首页> 外文OA文献 >An efficient dynamic ID based remote user authentication scheme using self-certified public keys for multi-server environment
【2h】

An efficient dynamic ID based remote user authentication scheme using self-certified public keys for multi-server environment

机译:一种基于动态ID的高效远程用户认证方案   用于多服务器环境的自认证公钥

摘要

Recently, Li et al. analyzed Lee et al.'s multi-server authentication schemeand proposed a novel smart card and dynamic ID based remote user authenticationscheme for multi-server environments. They claimed that their scheme can resistseveral kinds of attacks. However, through careful analysis, we find that Li etal.'s scheme is vulnerable to stolen smart card and offline dictionary attack,replay attack, impersonation attack and server spoofing attack. By analyzingother similar schemes, we find that the certain type of dynamic ID basedmulti-server authentication scheme in which only hash functions are used and noregistration center participates in the authentication and session keyagreement phase is hard to provide perfect efficient and secure authentication.To compensate for these shortcomings, we improve the recently proposed Liao etal.'s multi-server authentication scheme which is based on pairing andself-certified public keys, and propose a novel dynamic ID based remote userauthentication scheme for multi-server environments. Liao et al.'s scheme isfound vulnerable to offline dictionary attack and denial of service attack, andcannot provide user's anonymity and local password verification. However, ourproposed scheme overcomes the shortcomings of Liao et al.'s scheme. Securityand performance analyses show the proposed scheme is secure against variousattacks and has many excellent features.
机译:最近,李等人。分析了Lee等人的多服务器身份验证方案,并提出了一种适用于多服务器环境的新颖的基于智能卡和动态ID的远程用户身份验证方案。他们声称他们的计划可以抵抗多种攻击。然而,通过仔细的分析,我们发现李等人的方案很容易受到智能卡被盗和离线字典攻击,重放攻击,模拟攻击和服务器欺骗攻击的攻击。通过分析其他类似方案,我们发现仅使用哈希函数且没有注册中心参与认证和会话密钥协商阶段的某种类型的基于动态ID的多服务器认证方案很难提供完美的高效和安全认证。这些缺点,我们改进了Liao et al。提出的基于配对和自认证公钥的多服务器身份验证方案,并针对多服务器环境提出了一种新颖的基于动态ID的远程用户身份验证方案。 Liao等人的方案很容易受到离线字典攻击和拒绝服务攻击的影响,无法提供用户的匿名性和本地密码验证。然而,我们提出的方案克服了廖等人方案的缺点。安全性和性能分析表明,所提出的方案具有抵抗各种攻击的能力,并且具有许多出色的功能。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号