Title :
Cryptanalysis of an anonymous multi-server authenticated key agreement scheme using smart cards and biometrics
Author :
Chun-Ta Li ; Cheng-Chi Lee ; Hua-Hsuan Chen ; Min-Jie Syu ; Chun-Cheng Wang
Author_Institution :
Dept. of Inf. Manage., Tainan Univ. of Technol., Tainan, Taiwan
Abstract :
With the growing popularity of network applications, multi-server architectures are becoming an essential part of heterogeneous networks and numerous security mechanisms have been widely studied in recent years. To protect sensitive information and restrict the access of precious services for legal privileged users only, smart card and biometrics based password authentication schemes have been widely utilized for various transaction-oriented environments. In 2014, Chuang and Chen proposed an anonymous multi-server authenticated key agreement scheme based on trust computing using smart cards, password, and biometrics. They claimed that their three-factor scheme achieves better efficiency and security as compared to those for other existing biometrics-based and multi-server schemes. Unfortunately, in this paper, we found that the user anonymity of Chuang-Chen´s authentication scheme cannot be protected from an eavesdropping attack during authentication phase. Moreover, their scheme is vulnerable to smart card lost problems, many logged-in users´ attacks and denial-of-service attacks and is not easily reparable.
Keywords :
biometrics (access control); cryptography; message authentication; smart cards; trusted computing; anonymous multiserver authenticated key agreement scheme; biometrics; cryptanalysis; denial-of-service attacks; eavesdropping attack; password authentication; smart card loss problems; trusted computing; user anonymity; Authentication; Biometrics (access control); Computer crime; Cryptography; Servers; Smart cards; Anonymity; Authentication; Biometrics; Cryptanalysis; Multi-server; Password; Smart cards;
Conference_Titel :
Information Networking (ICOIN), 2015 International Conference on
Conference_Location :
Cambodia
DOI :
10.1109/ICOIN.2015.7057955