Cryptanalysis and improvement on anonymous three-factor authentication scheme for mobile networks. (April 2017)
- Record Type:
- Journal Article
- Title:
- Cryptanalysis and improvement on anonymous three-factor authentication scheme for mobile networks. (April 2017)
- Main Title:
- Cryptanalysis and improvement on anonymous three-factor authentication scheme for mobile networks
- Authors:
- Xie, Qi
Tang, Zhixiong
Chen, Kefei - Abstract:
- Highlights: We found that Wu et al.'s three-factor authentication scheme cannot resist impersonation attack. Using a random nonce to de/encrypt the transmitted messages of the proposed scheme guarantee both efficiency and secrecy. We use pi calculus based formal verification tool ProVerif to prove authentication and security of the proposed protocol. The proposed protocol achieves optimal computational efficiency for anonymous three-factor authentication protocol with perfect forward secrecy. Abstract: User authentication protocol is an important security mechanism for mobile networks. Recently, Wu et al. proposed a biometrics-based three-factor user authentication scheme using elliptic curve cryptography for mobile networks. However, in this paper, we find out that their scheme is vulnerable to the impersonation attack, because de/encryption key of the server and the user can be computed by an adversary. And then an improved three-factor authentication scheme for mobile client-server networks is proposed to overcome the weakness. The proposed scheme uses a random nonce to decrypt and encrypt messages without using the server's public key for reducing computation cost and avoiding the key management problem, and it also achieves user's anonymity. In addition, we apply the pi calculus-based formal verification tool ProVerif for security evaluations, and compare our scheme with some related schemes to show that the proposed scheme is both secure and efficient. GraphicalHighlights: We found that Wu et al.'s three-factor authentication scheme cannot resist impersonation attack. Using a random nonce to de/encrypt the transmitted messages of the proposed scheme guarantee both efficiency and secrecy. We use pi calculus based formal verification tool ProVerif to prove authentication and security of the proposed protocol. The proposed protocol achieves optimal computational efficiency for anonymous three-factor authentication protocol with perfect forward secrecy. Abstract: User authentication protocol is an important security mechanism for mobile networks. Recently, Wu et al. proposed a biometrics-based three-factor user authentication scheme using elliptic curve cryptography for mobile networks. However, in this paper, we find out that their scheme is vulnerable to the impersonation attack, because de/encryption key of the server and the user can be computed by an adversary. And then an improved three-factor authentication scheme for mobile client-server networks is proposed to overcome the weakness. The proposed scheme uses a random nonce to decrypt and encrypt messages without using the server's public key for reducing computation cost and avoiding the key management problem, and it also achieves user's anonymity. In addition, we apply the pi calculus-based formal verification tool ProVerif for security evaluations, and compare our scheme with some related schemes to show that the proposed scheme is both secure and efficient. Graphical abstract: … (more)
- Is Part Of:
- Computers & electrical engineering. Volume 59(2017)
- Journal:
- Computers & electrical engineering
- Issue:
- Volume 59(2017)
- Issue Display:
- Volume 59, Issue 2017 (2017)
- Year:
- 2017
- Volume:
- 59
- Issue:
- 2017
- Issue Sort Value:
- 2017-0059-2017-0000
- Page Start:
- 218
- Page End:
- 230
- Publication Date:
- 2017-04
- Subjects:
- Three-factor -- Authentication -- Mobile networks -- Anonymity
Computer engineering -- Periodicals
Electrical engineering -- Periodicals
Electrical engineering -- Data processing -- Periodicals
Ordinateurs -- Conception et construction -- Périodiques
Électrotechnique -- Périodiques
Électrotechnique -- Informatique -- Périodiques
Computer engineering
Electrical engineering
Electrical engineering -- Data processing
Periodicals
Electronic journals
621.302854 - Journal URLs:
- http://www.sciencedirect.com/science/journal/00457906/ ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.compeleceng.2016.11.038 ↗
- Languages:
- English
- ISSNs:
- 0045-7906
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.680000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 233.xml