Security Enhancement of an Improved Remote User Authentication Scheme with Key Agreement
Autor: | Sonam Devgan Kaul, Amit K. Awasthi |
---|---|
Rok vydání: | 2016 |
Předmět: |
Challenge-Handshake Authentication Protocol
Password Computer science business.industry Generic Security Service Algorithm for Secret Key Transaction 020206 networking & telecommunications 02 engineering and technology Mutual authentication Adversary Computer security computer.software_genre Computer Science Applications 3-D Secure Secure communication Authentication protocol 0202 electrical engineering electronic engineering information engineering Session key 020201 artificial intelligence & image processing Smart card Electrical and Electronic Engineering Challenge–response authentication business computer Data Authentication Algorithm |
Zdroj: | Wireless Personal Communications. 89:621-637 |
ISSN: | 1572-834X 0929-6212 |
DOI: | 10.1007/s11277-016-3297-6 |
Popis: | In 2014, Kumari, Khan and Li proposed smart card based secure and robust remote user authentication scheme with key agreement and claimed that their scheme is suitable, secure and efficient for real life applications. But in this paper, we demonstrate that their proposed mechanism is completely insecure as an adversary can easily obtain not only the security parameters of the protocol but also obtains the common session key of future communication between user and the server. In addition, an adversary gets password of the registered user as well as secret key of the server. Thus collapses the entire system and authors claims are proven to be wrong. Hence, to remedy the identified security flaws and to ensure secure communication through an insecure channel, we propose an upgraded secure and efficient authentication protocol. Furthermore, we verify the security of our authentication protocol informally as well as formally via widely accepted OFMC and CL-AtSe back-ends of AVISPA tool against active and passive attacks. |
Databáze: | OpenAIRE |
Externí odkaz: |