A secure lightweight authentication scheme with user anonymity for roaming service in ubiquitous networks. Issue 17 (14th August 2016)
- Record Type:
- Journal Article
- Title:
- A secure lightweight authentication scheme with user anonymity for roaming service in ubiquitous networks. Issue 17 (14th August 2016)
- Main Title:
- A secure lightweight authentication scheme with user anonymity for roaming service in ubiquitous networks
- Authors:
- Karuppiah, Marimuthu
Kumari, Saru
Das, Ashok Kumar
Li, Xiong
Wu, Fan
Basu, Sayantani - Abstract:
- Abstract: Ubiquitous networks provide effective roaming services for mobile users ( M U s ). Through the worldwide roaming technology, authorized M U s can avail ubiquitous network services. Important security issues to be considered in ubiquitous networks are authentication of roaming M U s and protection of privacy of M U s . However, because of the broadcast nature of wireless channel and resource limitations of terminals, providing efficient user authentication with privacy preservation is a challenging task. Very recently, Farash et al. proposed an authentication scheme with anonymity for consumer roaming in ubiquitous networks and claimed their scheme achieves all security requirements. In this paper, we show that the scheme of Farash et al. fails to achieve user anonymity and mutual authentication. Their scheme also fails to provide local password verification, and it has a faulty password change phase. Moreover, their scheme is vulnerable to replay, offline password guessing, and forgery attacks. To fix the security flaws of the scheme of Farash et al., we present an improved authentication scheme for accessing roaming service provided by ubiquitous networks. We then formally verify the security properties of our scheme by the widely‐accepted push‐button tool called Automated Validation of Internet Security Protocols and Applications. Security and performance analyses show that our scheme is more powerful, efficient, and secure when it is compared with existingAbstract: Ubiquitous networks provide effective roaming services for mobile users ( M U s ). Through the worldwide roaming technology, authorized M U s can avail ubiquitous network services. Important security issues to be considered in ubiquitous networks are authentication of roaming M U s and protection of privacy of M U s . However, because of the broadcast nature of wireless channel and resource limitations of terminals, providing efficient user authentication with privacy preservation is a challenging task. Very recently, Farash et al. proposed an authentication scheme with anonymity for consumer roaming in ubiquitous networks and claimed their scheme achieves all security requirements. In this paper, we show that the scheme of Farash et al. fails to achieve user anonymity and mutual authentication. Their scheme also fails to provide local password verification, and it has a faulty password change phase. Moreover, their scheme is vulnerable to replay, offline password guessing, and forgery attacks. To fix the security flaws of the scheme of Farash et al., we present an improved authentication scheme for accessing roaming service provided by ubiquitous networks. We then formally verify the security properties of our scheme by the widely‐accepted push‐button tool called Automated Validation of Internet Security Protocols and Applications. Security and performance analyses show that our scheme is more powerful, efficient, and secure when it is compared with existing schemes. Copyright © 2016 John Wiley & Sons, Ltd. Abstract : In this paper, we show that the scheme of Farash et al. fails to achieve user anonymity and mutual authentication. Their scheme also fails to provide local password verification, and it has a faulty password change phase. Moreover, their scheme is vulnerable to replay, offline password guessing, and forgery attacks. To fix the security flaws of the scheme of Farash et al., we present an improved authentication scheme for accessing roaming service provided by ubiquitous networks. … (more)
- Is Part Of:
- Security and communication networks. Volume 9:Issue 17(2016)
- Journal:
- Security and communication networks
- Issue:
- Volume 9:Issue 17(2016)
- Issue Display:
- Volume 9, Issue 17 (2016)
- Year:
- 2016
- Volume:
- 9
- Issue:
- 17
- Issue Sort Value:
- 2016-0009-0017-0000
- Page Start:
- 4192
- Page End:
- 4209
- Publication Date:
- 2016-08-14
- Subjects:
- authentication -- ubiquitous networks -- user anonymity -- AVISPA -- security
Computer networks -- Security measures -- Periodicals
Computer security -- Periodicals
Cryptography -- Periodicals
005.805 - Journal URLs:
- http://onlinelibrary.wiley.com/journal/10.1002/(ISSN)1939-0122 ↗
https://www.hindawi.com/journals/scn/ ↗
http://onlinelibrary.wiley.com/ ↗ - DOI:
- 10.1002/sec.1598 ↗
- Languages:
- English
- ISSNs:
- 1939-0114
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library HMNTS - ELD Digital store
- Ingest File:
- 611.xml