The Experts below are selected from a list of 5784 Experts worldwide ranked by ideXlab platform

Muhammad Khurram Khan - One of the best experts on this subject based on the ideXlab platform.

  • questioning key compromise Attack on ostad sharif et al s authentication and session key generation scheme for healthcare applications
    IEEE Access, 2019
    Co-Authors: Saru Kumari, Chienming Chen, Pradeep Chaudhary, Muhammad Khurram Khan
    Abstract:

    Recently, Ostad-Sharif et al. pointed out the susceptibility of three different authentication schemes themed for telecare medicine/medical information systems to key compromise impersonation Attack (KCIA). To further address this issue, they proposed an ECC-based authentication and key generation scheme for healthcare applications. In this paper, we show that Ostad-Sharif et al.'s scheme is not only affected with key compromise impersonation Attack but also suffers from a key compromise password guessing Attack. Several papers have been published by the researchers by applying KCIA on existing authentication protocols. Before any further move in research in this direction, researchers must contemplate about KCIA. We conclude this article with a rigorous analysis of KCIA along with two questions to ponderon for the research community working in this field.

  • an efficient chaos based 2 party key agreement protocol with provable security
    International Journal of Communication Systems, 2017
    Co-Authors: Min Luo, Yunru Zhang, Muhammad Khurram Khan
    Abstract:

    Summary Key agreement protocol is an important cryptographic primitive, which allows 2 parties to establish a secure session in an open network environment. A various of key agreement protocols were proposed. Nowadays, there still exists some other security flaws waiting to be solved. Owing to reduce the computational and communication costs and improve the security, chaotic map has been studied in-depth and treated as a good solution. Recently, Liu et al proposed a chaos-based 2-party key agreement protocol and demonstrated that it can defend denial-of-service Attack and replay Attack. We found, however, it cannot resist off-line Password-Guessing Attack, and it also has some other security flaws. In this paper, we propose an improved chaos-based 2-party key agreement protocol. The results prove that the protocol can solve the threats of off-line Password-Guessing Attack and other security flaws in the security proof section. What is more, performance analysis shows that the computational cost of the improved protocol is lower than Liu et al protocol.

  • An enhanced mutual authentication and key agreement scheme for mobile user roaming service in global mobility networks
    Annals of Telecommunications, 2017
    Co-Authors: Fan Wu, Lili Xu, Muhammad Khurram Khan, Saru Kumari, Xiong Li, Ashok Kumar Das
    Abstract:

    Roaming service is required in the ubiquitous access used in the global mobility networks (GLOMONETs) and the security is one of the most important issues. Many researchers focus their interests on authentication schemes for GLOMONETs. In 2015, Gope and Hwang, Zhang et al. and Farash et al. proposed their key agreement authentication schemes for GLOMONETs, respectively. However, we find weaknesses in them. Gope and Hwang’s scheme is under the off-line guessing Attack and the de-synchronization Attack. Moreover, it does not keep strong forward security and the session key is known by the home agent. Zhang et al.’s scheme has several weaknesses including vulnerability to the off-line guessing Attack, destitution of password change phase, and the leakage of updated session key. Farash et al.’s scheme lacks user anonymity and strong forward secrecy and is vulnerable to the off-line password guessing Attack. The session key is known to the home agent, too. Furthermore, neither Gope and Hwang’s scheme nor Farash et al.’s scheme has the session key update phase. To eliminate the problems, we present an improved authentication and key agreement scheme for GLOMONETs. According to the formal proof and the informal analysis, our scheme is well-performed and applicable.

