The Experts below are selected from a list of 5547 Experts worldwide ranked by ideXlab platform
Muhammad Khurram Khan - One of the best experts on this subject based on the ideXlab platform.
-
an enhanced smart card based remote user password authentication scheme
Journal of Network and Computer Applications, 2013Co-Authors: Jianwei Niu, Muhammad Khurram Khan, Junguo LiaoAbstract:Smart card based password authentication is one of the simplest and efficient authentication mechanisms to ensure secure communication in Insecure Network environments. Recently, Chen et al. have pointed out the weaknesses of some password authentication schemes and proposed a robust smart card based remote user password authentication scheme to improve the security. As per their claims, their scheme is efficient and can ensure forward secrecy of the session key. However, we find that Chen et al.'s scheme cannot really ensure forward secrecy, and it cannot detect the wrong password in login phase. Besides, the password change phase of Chen et al.'s scheme is unfriendly and inefficient since the user has to communicate with the server to update his/her password. In this paper, we propose a modified smart card based remote user password authentication scheme to overcome the aforementioned weaknesses. The analysis shows that our proposed scheme is user friendly and more secure than other related schemes.
-
chaotic hash based fingerprint biometric remote user authentication scheme on mobile devices
Chaos Solitons & Fractals, 2008Co-Authors: Muhammad Khurram Khan, Jiashu Zhang, Xiaomin WangAbstract:Abstract This paper presents an efficient and practical chaotic hash-based fingerprint biometric remote user authentication scheme on mobile devices e.g. cell phone and PDA. Our scheme is completely based on the new family of one-way collision free chaotic hash functions, which are much efficient than modular exponentiation-based authentication schemes e.g. RSA. Proposed scheme is two-factor authentication scheme and a user has to identify him with: something he knows (e.g. password) and something he is (e.g. fingerprint biometric). Security analysis shows that the proposed scheme provides secure, robust, and trustworthy remote authentication of mobile users over Insecure Network. In addition, computational costs and efficiency of the proposed scheme are encouraging for the practical implementation in the real environment.
-
an efficient and practical fingerprint based remote user authentication scheme with smart cards
Lecture Notes in Computer Science, 2006Co-Authors: Muhammad Khurram Khan, Jiashu ZhangAbstract:, Recently, Lee et al. proposed a fingerprint-based remote user authentication scheme using smart cards. We demonstrate that their scheme is vulnerable and susceptible to the attack and has some practical pitfalls. Their scheme performs only unilateral authentication (only client authentication) and there is no mutual authentication between user and remote system, so their scheme suscepts from the server spoofing attack. Furthermore, in their scheme, remote system generates and assigns the passwords, and users cannot choose and change their passwords. Moreover, passwords are long pseudorandom numbers and difficult to remember for a user. To solve these problems, we propose an efficient and practical fingerprint-based remote user authentication scheme using smart cards, which is based on one-way collision free hash functions. Proposed scheme not only overcomes all the drawbacks and problems of Lee et al.'s scheme, but also provides a secure and user-friendly fingerprint-based remote user authentication over Insecure Network. In addition, computational costs and efficiency of the proposed scheme are better than Lee et al.'s scheme.
Jiashu Zhang - One of the best experts on this subject based on the ideXlab platform.
-
chaotic hash based fingerprint biometric remote user authentication scheme on mobile devices
Chaos Solitons & Fractals, 2008Co-Authors: Muhammad Khurram Khan, Jiashu Zhang, Xiaomin WangAbstract:Abstract This paper presents an efficient and practical chaotic hash-based fingerprint biometric remote user authentication scheme on mobile devices e.g. cell phone and PDA. Our scheme is completely based on the new family of one-way collision free chaotic hash functions, which are much efficient than modular exponentiation-based authentication schemes e.g. RSA. Proposed scheme is two-factor authentication scheme and a user has to identify him with: something he knows (e.g. password) and something he is (e.g. fingerprint biometric). Security analysis shows that the proposed scheme provides secure, robust, and trustworthy remote authentication of mobile users over Insecure Network. In addition, computational costs and efficiency of the proposed scheme are encouraging for the practical implementation in the real environment.
