首页> 外文期刊>Wireless personal communications: An Internaional Journal >Analysis and Improvement on a Biometric-Based Remote User Authentication Scheme Using Smart Cards
【24h】

Analysis and Improvement on a Biometric-Based Remote User Authentication Scheme Using Smart Cards

机译:基于智能卡的基于生物识别的远程用户身份验证方案的分析和改进

获取原文
获取原文并翻译 | 示例
       

摘要

In a recent paper (BioMed Research International, 2013/491289), Khan et al. proposed an improved biometrics-based remote user authentication scheme with user anonymity. The scheme is believed to be secure against password guessing attack, user impersonation attack, server masquerading attack, and provide user anonymity, even if the secret information stored in the smart card is compromised. In this paper, we analyze the security of Khan et al.'s scheme, and demonstrate that their scheme doesn't provide user anonymity. This also renders that their scheme is insecure against other attacks, such as off-line password guessing attack, user impersonation attacks. Subsequently, we propose a robust biometric-based remote user authentication scheme. Besides, we simulate our scheme for the formal security verification using the wide-accepted BAN logic to ensure our scheme is working correctly by achieving the mutual authentication goals.
机译:Khan等人在最近的一篇论文中(国际生物医学研究,2013/491289)。提出了一种改进的基于生物特征的具有用户匿名的远程用户认证方案。即使存储在智能卡中的机密信息遭到破坏,该方案也可以抵御密码猜测攻击,用户模拟攻击,服务器伪装攻击并提供用户匿名性。在本文中,我们分析了Khan等人的方案的安全性,并证明了他们的方案没有提供用户匿名性。这也使他们的方案无法抵抗其他攻击,例如离线密码猜测攻击,用户模拟攻击。随后,我们提出了一个强大的基于生物特征的远程用户身份验证方案。此外,我们使用广泛接受的BAN逻辑对我们用于正式安全验证的方案进行仿真,以确保我们的方案通过实现相互认证目标而正常工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号