Skip to main navigation Skip to search Skip to main content

A robust anonymous biometric-based authenticated key agreement scheme for multi-server environments

  • Hua Guo
  • , Pei Wang
  • , Xiyong Zhang*
  • , Yuanfei Huang
  • , Fangchao Ma
  • *Corresponding author for this work
  • Beihang University
  • National Computer Network Emergency Response Technical Team/Coordination Center of China
  • State Key Laboratory of Space-Ground Integrated Information Technology
  • Beijing Information Technology Institute

Research output: Contribution to journalArticlepeer-review

Abstract

In order to improve the security in remote authentication systems, numerous biometric-based authentication schemes using smart cards have been proposed. Recently, Moon et al. presented an authentication scheme to remedy the flaws of Lu et al.’s scheme, and claimed that their improved protocol supports the required security properties. Unfortunately, we found that Moon et al.’s scheme still has weaknesses. In this paper, we show that Moon et al.’s scheme is vulnerable to insider attack, server spoofing attack, user impersonation attack and guessing attack. Furthermore, we propose a robust anonymous multi-server authentication scheme using public key encryption to remove the aforementioned problems. From the subsequent formal and informal security analysis, we demonstrate that our proposed scheme provides strong mutual authentication and satisfies the desirable security requirements. The functional and performance analysis shows that the improved scheme has the best secure functionality and is computational efficient.

Original languageEnglish
Article numbere0187403
JournalPLOS ONE
Volume12
Issue number11
DOIs
StatePublished - Nov 2017

Fingerprint

Dive into the research topics of 'A robust anonymous biometric-based authenticated key agreement scheme for multi-server environments'. Together they form a unique fingerprint.

Cite this