  • a user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps
    Future Generation Computer Systems, 2016
    Co-Authors: Saru Kumari, Ashok Kumar Das, Hamed Arshad, Muhammad Khurram Khan
    Abstract:

    Spread of wireless network technology has opened new doors to utilize sensor technology in various areas via Wireless Sensor Networks (WSNs). Many authentication protocols for among the service seeker users, sensing component sensor nodes (SNs) and the service provider base-station or gateway node (GWN) are available to realize services from WSNs efficiently and without any fear of deceit. Recently, Li et al. and He et al. independently proposed mutual authentication and key agreement schemes for WSNs. We find that both the schemes achieve mutual authentication, establish session key and resist many known Attacks but still have security weaknesses. We show the applicability of stolen verifier, user impersonation, password guessing and smart card loss Attacks on Li et al.'s scheme. Although their scheme employs the feature of dynamic identity, an Attacker can reveal and guess the identity of a registered user. We demonstrate the susceptibility of He et al.'s scheme to password guessing Attack. In both the schemes, the security of the session key established between user and SNs is imperfect due to lack of forward secrecy and session-specific temporary information leakage Attack. In addition both the schemes impose extra computational load on resource scanty sensor-nodes and are not user friendly due to absence of user anonymity and lack of password change facility. To handle these drawbacks, we design a mutual authentication and key agreement scheme for WSN using chaotic maps. To the best of our knowledge, we are the first to propose an authentication scheme for WSN based on chaotic maps. We show the superiority of the proposed scheme over its predecessor schemes by means of detailed security analysis and comparative evaluation. We also formally analyze our scheme using BAN logic. We examine recently proposed Li et al.'s and He et al.'s schemes for WSN.We show security weaknesses in both schemes.We propose an improved scheme for WSN using Chebyshev chaotic maps.Formal security proof using BAN logic and conventional analysis assure the security of our scheme.Comparative evaluation shows the superiority of our scheme over related schemes.

  • design of an anonymity preserving three factor authenticated key exchange protocol for wireless sensor networks
    Computer Networks, 2016
    Co-Authors: Ruhul Amin, G. P. Biswas, Muhammad Khurram Khan, S Hafizul K Islam, Lu Leng, Neeraj Kumar
    Abstract:

    We observed that Farash et?al.'s authentication protocol for WSN is susceptible to many security Attacks.The protocol is also unable to preserve user anonymity.We designed an anonymity preserving authentication scheme for WSN.We analyze the security of the proposed protocol using AVISPA S/W.The proposed protocol is secure against active and passive Attacks and more efficient than other protocols. Recently, Farash et?al. pointed out some security weaknesses of Turkanovic et?al.'s protocol, which they extended to enhance its security. However, we found some problems with Farash et?al.'s protocol, such as a known session-specific temporary information Attack, an off-line Password-Guessing Attack using a stolen-smartcard, a new-smartcard-issue Attack, and a user-impersonation Attack. Additionally, their protocol cannot preserve user-anonymity, and the secret key of the gateway node is insecure. The main intention of this paper is to design an efficient and robust smartcard-based user authentication and session key agreement protocol for wireless sensor networks that use the Internet of Things. We analyze its security, proving that our protocol not only overcomes the weaknesses of Farash et?al.'s protocol, but also preserves additional security attributes, such as the identity change and smartcard revocation phases. Moreover, the results of a simulation using AVISPA show that our protocol is secure against active and passive Attacks. The security and performance of our work are also compared with a number of related protocols.

Saru Kumari - One of the best experts on this subject based on the ideXlab platform.

  • questioning key compromise Attack on ostad sharif et al s authentication and session key generation scheme for healthcare applications
    IEEE Access, 2019
    Co-Authors: Saru Kumari, Chienming Chen, Pradeep Chaudhary, Muhammad Khurram Khan
    Abstract:

    Recently, Ostad-Sharif et al. pointed out the susceptibility of three different authentication schemes themed for telecare medicine/medical information systems to key compromise impersonation Attack (KCIA). To further address this issue, they proposed an ECC-based authentication and key generation scheme for healthcare applications. In this paper, we show that Ostad-Sharif et al.'s scheme is not only affected with key compromise impersonation Attack but also suffers from a key compromise password guessing Attack. Several papers have been published by the researchers by applying KCIA on existing authentication protocols. Before any further move in research in this direction, researchers must contemplate about KCIA. We conclude this article with a rigorous analysis of KCIA along with two questions to ponderon for the research community working in this field.

