

  • With the rapid development of Internet, advances in the information and communication technology enhance the quality of online services for distributed networks, which provide the highly useful services to users in a variety of aspects, such as online medicine, online education, online shopping and internet banking [1, 2]

  • A user anonymity-preserving biometric-based multi-server authenticated key agreement scheme using smart cards is proposed by Mishra et al [53], which is applicable for expert systems to achieve the anonymous authentication in multi-server environment

  • Based on the cryptanalysis of Mishra et al.’s scheme, we present a novel robust biometric-based multi-server authentication and key agreement scheme which consists of six phases: server registration phase, user registration phase, login phase, authentication phase, password change phase and revocation/re-registration phase

Read more

Summary

OPEN ACCESS

With the security requirements of networks, biometrics authenticated schemes which are applied in the multi-server environment come to be more crucial and widely deployed. We propose a novel biometric-based multi-server authentication and key agreement scheme which is based on the cryptanalysis of Mishra et al.’s scheme. Compared with several related schemes, our scheme has more secure properties and lower computation cost. It is obviously more appropriate for practical applications in the remote distributed networks.

Introduction
Cryptanalysis and Improvement of an Authenticated Key Agreement Scheme
Threat assumptions
Fuzzy extractor
Server registration phase
User registration phase
Login phase
Authentication phase
Password change phase
Masquerade attack
Replay attack
No perfect forward secrecy
The proposed scheme
Analysis of our scheme
Informal security analysis
Formal security analysis
Functionality analysis
Efficiency analysis
No Yes No No Yes Yes No No Yes Yes Yes
Yes Yes Yes Yes Yes Yes
Conclusion
Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call