Understanding security failures of multi-factor authentication schemes for multi-server environments. Issue 88 (January 2020)
- Record Type:
- Journal Article
- Title:
- Understanding security failures of multi-factor authentication schemes for multi-server environments. Issue 88 (January 2020)
- Main Title:
- Understanding security failures of multi-factor authentication schemes for multi-server environments
- Authors:
- Wang, Ding
Zhang, Xizhe
Zhang, Zijian
Wang, Ping - Abstract:
- Highlights: We demonstrate concrete attacks on five foremost multi-factor authentication schemes. Attacks arising from malicious insiders are realistic. Attacks arising from the leakage of session-specific parameters are damaging. We point out the underlying reasons for the identified security flaws. We draw some useful lessons from the cryptanalysis results. Abstract: Revealing the security flaws of existing cryptographic protocols is the key to understanding how to achieve better security. Dozens of multi-factor authentication schemes for multi-server environments were successively proposed, yet most of them have been shortly found problematic. The research pattern of this area has fallen into the undesirable "break-fix-break-fix" cycle, in which lots of efforts have been devoted but little real progress has been made. In this paper, we revisit five leading two-factor authentication schemes for multi-server environments (i.e., Xu et al. scheme at ICICS'17, Wu et al. scheme at FC'17, Leu-Hsieh's scheme at IET IS'14, Zhou et al. scheme at WINET'18 and Roy et al. scheme at IEEE TII'19), and demonstrate that all of them suffer from critical security defects (e.g., no truly multi-factor security and temporary information leakage attack) or are short of important properties (e.g., no user anonymity). Our results invalidate any use of these five schemes for practical applications without further improvement, and underscore some new challenges (e.g., attacks arising from theHighlights: We demonstrate concrete attacks on five foremost multi-factor authentication schemes. Attacks arising from malicious insiders are realistic. Attacks arising from the leakage of session-specific parameters are damaging. We point out the underlying reasons for the identified security flaws. We draw some useful lessons from the cryptanalysis results. Abstract: Revealing the security flaws of existing cryptographic protocols is the key to understanding how to achieve better security. Dozens of multi-factor authentication schemes for multi-server environments were successively proposed, yet most of them have been shortly found problematic. The research pattern of this area has fallen into the undesirable "break-fix-break-fix" cycle, in which lots of efforts have been devoted but little real progress has been made. In this paper, we revisit five leading two-factor authentication schemes for multi-server environments (i.e., Xu et al. scheme at ICICS'17, Wu et al. scheme at FC'17, Leu-Hsieh's scheme at IET IS'14, Zhou et al. scheme at WINET'18 and Roy et al. scheme at IEEE TII'19), and demonstrate that all of them suffer from critical security defects (e.g., no truly multi-factor security and temporary information leakage attack) or are short of important properties (e.g., no user anonymity). Our results invalidate any use of these five schemes for practical applications without further improvement, and underscore some new challenges (e.g., attacks arising from the leakage of session-specific parameters and from malicious insiders) in designing sound multi-factor schemes for multi-server environments. We also draw some useful lessons from the cryptanalysis results. … (more)
- Is Part Of:
- Computers & security. Issue 88(2020)
- Journal:
- Computers & security
- Issue:
- Issue 88(2020)
- Issue Display:
- Volume 88, Issue 88 (2020)
- Year:
- 2020
- Volume:
- 88
- Issue:
- 88
- Issue Sort Value:
- 2020-0088-0088-0000
- Page Start:
- Page End:
- Publication Date:
- 2020-01
- Subjects:
- Multi-factor authentication -- Password -- User anonymity -- Smart card loss attack -- Multi-factor security -- Forward secrecy
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2019.101619 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 16306.xml