  • An enhanced three factor based authentication protocol using wireless medical sensor networks for healthcare monitoring
    Journal of Ambient Intelligence and Humanized Computing, 2018
    Co-Authors: Rifaqat Ali, Saru Kumari, Arup Kumar Pal, Arun Kumar Sangaiah
    Abstract:

    With the rapid growth of wireless medical sensor networks (WMSNs) based healthcare applications, protecting both the privacy and security from illegitimate users, are major concern issues since patient’s precise information is vital for the proper diagnosis procedure. So, authentication protocol is one of the efficient mechanisms to deal with trustworthy and authentic users. Several authentication protocols have been proposed in WMSNs environment. However, the most of these protocols are so susceptible to security threats and not suitable for practical use. In this article, recently proposed Amin et al.’s authentication scheme is reviewed and some vulnerabilities like off-line password guessing Attack, user impersonation Attack, known session-key temporary information Attack, the revelation of secret parameters, and identity guessing Attack are pointed out. To overcome all the above mentioned vulnerabilities, we have proposed an enhanced three-factor based remote user authentication protocol in WMSNs environment. Further, the proposed protocol is validated using Burrows–Abadi–Needham logic and then simulated using Automated Validation of Internet Security Protocols and Applications tool. Moreover, the security analysis ensures that the proposed protocol is well protected from various types of malicious Attacks. In addition, the performance evaluation shows better efficiency and suitability of our protocol over other related protocols.

  • An enhanced mutual authentication and key agreement scheme for mobile user roaming service in global mobility networks
    Annals of Telecommunications, 2017
    Co-Authors: Fan Wu, Lili Xu, Muhammad Khurram Khan, Saru Kumari, Xiong Li, Ashok Kumar Das
    Abstract:

    Roaming service is required in the ubiquitous access used in the global mobility networks (GLOMONETs) and the security is one of the most important issues. Many researchers focus their interests on authentication schemes for GLOMONETs. In 2015, Gope and Hwang, Zhang et al. and Farash et al. proposed their key agreement authentication schemes for GLOMONETs, respectively. However, we find weaknesses in them. Gope and Hwang’s scheme is under the off-line guessing Attack and the de-synchronization Attack. Moreover, it does not keep strong forward security and the session key is known by the home agent. Zhang et al.’s scheme has several weaknesses including vulnerability to the off-line guessing Attack, destitution of password change phase, and the leakage of updated session key. Farash et al.’s scheme lacks user anonymity and strong forward secrecy and is vulnerable to the off-line password guessing Attack. The session key is known to the home agent, too. Furthermore, neither Gope and Hwang’s scheme nor Farash et al.’s scheme has the session key update phase. To eliminate the problems, we present an improved authentication and key agreement scheme for GLOMONETs. According to the formal proof and the informal analysis, our scheme is well-performed and applicable.

  • provably secure user authentication and key agreement scheme for wireless sensor networks
    Security and Communication Networks, 2016
    Co-Authors: Ashok Kumar Das, Saru Kumari, Vanga Odelu, Xinyi Huang
    Abstract:

    In recent years, user authentication has emerged as an interesting field of research in wireless sensor networks. Most recently, in 2016, Chang and Le presented a scheme to authenticate the users in wireless sensor network using a password and smart card. They proposed two protocols P1 and P2. P1 is based on exclusive or XOR and hash functions, while P2 deploys elliptic curve cryptography in addition to the two functions used in P1. Although their protocols are efficient, we point out that both P1 and P2 are vulnerable to session specific temporary information Attack and offline password guessing Attack, while P1 is also vulnerable to session key breach Attack. In addition, we show that both the protocols P1 and P2 are inefficient in authentication and password change phases. To withstand these weaknesses found in their protocols, we aim to design a new authentication and key agreement scheme using elliptic curve cryptography. Rigorous formal security proofs using the broadly accepted, the random oracle models, and the Burrows-Abadi-Needham logic and verification using the well-known Automated Validation of Internet Security Protocols and Applications tool are preformed on our scheme. The analysis shows that our designed scheme has the ability to resist a number of known Attacks comprising those found in both Chang-Le's protocols. Copyright © 2016 John Wiley & Sons, Ltd.

