An improved lightweight multiserver authentication scheme. (4th July 2017)
- Record Type:
- Journal Article
- Title:
- An improved lightweight multiserver authentication scheme. (4th July 2017)
- Main Title:
- An improved lightweight multiserver authentication scheme
- Authors:
- Irshad, Azeem
Chaudhry, Shehzad Ashraf
Kumari, Saru
Usman, Muhammad
Mahmood, Khalid
Faisal, Muhammad Shahzad - Abstract:
- Summary: Multiserver authentication complies with the up‐to‐date requirements of Internet services and latest applications. The multiserver architecture enables the expedient authentication of subscribers on an insecure channel for the delivery of services. The users rely on a single registration of a trusted third party for the procurement of services from various servers. Recently, Chen and Lee, Moon et al, and Wang et al presented multiserver key agreement schemes that are found to be vulnerable to many attacks according to our analysis. The Chen and Lee scheme was found susceptible to impersonation attack, trace attack, stolen smart card attack exposing session key, key‐compromise impersonation attack, and inefficient password modification. The Moon et al is susceptible to stolen card attack leading to further attacks, ie, identity guessing, key‐compromise impersonation attack, user impersonation attack, and session keys disclosure, while Wang et al is also found to be prone to trace attack, session‐specific temporary information attack, key‐compromise information attack, and privileged insider attack leading to session key disclosure and user impersonation attacks. We propose an improved protocol countering the indicated weaknesses of these schemes in an equivalent cost. Our scheme demonstrates automated and security analysis on the basis of Burrows‐Abadi‐Needham logic and also presents the performance evaluation for related schemes. Abstract : We have proposed anSummary: Multiserver authentication complies with the up‐to‐date requirements of Internet services and latest applications. The multiserver architecture enables the expedient authentication of subscribers on an insecure channel for the delivery of services. The users rely on a single registration of a trusted third party for the procurement of services from various servers. Recently, Chen and Lee, Moon et al, and Wang et al presented multiserver key agreement schemes that are found to be vulnerable to many attacks according to our analysis. The Chen and Lee scheme was found susceptible to impersonation attack, trace attack, stolen smart card attack exposing session key, key‐compromise impersonation attack, and inefficient password modification. The Moon et al is susceptible to stolen card attack leading to further attacks, ie, identity guessing, key‐compromise impersonation attack, user impersonation attack, and session keys disclosure, while Wang et al is also found to be prone to trace attack, session‐specific temporary information attack, key‐compromise information attack, and privileged insider attack leading to session key disclosure and user impersonation attacks. We propose an improved protocol countering the indicated weaknesses of these schemes in an equivalent cost. Our scheme demonstrates automated and security analysis on the basis of Burrows‐Abadi‐Needham logic and also presents the performance evaluation for related schemes. Abstract : We have proposed an authentication scheme for multiserver environment resistant to various security threats exhibited in the previous related literature. The computational/communication cost of the proposed scheme is equivalent to that of some previous schemes susceptible to threats. We demonstrate the security of our scheme using ProVerif automated tool and Burrows‐Abadi‐Needham logic. The performance evaluation with related schemes shows the robustness of our scheme. … (more)
- Is Part Of:
- International journal of communication systems. Volume 30:Number 17(2017)
- Journal:
- International journal of communication systems
- Issue:
- Volume 30:Number 17(2017)
- Issue Display:
- Volume 30, Issue 17 (2017)
- Year:
- 2017
- Volume:
- 30
- Issue:
- 17
- Issue Sort Value:
- 2017-0030-0017-0000
- Page Start:
- n/a
- Page End:
- n/a
- Publication Date:
- 2017-07-04
- Subjects:
- attacks -- biometrics -- multiserver authentication -- remote authentication
Telecommunication systems -- Periodicals
621.382 - Journal URLs:
- http://onlinelibrary.wiley.com/ ↗
- DOI:
- 10.1002/dac.3351 ↗
- Languages:
- English
- ISSNs:
- 1074-5351
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4542.172515
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 5366.xml