首页> 美国卫生研究院文献>other >A Robust and Effective Smart-Card-Based Remote User Authentication Mechanism Using Hash Function
【2h】

A Robust and Effective Smart-Card-Based Remote User Authentication Mechanism Using Hash Function

机译:基于哈希函数的鲁棒有效的基于智能卡的远程用户身份验证机制

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

In a remote user authentication scheme, a remote server verifies whether a login user is genuine and trustworthy, and also for mutual authentication purpose a login user validates whether the remote server is genuine and trustworthy. Several remote user authentication schemes using the password, the biometrics, and the smart card have been proposed in the literature. However, most schemes proposed in the literature are either computationally expensive or insecure against several known attacks. In this paper, we aim to propose a new robust and effective password-based remote user authentication scheme using smart card. Our scheme is efficient, because our scheme uses only efficient one-way hash function and bitwise XOR operations. Through the rigorous informal and formal security analysis, we show that our scheme is secure against possible known attacks. We perform the simulation for the formal security analysis using the widely accepted AVISPA (Automated Validation Internet Security Protocols and Applications) tool to ensure that our scheme is secure against passive and active attacks. Furthermore, our scheme supports efficiently the password change phase always locally without contacting the remote server and correctly. In addition, our scheme performs significantly better than other existing schemes in terms of communication, computational overheads, security, and features provided by our scheme.
机译:在远程用户身份验证方案中,远程服务器会验证登录用户是否真实可信,并且出于相互身份验证的目的,登录用户会验证远程服务器是否真实可信。文献中已经提出了几种使用密码,生物特征识别和智能卡的远程用户认证方案。但是,文献中提出的大多数方案要么计算量大,要么对几种已知的攻击都不安全。在本文中,我们旨在提出一种新的,健壮且有效的基于密码的智能卡远程用户身份验证方案。我们的方案是有效的,因为我们的方案仅使用有效的单向哈希函数和按位XOR运算。通过严格的非正式和正式安全性分析,我们证明了我们的方案对于可能的已知攻击是安全的。我们使用广泛接受的AVISPA(自动验证Internet安全协议和应用程序)工具对正式的安全性分析进行仿真,以确保我们的方案能够抵御被动和主动攻击。此外,我们的方案始终在本地有效地支持密码更改阶段,而无需正确地联系远程服务器。另外,我们的方案在通信,计算开销,安全性和我们的方案提供的功能方面,都比其他现有方案有更好的性能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号