-
an efficient and practical fingerprint based remote user authentication scheme with smart cards
Lecture Notes in Computer Science, 2006Co-Authors: Muhammad Khurram Khan, Jiashu ZhangAbstract:, Recently, Lee et al. proposed a fingerprint-based remote user authentication scheme using smart cards. We demonstrate that their scheme is vulnerable and susceptible to the attack and has some practical pitfalls. Their scheme performs only unilateral authentication (only client authentication) and there is no mutual authentication between user and remote system, so their scheme suscepts from the server spoofing attack. Furthermore, in their scheme, remote system generates and assigns the passwords, and users cannot choose and change their passwords. Moreover, passwords are long pseudorandom numbers and difficult to remember for a user. To solve these problems, we propose an efficient and practical fingerprint-based remote user authentication scheme using smart cards, which is based on one-way collision free hash functions. Proposed scheme not only overcomes all the drawbacks and problems of Lee et al.'s scheme, but also provides a secure and user-friendly fingerprint-based remote user authentication over Insecure Network. In addition, computational costs and efficiency of the proposed scheme are better than Lee et al.'s scheme.
Zhong Chen - One of the best experts on this subject based on the ideXlab platform.
-
new identity based three party authenticated key agreement protocol with provable security
Journal of Network and Computer Applications, 2013Co-Authors: Hu Xiong, Zhong ChenAbstract:Key agreement allows multi-parties exchanging public information to create a common secret key that is known only to those entities over an Insecure Network. In the recent years, several identity-based (ID-based) authenticated key agreement protocols have been proposed and most of them broken. In this paper, we formalize the security model of ID-based authenticated tripartite key agreement protocol and propose a provably secure ID-based authenticated key agreement protocol for three parties with formal security proof under the computational Diffie-Hellman assumption. Experimental results by using the AVISPA tool show that the proposed protocol is secure against various malicious attacks.
Junguo Liao - One of the best experts on this subject based on the ideXlab platform.
-
an enhanced smart card based remote user password authentication scheme
Journal of Network and Computer Applications, 2013Co-Authors: Jianwei Niu, Muhammad Khurram Khan, Junguo LiaoAbstract:Smart card based password authentication is one of the simplest and efficient authentication mechanisms to ensure secure communication in Insecure Network environments. Recently, Chen et al. have pointed out the weaknesses of some password authentication schemes and proposed a robust smart card based remote user password authentication scheme to improve the security. As per their claims, their scheme is efficient and can ensure forward secrecy of the session key. However, we find that Chen et al.'s scheme cannot really ensure forward secrecy, and it cannot detect the wrong password in login phase. Besides, the password change phase of Chen et al.'s scheme is unfriendly and inefficient since the user has to communicate with the server to update his/her password. In this paper, we propose a modified smart card based remote user password authentication scheme to overcome the aforementioned weaknesses. The analysis shows that our proposed scheme is user friendly and more secure than other related schemes.
Yixian Yang - One of the best experts on this subject based on the ideXlab platform.
-
an extended chaotic maps based three party password authenticated key agreement with user anonymity
PLOS ONE, 2016Co-Authors: Hao Zhang, Yixian YangAbstract:User anonymity is one of the key security features of an authenticated key agreement especially for communicating messages via an Insecure Network. Owing to the better properties and higher performance of chaotic theory, the chaotic maps have been introduced into the security schemes, and hence numerous key agreement schemes have been put forward under chaotic-maps. Recently, Xie et al. released an enhanced scheme under Farash et al.’s scheme and claimed their improvements could withstand the security loopholes pointed out in the scheme of Farash et al., i.e., resistance to the off-line password guessing and user impersonation attacks. Nevertheless, through our careful analysis, the improvements were released by Xie et al. still could not solve the problems troubled in Farash et al‥ Besides, Xie et al.’s improvements failed to achieve the user anonymity and the session key security. With the purpose of eliminating the security risks of the scheme of Xie et al., we design an anonymous password-based three-party authenticated key agreement under chaotic maps. Both the formal analysis and the formal security verification using AVISPA are presented. Also, BAN logic is used to show the correctness of the enhancements. Furthermore, we also demonstrate that the design thwarts most of the common attacks. We also make a comparison between the recent chaotic-maps based schemes and our enhancements in terms of performance.