首页> 外文会议>10th IEEE International Conference on Computer and Information Technology >A Novel Dynamic ID-based Remote User Authentication and Access Control Scheme for Multi-server Environment
【24h】

A Novel Dynamic ID-based Remote User Authentication and Access Control Scheme for Multi-server Environment

机译:一种新的基于动态ID的多服务器环境远程用户身份验证和访问控制方案

获取原文

摘要

Since the number of server providing the facilities for users is usually more than one, remote user authentication schemes used for multi-server architectures, rather than single server circumstance, is considered. In 2007, Liao and Wang proposed a ȁC;secure dynamic ID based remote user authentication scheme for multi-server environmentȁD; that uses dynamic ID instead of static ID to achieve userȁ9;s anonymity for verifying the legitimacy of a remote login user. In this paper, we analyze their protocol and demonstrate that it cannot achieve true anonymity and has some other weaknesses. We further propose the improvements to avoid those security problems. Besides user privacy, the key features of our scheme are including no verification table, freely chosen password, mutual authentication, low computation and communication cost, single registration, session key agreement, access control, and being secure against the related attacks.
机译:由于为用户提供便利的服务器数量通常不止一个,因此考虑了用于多服务器体系结构而不是单服务器环境的远程用户身份验证方案。 2007年,Liao和Wang提出了一种“ C;基于安全动态ID的多服务器环境远程用户身份验证方案”D。使用动态ID代替静态ID来实现用户9分;匿名用于验证远程登录用户的合法性。在本文中,我们分析了他们的协议,并证明了该协议无法实现真正​​的匿名性并存在其他一些弱点。我们进一步提出了改进措施以避免这些安全问题。除了用户隐私之外,我们的方案的关键功能还包括:没有验证表,自由选择的密码,相互认证,低计算和通信成本,单次注册,会话密钥协议,访问控制以及对相关攻击的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号