A novel remote user authentication and key agreement scheme for mobile client-server environment

نویسندگان

  • Haiyan Sun
  • Qiaoyan Wen
  • Hua Zhang
  • Zhengping Jin
چکیده

Recently, many identity (ID)-based user authentication and key agreement schemes for mobile client-server environment were proposed. However, these schemes are subjected to an inherent design weakness, namely, the server knows all users’ private keys. Under this problem, these schemes cannot provide insider attack resistance or mutual authentication. Furthermore, some of these schemes cannot simultaneously provide user anonymity, perfect forward secrecy, or leakage of session temporary secrets resistance. In this paper, we propose a strongly secure remote user authentication and key agreement scheme to solve these security weaknesses. Security proof shows that the proposed scheme can achieve mutual authentication and key agreement, and provide perfect forward secrecy. Further security analysis shows that the proposed scheme can provide user anonymity, insider attack resistance and leakage of session temporary secrets resistance. In addition, the proposed scheme possesses low computation cost and low power consumption. Thus the proposed scheme is more suitable for mobile client-server environment.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Comments on a novel user authentication and key agreement scheme

In 2013, Sun et al. showed that the related works' authentication schemes proposed by [2-7] are vulnerable to an insider attack and fail to provide mutual authentication. These two attacks can be successfully plotted by an adversary, since the private key of the server can compute all the legal users’ private keys. They then proposed a new remote user authentication and key agreement scheme for...

متن کامل

Comments on ID-Based Client Authentication with Key Agreement Protocol on ECC for Mobile Client-Server Environment

In 2011, Debiao et al. proposed an ID-based remote mutual authentication with key agreement scheme on ECC for mobile client–server environment [H. Debiao, C. Jianhua, H. Jin: An ID-based client authentication with key agreement protocol for mobile client–server environment on ECC with provable security, Information Fusion, 2011]. They claimed their scheme provides remote mutual authentication w...

متن کامل

A biometric-based Password Authentication with key Exchange Scheme using Mobile Device for Multi-Server Environment

Remote authentication for multi-server environment can help users register only once and access arbitrary services conveniently in the same registry realm. However, most of the solutions are plagued by security problems. In this paper, we point out that ‘a novel smart card and dynamic ID based remote user authentication scheme for multi-server environment’ is vulnerable to user impersonation at...

متن کامل

A New Secure Mutual Authentication Scheme with Smart Cards Using Bilinear Pairings

Mutual authentication is an important security property for providing secure remote communication in client-server environment. Up to now, various remote user authentication schemes with smart card using bilinear pairings were proposed by different researchers. Unfortunately, most previously proposed authentication schemes do not provide mutual authentication and session key agreement. This pap...

متن کامل

An improved dynamic ID-based remote user authentication with key agreement scheme

In 2011, Lee et al. improved Hsiang et al.'s scheme and proposed a security dynamic ID-based remote user authentication scheme for multi-server environment using smart cards. They claimed that their protocol is efficient and can resist several kinds of known attacks. However, we observe that Lee et al.'s scheme is still vulnerable to stolen smart card attack, malicious server attack. To remedy ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2013