首页> 美国卫生研究院文献>other >An improved anonymous authentication scheme for roaming in ubiquitous networks
【2h】

An improved anonymous authentication scheme for roaming in ubiquitous networks

机译:一种改进的匿名认证机制可在无处不在的网络中漫游

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

With the evolution of communication technology and the exponential increase of mobile devices, the ubiquitous networking allows people to use our data and computing resources anytime and everywhere. However, numerous security concerns and complicated requirements arise as these ubiquitous networks are deployed throughout people’s lives. To meet the challenge, the user authentication schemes in ubiquitous networks should ensure the essential security properties for the preservation of the privacy with low computational cost. In 2017, Chaudhry et al. proposed a password-based authentication scheme for the roaming in ubiquitous networks to enhance the security. Unfortunately, we found that their scheme remains insecure in its protection of the user privacy. In this paper, we prove that Chaudhry et al.’s scheme is vulnerable to the stolen-mobile device and user impersonation attacks, and its drawbacks comprise the absence of the incorrect login-input detection, the incorrectness of the password change phase, and the absence of the revocation provision. Moreover, we suggest a possible way to fix the security flaw in Chaudhry et al’s scheme by using the biometric-based authentication for which the bio-hash is applied in the implementation of a three-factor authentication. We prove the security of the proposed scheme with the random oracle model and formally verify its security properties using a tool named ProVerif, and analyze it in terms of the computational and communication cost. The analysis result shows that the proposed scheme is suitable for resource-constrained ubiquitous environments.
机译:随着通信技术的发展和移动设备的迅猛增长,无处不在的网络使人们可以随时随地使用我们的数据和计算资源。但是,随着这些无处不在的网络被部署到人们的生活中,随之而来的是许多安全问题和复杂的要求。为了应对这一挑战,无处不在的网络中的用户身份验证方案应确保基本的安全属性,以较低的计算成本来保护隐私。在2017年,Chaudhry等人为了提高安全性,提出了一种基于密码的身份验证方案,用于在无处不在的网络中漫游。不幸的是,我们发现他们的方案在保护用户隐私方面仍然不安全。在本文中,我们证明了Chaudhry等人的方案容易受到被盗的移动设备和用户假冒攻击的侵害,其缺点包括缺少错误的登录输入检测,密码更改阶段的不正确以及没有撤销规定。此外,我们提出了一种可行的方法,可以通过使用基于生物特征的身份验证来解决Chaudhry等人方案中的安全漏洞,为此,将生物哈希应用于三因素身份验证。我们使用随机预言机模型证明了该方案的安全性,并使用名为ProVerif的工具正式验证了其安全性,并从计算和通信成本方面对其进行了分析。分析结果表明,该方案适用于资源受限的泛在环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号