首页> 外文会议>International Conference on Cloud Computing and Security >Cryptanalysis and Improvement of a Smart Card Based Mutual Authentication Scheme in Cloud Computing
【24h】

Cryptanalysis and Improvement of a Smart Card Based Mutual Authentication Scheme in Cloud Computing

机译:云计算中基于智能卡的相互认证方案的密码分析和改进

获取原文

摘要

Cloud computing enables the users to access and share the data as and when required at anytime from anywhere. Due to its open access, one of the major issues faced by cloud computing is how to prevent the outsourced data from being leaked to unauthorized users. Therefore, mutual authentication between the user and the cloud service provider is a necessity to ensure that sensitive data in the cloud are not available to illegal users. Recently, Li et al. proposed a two-factor authentication protocol based on elliptic curve cryp-tosystem which enables the cloud users to access their outsourced data. However, we first show that their scheme suffers from the problem of wrong password login. Secondly, their scheme is prone to denial of service attack in the password-changing phase. Thirdly, it fails to provide user revocation when the smart card is lost or stolen. To remedy these flaws, we propose an improved two-factor authentication and key agreement protocol, which not only guards various known attacks, but also provides more desired security properties.
机译:云计算使用户可以随时随地根据需要访问和共享数据。由于其开放式访问,云计算面临的主要问题之一是如何防止外包数据泄露给未经授权的用户。因此,用户和云服务提供商之间的相互认证是确保非法用户无法使用云中的敏感数据的必要条件。最近,李等人。提出了一种基于椭圆曲线Cryp-tosystem的两因素身份验证协议,该协议使云用户可以访问其外包数据。但是,我们首先表明,他们的方案存在密码登录错误的问题。其次,他们的方案在密码更改阶段容易遭到拒绝服务攻击。第三,当智能卡丢失或被盗时,它无法为用户提供撤销服务。为了纠正这些缺陷,我们提出了一种改进的两因素身份验证和密钥协商协议,该协议不仅可以防御各种已知的攻击,而且还可以提供更多所需的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号