• DocumentCode
    1979186
  • Title

    Cryptanalysis of an anonymous multi-server authenticated key agreement scheme using smart cards and biometrics

  • Author

    Chun-Ta Li ; Cheng-Chi Lee ; Hua-Hsuan Chen ; Min-Jie Syu ; Chun-Cheng Wang

  • Author_Institution
    Dept. of Inf. Manage., Tainan Univ. of Technol., Tainan, Taiwan
  • fYear
    2015
  • fDate
    12-14 Jan. 2015
  • Firstpage
    498
  • Lastpage
    502
  • Abstract
    With the growing popularity of network applications, multi-server architectures are becoming an essential part of heterogeneous networks and numerous security mechanisms have been widely studied in recent years. To protect sensitive information and restrict the access of precious services for legal privileged users only, smart card and biometrics based password authentication schemes have been widely utilized for various transaction-oriented environments. In 2014, Chuang and Chen proposed an anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards, password, and biometrics. They claimed that their three-factor scheme achieves better efficiency and security as compared to those for other existing biometrics-based and multi-server schemes. Unfortunately, in this paper, we found that the user anonymity of Chuang-Chen´s authentication scheme cannot be protected from an eavesdropping attack during authentication phase. Moreover, their scheme is vulnerable to smart card lost problems, many logged-in users´ attacks and denial-of-service attacks and is not easily reparable.
  • Keywords
    biometrics (access control); cryptography; message authentication; smart cards; trusted computing; anonymous multiserver authenticated key agreement scheme; biometrics; cryptanalysis; denial-of-service attacks; eavesdropping attack; password authentication; smart card loss problems; trusted computing; user anonymity; Authentication; Biometrics (access control); Computer crime; Cryptography; Servers; Smart cards; Anonymity; Authentication; Biometrics; Cryptanalysis; Multi-server; Password; Smart cards;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Information Networking (ICOIN), 2015 International Conference on
  • Conference_Location
    Cambodia
  • Type

    conf

  • DOI
    10.1109/ICOIN.2015.7057955
  • Filename
    7057955