  • a user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps
    Future Generation Computer Systems, 2016
    Co-Authors: Saru Kumari, Ashok Kumar Das, Hamed Arshad, Muhammad Khurram Khan
    Abstract:

    Spread of wireless network technology has opened new doors to utilize sensor technology in various areas via Wireless Sensor Networks (WSNs). Many authentication protocols for among the service seeker users, sensing component sensor nodes (SNs) and the service provider base-station or gateway node (GWN) are available to realize services from WSNs efficiently and without any fear of deceit. Recently, Li et al. and He et al. independently proposed mutual authentication and key agreement schemes for WSNs. We find that both the schemes achieve mutual authentication, establish session key and resist many known Attacks but still have security weaknesses. We show the applicability of stolen verifier, user impersonation, password guessing and smart card loss Attacks on Li et al.'s scheme. Although their scheme employs the feature of dynamic identity, an Attacker can reveal and guess the identity of a registered user. We demonstrate the susceptibility of He et al.'s scheme to password guessing Attack. In both the schemes, the security of the session key established between user and SNs is imperfect due to lack of forward secrecy and session-specific temporary information leakage Attack. In addition both the schemes impose extra computational load on resource scanty sensor-nodes and are not user friendly due to absence of user anonymity and lack of password change facility. To handle these drawbacks, we design a mutual authentication and key agreement scheme for WSN using chaotic maps. To the best of our knowledge, we are the first to propose an authentication scheme for WSN based on chaotic maps. We show the superiority of the proposed scheme over its predecessor schemes by means of detailed security analysis and comparative evaluation. We also formally analyze our scheme using BAN logic. We examine recently proposed Li et al.'s and He et al.'s schemes for WSN.We show security weaknesses in both schemes.We propose an improved scheme for WSN using Chebyshev chaotic maps.Formal security proof using BAN logic and conventional analysis assure the security of our scheme.Comparative evaluation shows the superiority of our scheme over related schemes.

Dheerendra Mishra - One of the best experts on this subject based on the ideXlab platform.

  • Cryptanalysis and Improvement of Jiang et al.’s Smart Card Based Remote User Authentication Scheme
    2016
    Co-Authors: Dheerendra Mishra, Ankita Chaturvedi, Sourav Mukhopadhyay
    Abstract:

    Smart card based remote user password authentication schemes are one of the user-friendly and scalable mechanism to establish secure communication between remote entities. These schemes try to ensure secure and authorized communication between remote entities over the insecure public network. Although, most of the existing schemes do not satisfy desirable attributes, such that resistance against Attacks, user anonymity and efficiency. In 2012, Chen et al. proposed a robust smart cased based remote user authentication scheme to erase the weaknesses of Sood et al.’s scheme. Recently, Jiang et al. showed that Chen et al.’s scheme is vulnerable to password guessing Attack. Furthermore, Jiang et al. presented a solution to overcome the shortcoming of Chen et al.’s scheme. In the paper, we show that Jiang et al.’s scheme is still vulnerable to insider Attack, on-line and off-line password guessing Attack and user impersonation Attack. Their scheme also fails to ensure perfect forward secrecy and user’s anonymity. Moreover, It does not provide efficient login and user-friendly password change phase. Further, to overcome these drawbacks, we present a modify scheme which reduces the computation overhead and satisfies all desirable security attributes where Jiang et al.’s scheme failed

  • an anonymous and secure biometric based enterprise digital rights management system for mobile environment
    Security and Communication Networks, 2015
    Co-Authors: Ashok Kumar Das, Dheerendra Mishra, Sourav Mukhopadhyay
    Abstract:

