首页 | 本学科首页   官方微博 | 高级检索  
     


Design of a user anonymous password authentication scheme without smart card
Authors:Saru Kumari  Muhammad Khurram Khan  Xiong Li  Fan Wu
Affiliation:1. Department of Mathematics, Agra College, Dr. B. R. A. University, Agra, Uttar Pradesh, India;2. Center of Excellence in Information Assurance, King Saud University, Riyadh, Kingdom of Saudi Arabia;3. School of Computer Science and Engineering, Hunan University of Science and Technology, Xiangtan, China;4. Department of Computer Science and Engineering, Xiamen Institute of Technology, Huaqiao University, Xiamen, China
Abstract:Recently, Jiang et al. and He et al. independently found security problems in Chen et al.'s remote user authentication scheme for non‐tamper‐proof storage devices like Universal Serial Bus stick and proposed improvements. Nonetheless, we detect that the schemes proposed by Jiang et al. and He et al. overlook a user's privacy. We also observe that Jiang et al.'s scheme is vulnerable to insider attack and denial of service attacks and lacks forward secrecy. We point out that the password changing facility in He et al.'s scheme is equivalent to undergoing registration, whereas in Jiang et al.'s scheme, it is unsuitable. Moreover, the login phase of both the schemes is incapable to prevent the use of wrong password leading to the computation of an unworkable login request. Therefore, we design a new scheme with user anonymity to surmount the identified weaknesses. Without adding much in communication/computational cost, our scheme provides more security characteristics and keeps the merits of the original schemes. As compared with its predecessor schemes, the proposed scheme stands out as a more apt user authentication method for common storage devices. We have also presented a formal proof of security of the proposed scheme based on the logic proposed by Burrows, Abadi and Needham (BAN logic). Copyright © 2014 John Wiley & Sons, Ltd.
Keywords:authentication  user anonymity  common storage device  forward secrecy  ineffective login
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号