DocumentCode
84764
Title
A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards
Author
Odelu, Vanga ; Das, Ashok Kumar ; Goswami, Adrijit
Author_Institution
Dept. of Math., IIT Kharagpur, Kharagpur, India
Volume
10
Issue
9
fYear
2015
fDate
Sept. 2015
Firstpage
1953
Lastpage
1966
Abstract
Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He-Wang´s scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user´s anonymity. Furthermore, He-Wang´s scheme cannot provide the user revocation facility when the smart card is lost/stolen or user´s authentication parameter is revealed. Apart from these, He-Wang´s scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows-Abadi-Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He-Wang´s scheme.
Keywords
biometrics (access control); formal logic; formal verification; message authentication; mobile computing; protocols; public key cryptography; smart cards; Burrows-Abadi-Needham logic; ECC; He-Wang scheme; battery-limited mobile device; biometric security; biometrics-based smart card; elliptic curve cryptography; formal security verification; impersonation attack; multiserver authentication protocol; session-specific temporary information attack; user anonymity; Authentication; Elliptic curve cryptography; Elliptic curves; Protocols; Servers; Smart cards; AVISPA; Authentication; BAN logic; Revocation and re-registration; Security; Smart card; authentication; revocation and re-registration; smart card;
fLanguage
English
Journal_Title
Information Forensics and Security, IEEE Transactions on
Publisher
ieee
ISSN
1556-6013
Type
jour
DOI
10.1109/TIFS.2015.2439964
Filename
7115930
Link To Document