    Internet-based content distribution facilitates an efficient platform to sell the digital content to the remote users. However, the digital content can be easily copied and redistributed over the network, which causes huge loss to the right holders. On the contrary, the digital rights management DRM systems have been introduced in order to regulate authorized content distribution. Enterprise DRM E-DRM system is an application of DRM technology, which aims to prevent illegal access of data in an enterprise. Earlier works on E-DRM do not address anonymity, which may lead to identity theft. Recently, Chang et al. proposed an efficient E-DRM mechanism. Their scheme provides greater efficiency and protects anonymity. Unfortunately, we identify that their scheme does not resist the insider Attack and Password-Guessing Attack. In addition, Chang et al.'s scheme has some design flaws in the authorization phase. We then point out the requirements of E-DRM system and present the cryptanalysis of Chang et al.'s scheme. In order to remedy the security weaknesses found in Chang et al.'s scheme, we aim to present a secure and efficient E-DRM scheme. The proposed scheme supports the authorized content key distribution and satisfies the desirable security attributes. Additionally, our scheme offers low communication and computation overheads and user's anonymity as well. Through the rigorous formal and informal security analyses, we show that our scheme is secure against possible known Attacks. Furthermore, the simulation results for the formal security analysis using the widely accepted Automated Validation of Internet Security Protocols and Applications tool ensure that our scheme is also secure. Copyright © 2015 John Wiley & Sons, Ltd.

  • on the security flaws in id based password authentication schemes for telecare medical information systems
    Journal of Medical Systems, 2015
    Co-Authors: Dheerendra Mishra
    Abstract:

    Telecare medical information systems (TMIS) enable healthcare delivery services. However, access of these services via public channel raises security and privacy issues. In recent years, several smart card based authentication schemes have been introduced to ensure secure and authorized communication between remote entities over the public channel for the (TMIS). We analyze the security of some of the recently proposed authentication schemes of Lin, Xie et al., Cao and Zhai, and Wu and Xu's for TMIS. Unfortunately, we identify that these schemes failed to satisfy desirable security attributes. In this article we briefly discuss four dynamic ID-based authentication schemes and demonstrate their failure to satisfy desirable security attributes. The study is aimed to demonstrate how inefficient password change phase can lead to denial of server scenario for an authorized user, and how an inefficient login phase causes the communication and computational overhead and decrease the performance of the system. Moreover, we show the vulnerability of Cao and Zhai's scheme to known session specific temporary information Attack, vulnerability of Wu and Xu's scheme to off-line password guessing Attack, and vulnerability of Xie et al.'s scheme to untraceable on-line password guessing Attack.

  • Cryptanalysis and Improvement of Yan et al.’s Biometric-Based Authentication Scheme for Telecare Medicine Information Systems
    Journal of Medical Systems, 2014
    Co-Authors: Dheerendra Mishra, Ashish Chaturvedi, Sourav Mukhopadhyay, Saru Kumari, Muhammad Khurram Khan
    Abstract:

    Remote user authentication is desirable for a Telecare Medicine Information System (TMIS) for the safety, security and integrity of transmitted data over the public channel. In 2013, Tan presented a biometric based remote user authentication scheme and claimed that his scheme is secure. Recently, Yan et al. demonstrated some drawbacks in Tan’s scheme and proposed an improved scheme to erase the drawbacks of Tan’s scheme. We analyze Yan et al.’s scheme and identify that their scheme is vulnerable to off-line password guessing Attack, and does not protect anonymity. Moreover, in their scheme, login and password change phases are inefficient to identify the correctness of input where inefficiency in password change phase can cause denial of service Attack. Further, we design an improved scheme for TMIS with the aim to eliminate the drawbacks of Yan et al.’s scheme.

