首页> 外文期刊>International journal of communication systems >A provable and secure mobile user authentication scheme for mobile cloud computing services
【24h】

A provable and secure mobile user authentication scheme for mobile cloud computing services

机译:用于移动云计算服务的可证明且安全的移动用户身份验证方案

获取原文
获取原文并翻译 | 示例
       

摘要

The mobile cloud computing (MCC) has enriched the quality of services that the clients access from remote cloud-based servers. The growth in the number of wireless users for MCC has further augmented the requirement for a robust and efficient authenticated key agreement mechanism. Formerly, the users would access cloud services from various cloud-based service providers and authenticate one another only after communicating with the trusted third party (TTP). This requirement for the clients to access the TTP during each mutual authentication session, in earlier schemes, contributes to the redundant latency overheads for the protocol. Recently, Tsai et al have presented a bilinear pairing based multi-server authentication (MSA) protocol, to bypass the TTP, at least during mutual authentication. The scheme construction works fine, as far as the elimination of TTP involvement for authentication has been concerned. However, Tsai et al scheme has been found vulnerable to server spoofing attack and desynchronization attack, and lacks smart card-based user verification, which renders the protocol inapt for practical implementation in different access networks. Hence, we have proposed an improved model designed with bilinear pairing operations, countering the identified threats as posed to Tsai scheme. Additionally, the proposed scheme is backed up by performance evaluation and formal security analysis.
机译:移动云计算(MCC)丰富了客户端从基于远程云的服务器访问的服务的质量。 MCC的无线用户数量的增长进一步增加了对健壮和有效的认证密钥协商机制的需求。以前,用户只有在与受信任的第三方(TTP)通信之后,才能从各种基于云的服务提供商访问云服务并进行相互身份验证。在较早的方案中,客户端在每个相互身份验证会话期间访问TTP的这种要求导致了协议的冗余等待时间开销。最近,Tsai等人提出了一种基于双线性配对的多服务器身份验证(MSA)协议,至少在相互身份验证期间绕过了TTP。就消除认证涉及的TTP而言,该方案的建设工作良好。然而,Tsai等人的方案已经发现容易受到服务器欺骗攻击和失步攻击的攻击,并且缺乏基于智能卡的用户验证,这使得该协议不适合在不同的接入网络中实际实施。因此,我们提出了一种采用双线性配对操作设计的改进模型,以应对对Tsai方案造成的已识别威胁。此外,通过性能评估和正式的安全分析来支持所提出的方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号