首页> 外文期刊>Wireless personal communications: An Internaional Journal >A Novel Chaotic Maps-Based User Authentication and Key Agreement Protocol for Multi-server Environments with Provable Security
【24h】

A Novel Chaotic Maps-Based User Authentication and Key Agreement Protocol for Multi-server Environments with Provable Security

机译:一种新颖的基于混沌地图的用户验证和密钥协商协议,用于可证明安全性的多服务器环境

获取原文
获取原文并翻译 | 示例
           

摘要

The widespread popularity of the computer networks has triggered concerns about information security. Password-based user authentication with key agreement protocols have drawn attentions since it provides proper authentication of a user before granting access right to services, and then ensure secure communication over insecure channels. Recently, Lee et al. pointed out different security flaws on Tsaur et al.'s multi-server user authentication protocol, and they further proposed an extended chaotic maps-based user authentication with key agreement protocol for multi-server environments. However, we observed that Lee et al.'s protocol has some functionality and security flaws, i.e., it is inefficient in detection of unauthorized login and it does not support password change mechanism. Besides, their protocol is vulnerable to registration center spoofing attack and server spoofing attack. In order to remedy the aforementioned flaws, we proposed a novel chaotic maps-based user authentication with key agreement protocol for multi-server environments. The proposed protocol is provably secure in the random oracle model under the chaotic-maps based computational Diffie-Hellman assumption. In addition, we analyzed our protocol using BAN logic model. We also compared our protocol with Lee et al.'s protocol in aspects of computation cost, functionalities and securities.
机译:计算机网络的广泛普及引发了人们对信息安全的担忧。具有密钥协商协议的基于密码的用户身份验证受到关注,因为它在授予服务访问权限之前提供了对用户的正确身份验证,然后确保通过不安全通道进行安全通信。最近,李等人。指出Tsaur等人的多服务器用户身份验证协议存在不同的安全漏洞,并且他们还针对多服务器环境提出了使用密钥协商协议的扩展的基于混沌映射的用户身份验证。但是,我们观察到Lee等人的协议具有一些功能和安全性缺陷,即,它在检测未授权登录方面效率低下,并且不支持密码更改机制。此外,它们的协议容易受到注册中心欺骗攻击和服务器欺骗攻击的攻击。为了弥补上述缺陷,我们针对多服务器环境提出了一种基于新的基于混沌图的用户认证和密钥协商协议。在基于混沌映射的计算Diffie-Hellman假设下,该随机协议在随机预言机模型中具有可证明的安全性。另外,我们使用BAN逻辑模型分析了我们的协议。我们还在计算成本,功能和证券方面将我们的协议与Lee等人的协议进行了比较。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号