首页> 外文期刊>Electrical and Computer Engineering, Canadian Journal of >Secure and Efficient Smart-Card-Based Remote User Authentication Scheme for Multiserver Environment
【24h】

Secure and Efficient Smart-Card-Based Remote User Authentication Scheme for Multiserver Environment

机译:用于多服务器环境的安全高效的基于智能卡的远程用户身份验证方案

获取原文
获取原文并翻译 | 示例
       

摘要

The growth of the Internet and telecommunication technology has facilitated remote access. During the last decade, many secure dynamic identity (ID)-based remote user authentication schemes have been proposed for the multiserver environment using smart cards. Recently, Li point that the Lee scheme is vulnerable to forgery attack, server spoofing attack, improper authentication, and unfriendly and inefficient password change. To overcome these security weaknesses, Li propose a novel smart-card- and dynamic ID-based remote user authentication scheme for multiserver environments. In this paper, we show that the Li scheme is also vulnerable to offline password guessing attack, stolen smart-card attack, forgery attack, and poor reparability. Their scheme does not also provide two-factor security. To provide a secure remote user authentication scheme for the multiserver environment and to overcome the security weaknesses, we propose an enhanced scheme. Our scheme is aimed at logically securing the data stored in the smart card and improving the dynamic property of the ID using password randomization for each session. Our scheme resists forgery attack, replay attack, stolen smart-card attack, offline password guessing attack, and spoofing attack. Our scheme’s efficiency has been established analytically and confirmed through simulation.
机译:互联网和电信技术的发展促进了远程访问。在过去的十年中,已经针对使用智能卡的多服务器环境提出了许多基于安全动态身份(ID)的远程用户身份验证方案。 Li最近指出,Lee方案容易受到伪造攻击,服务器欺骗攻击,不正确的身份验证以及不友好且效率低下的密码更改。为了克服这些安全漏洞,Li提出了一种针对多服务器环境的新颖的基于智能卡和动态ID的远程用户身份验证方案。在本文中,我们表明Li方案还容易受到脱机密码猜测攻击,被盗的智能卡攻击,伪造攻击以及可修复性较差的攻击。他们的方案也不提供两方面的安全性。为了为多服务器环境提供安全的远程用户身份验证方案并克服安全漏洞,我们提出了一种增强方案。我们的方案旨在逻辑上保护存储在智能卡中的数据,并为每个会话使用密码随机化来改善ID的动态属性。我们的方案可抵抗伪造攻击,重播攻击,被盗的智能卡攻击,离线密码猜测攻击和欺骗攻击。我们的方案的效率已通过分析确定,并通过仿真进行了确认。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号