TY - JOUR
T1 - An Enhancement of a Smart Card Authentication Scheme for Multi-server Architecture
AU - Li, Xiong
AU - Niu, Jianwei
AU - Kumari, Saru
AU - Liao, Junguo
AU - Liang, Wei
N1 - Publisher Copyright:
© 2014, Springer Science+Business Media New York.
PY - 2015/1
Y1 - 2015/1
N2 - User authentication is an important security issue for network based services. Multi-server authentication scheme resolves the repeated registration problem of single-server authentication scenario where the user has to register at different servers to access different types of network services. Recently, Pippal et al. proposed a smart card authentication scheme for multi-server architecture. They claimed that their scheme has some advantages and can resist kinds of attacks. However, we find their scheme cannot provide correct authentication, cannot resist impersonation attack, stolen smart card attack, and insider attack. Besides, their scheme is non-extensible when a new server added into the system. In order to overcome the aforementioned weaknesses of Pippal et al.’s scheme, we propose an improved smart card authentication scheme for multi-server architecture. We analyze the security of the proposed scheme using BAN logic, and the analysis result shows that the proposed scheme is more efficient and secure than Pippal et al.’s scheme.
AB - User authentication is an important security issue for network based services. Multi-server authentication scheme resolves the repeated registration problem of single-server authentication scenario where the user has to register at different servers to access different types of network services. Recently, Pippal et al. proposed a smart card authentication scheme for multi-server architecture. They claimed that their scheme has some advantages and can resist kinds of attacks. However, we find their scheme cannot provide correct authentication, cannot resist impersonation attack, stolen smart card attack, and insider attack. Besides, their scheme is non-extensible when a new server added into the system. In order to overcome the aforementioned weaknesses of Pippal et al.’s scheme, we propose an improved smart card authentication scheme for multi-server architecture. We analyze the security of the proposed scheme using BAN logic, and the analysis result shows that the proposed scheme is more efficient and secure than Pippal et al.’s scheme.
KW - Authentication
KW - BAN logic
KW - Cryptanalysis
KW - Multi-server architecture
KW - Password
KW - Smart card
UR - https://www.scopus.com/pages/publications/84938960924
U2 - 10.1007/s11277-014-2002-x
DO - 10.1007/s11277-014-2002-x
M3 - 文章
AN - SCOPUS:84938960924
SN - 0929-6212
VL - 80
SP - 175
EP - 192
JO - Wireless Personal Communications
JF - Wireless Personal Communications
IS - 1
ER -