首页> 外文期刊>Journal of computational and theoretical nanoscience >Secure Smart Card Based Remote User Authentication Scheme for Multi-Server Environment to Eliminate Smart Card Security Breach
【24h】

Secure Smart Card Based Remote User Authentication Scheme for Multi-Server Environment to Eliminate Smart Card Security Breach

机译:基于安全卡的远程用户身份验证方案,用于多服务器环境消除智能卡安全漏洞

获取原文
获取原文并翻译 | 示例
       

摘要

Remote user authentication technique based on smart card is a simple two-factor authentication technique that ensures secured access through insecure channels. Many smart card based remote user authentication schemes for single server and multi-server environments are proposed. In thispaper, we focus on the remote user authentication scheme for the multi-server environment. Recently, Banerjee et al. analyze the capability of Li et al. scheme and find out that it is vulnerable to stolen smart card and user impersonate attack. Banerjee et al. propose a new scheme and claimthat their scheme provides protection against various attacks. Braeken's analysis on Banerjee et al. shows that the scheme is not resistant to insider attack and also does not provide perfect forward secrecy. Our analysis on Braeken scheme shows that it is susceptible to impersonation attack,provides poor reparability and has no strong two factor security. Our analysis on these schemes shows that various attacks are possible as few parameters are insecurely stored in the smart card and are directly used in authentication phases. The dynamic property imposed in these schemes isbased on a random number—nonce and this is either passed as plaintext or hidden by known parameters. We propose a new remote user multi-server authentication scheme based on Diffie-Hellman problem (DHP) and the one-way hash function to provide security to the data when transmitted. Ourscheme fulfills the requirements of the multi-server authentication scheme and provides secure communication.
机译:基于智能卡的远程用户身份验证技术是一种简单的双因子认证技术,可确保通过不安全通道进行安全访问。提出了许多基于智能卡的单服务器和多服务器环境的远程用户身份验证方案。在此纸纸中,我们专注于多服务器环境的远程用户身份验证方案。最近,Banerjee等人。分析Li等人的能力。方案并发现它很容易被盗智能卡和用户模拟攻击。 Banerjee等人。提出了一个新的计划,并要求他们的计划提供针对各种攻击的保护。 Brahaeken对Banerjee等人的分析。表明该方案不抵抗内幕攻击,也没有提供完美的前锋保密。我们对Brahaken方案的分析表明,它易于冒充攻击,提供了差的可盈可力,并没有强有力的两个因素安全性。我们对这些方案的分析表明,只要少量参数不确定地存储在智能卡中,各种攻击是可能的,并且直接用于身份验证阶段。在这些方案中施加的动态属性在随机数 - 随机数上被缩小,这是通过被明文或通过已知参数隐藏的。我们提出了一种基于Diffie-Hellman问题(DHP)的新的远程用户多服务器认证方案和单向哈希函数,以在传输时向数据提供安全性。 OuScheme满足多服务器认证方案的要求,并提供安全通信。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号