首页> 外文会议>International Conference on Information Networking >Cryptanalysis of an anonymous multi-server authenticated key agreement scheme using smart cards and biometrics
【24h】

Cryptanalysis of an anonymous multi-server authenticated key agreement scheme using smart cards and biometrics

机译:使用智能卡和生物识别技术的匿名多服务器身份验证密钥协商方案的密码分析

获取原文

摘要

With the growing popularity of network applications, multi-server architectures are becoming an essential part of heterogeneous networks and numerous security mechanisms have been widely studied in recent years. To protect sensitive information and restrict the access of precious services for legal privileged users only, smart card and biometrics based password authentication schemes have been widely utilized for various transaction-oriented environments. In 2014, Chuang and Chen proposed an anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards, password, and biometrics. They claimed that their three-factor scheme achieves better efficiency and security as compared to those for other existing biometrics-based and multi-server schemes. Unfortunately, in this paper, we found that the user anonymity of Chuang-Chen's authentication scheme cannot be protected from an eavesdropping attack during authentication phase. Moreover, their scheme is vulnerable to smart card lost problems, many logged-in users' attacks and denial-of-service attacks and is not easily reparable.
机译:随着网络应用程序的日益普及,多服务器体系结构已成为异构网络的重要组成部分,并且近年来对许多安全机制进行了广泛的研究。为了保护敏感信息并仅限制合法特权用户访问珍贵服务,基于智能卡和生物识别的密码认证方案已广泛用于各种面向交易的环境。 2014年,Chuang和Chen提出了一种使用智能卡,密码和生物识别技术的基于信任计算的匿名多服务器身份验证密钥协议方案。他们声称,与其他现有的基于生物特征识别和多服务器的方案相比,他们的三因素方案实现了更好的效率和安全性。不幸的是,在本文中,我们发现,在身份验证阶段,不能保护Chuang-Chen身份验证方案的用户匿名性免受窃听攻击。而且,他们的方案容易受到智能卡丢失问题,许多登录用户的攻击和拒绝服务攻击的攻击,并且不易修复。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号