  • Security Enhancement of a Biometric based Authentication Scheme for Telecare Medicine Information Systems with Nonce
    Journal of Medical Systems, 2014
    Co-Authors: Dheerendra Mishra, Sourav Mukhopadhyay, Muhammad Khurram Khan, Saru Kumari, Ashish Chaturvedi
    Abstract:

    Telecare medicine information systems (TMIS) present the platform to deliver clinical service door to door. The technological advances in mobile computing are enhancing the quality of healthcare and a user can access these services using its mobile device. However, user and Telecare system communicate via public channels in these online services which increase the security risk. Therefore, it is required to ensure that only authorized user is accessing the system and user is interacting with the correct system. The mutual authentication provides the way to achieve this. Although existing schemes are either vulnerable to Attacks or they have higher computational cost while an scalable authentication scheme for mobile devices should be secure and efficient. Recently, Awasthi and Srivastava presented a biometric based authentication scheme for TMIS with nonce. Their scheme only requires the computation of the hash and XOR functions.pagebreak Thus, this scheme fits for TMIS. However, we observe that Awasthi and Srivastava’s scheme does not achieve efficient password change phase. Moreover, their scheme does not resist off-line password guessing Attack. Further, we propose an improvement of Awasthi and Srivastava’s scheme with the aim to remove the drawbacks of their scheme.

Ruhul Amin - One of the best experts on this subject based on the ideXlab platform.

  • design of an anonymity preserving three factor authenticated key exchange protocol for wireless sensor networks
    Computer Networks, 2016
    Co-Authors: Ruhul Amin, G. P. Biswas, Muhammad Khurram Khan, S Hafizul K Islam, Lu Leng, Neeraj Kumar
    Abstract:

    We observed that Farash et?al.'s authentication protocol for WSN is susceptible to many security Attacks.The protocol is also unable to preserve user anonymity.We designed an anonymity preserving authentication scheme for WSN.We analyze the security of the proposed protocol using AVISPA S/W.The proposed protocol is secure against active and passive Attacks and more efficient than other protocols. Recently, Farash et?al. pointed out some security weaknesses of Turkanovic et?al.'s protocol, which they extended to enhance its security. However, we found some problems with Farash et?al.'s protocol, such as a known session-specific temporary information Attack, an off-line Password-Guessing Attack using a stolen-smartcard, a new-smartcard-issue Attack, and a user-impersonation Attack. Additionally, their protocol cannot preserve user-anonymity, and the secret key of the gateway node is insecure. The main intention of this paper is to design an efficient and robust smartcard-based user authentication and session key agreement protocol for wireless sensor networks that use the Internet of Things. We analyze its security, proving that our protocol not only overcomes the weaknesses of Farash et?al.'s protocol, but also preserves additional security attributes, such as the identity change and smartcard revocation phases. Moreover, the results of a simulation using AVISPA show that our protocol is secure against active and passive Attacks. The security and performance of our work are also compared with a number of related protocols.

  • efficient biometric and password based mutual authentication for consumer usb mass storage devices
    IEEE Transactions on Consumer Electronics, 2015
    Co-Authors: Debasis Giri, Simon R Sherratt, Tanmoy Maitra, Ruhul Amin
    Abstract:

    A Universal Serial Bus (USB) Mass Storage Device (MSD), often termed a USB flash drive, is ubiquitously used to store important information in unencrypted binary format. This low cost consumer device is incredibly popular due to its size, large storage capacity and relatively high transfer speed. However, if the device is lost or stolen an unauthorized person can easily retrieve all the information. Therefore, it is advantageous in many applications to provide security protection so that only authorized users can access the stored information. In order to provide security protection for a USB MSD, this paper proposes a session key agreement protocol after secure user authentication. The main aim of this protocol is to establish session key negotiation through which all the information retrieved, stored and transferred to the USB MSD is encrypted. This paper not only contributes an efficient protocol, but also does not suffer from the forgery Attack and the password guessing Attack as compared to other protocols in the literature. This paper analyses the security of the proposed protocol through a formal analysis which proves that the information is stored confidentially and is protected offering strong resilience to relevant security Attacks. The computational cost and communication cost of the proposed scheme is analyzed and compared to related work to show that the proposed scheme has an improved tradeoff for computational cost, communication cost and security.

  • Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems
    Journal of Medical Systems, 2015
    Co-Authors: Ruhul Amin, Sk Hafizul Islam, G. P. Biswas, Muhammad Khurram Khan, Xiong Li
    Abstract:

    The E-health care systems employ IT infrastructure for maximizing health care resources utilization as well as providing flexible opportunities to the remote patient. Therefore, transmission of medical data over any public networks is necessary in health care system. Note that patient authentication including secure data transmission in e-health care system is critical issue. Although several user authentication schemes for accessing remote services are available, their security analysis show that none of them are free from relevant security Attacks. We reviewed Das et al.’s scheme and demonstrated their scheme lacks proper protection against several security Attacks such as user anonymity, off-line password guessing Attack, smart card theft Attack, user impersonation Attack, server impersonation Attack, session key discloser Attack. In order to overcome the mentioned security pitfalls, this paper proposes an anonymity preserving remote patient authentication scheme usable in E-health care systems. We then validated the security of the proposed scheme using BAN logic that ensures secure mutual authentication and session key agreement. We also presented the experimental results of the proposed scheme using AVISPA software and the results ensure that our scheme is secure under OFMC and CL-AtSe models. Moreover, resilience of relevant security Attacks has been proved through both formal and informal security analysis. The performance analysis and comparison with other schemes are also made, and it has been found that the proposed scheme overcomes the security drawbacks of the Das et al.’s scheme and additionally achieves extra security requirements.

  • Design and Analysis of Bilinear Pairing Based Mutual Authentication and Key Agreement Protocol Usable in Multi-server Environment
    Wireless Personal Communications, 2015
    Co-Authors: Ruhul Amin, G. P. Biswas
    Abstract:

    With the increasing popularity and demand for various applications, the internet user accesses remote server by performing remote user authentication protocol using smart card over the insecure channel. In order to resist insider Attack, most of the users remember a set of identity and password for accessing different application servers. Therefore, remembering set of identity and password is an extra overhead to the user. To avoid the mentioned shortcoming, many remote user authentication and key agreement protocols for multi-server architecture have been proposed in the literature. Recently, Hsieh–Leu proposed an improve protocol of Liao et al. scheme and claimed that the improve protocol is applicable for practical implementation. However, through careful analysis, we found that Hsieh–Leu scheme is still vulnerable to user anonymity, password guessing Attack, server masquerading Attack and the password change phase is inefficient. Therefore, the main aim of this paper was to design a bilinear pairing based three factors remote user authentication scheme using smart card for providing security weaknesses free protocol. In order to validate security proof of the proposed protocol, this paper uses BAN logic which ensures that the same protocol achieves mutual authentication and session key agreement property securely. Furthermore, this paper also informally illustrates that the proposed protocol is well protected against all the relevant security Attacks. The performance analysis and comparison with other schemes are also made, and it has been found that the proposed protocol achieves complete security requirements with comparatively lesser complexities.

  • cryptanalysis and design of a three party authenticated key exchange protocol using smart card
    Arabian Journal for Science and Engineering, 2015
    Co-Authors: Ruhul Amin, G. P. Biswas
    Abstract:

    Three-party authenticated key exchange protocol (3PAKE) is used to provide security protection on the transmitted data over the insecure communication by performing session key agreement between the entities involved. Comparing with the 2PAKE protocol, 3PAKE protocol is more suitable for managing unrestricted number of users. Recently, several researchers have proposed many 3PAKE protocols using smart card. However, we have scrutinized carefully recently published Yang et al.’s protocol, and it has been observed that the same protocol suffers from several security weaknesses such as insider Attack, off-line password guessing Attack, many logged-in users’ Attack and replay Attack. Moreover, we have justified a serious security issue of the password change phase of the same scheme. In order to fix the above-mentioned shortcomings, this paper proposes an efficient 3PAKE protocol using smart card based on the cryptographic one-way hash function. The formal security analysis proves that proposed protocol provides strong security protection on the relevant security Attacks including the above-mentioned security weaknesses. Moreover, the simulation results of the proposed scheme using AVISPA tool show that the same protocol is SAFE under OFMC and CL-AtSe models. The performance comparisons are also made, which ensure that the protocol is relatively better than the existing related schemes. To the best of our knowledge, the proposed scheme should be implemented in practical application, as it provides well security protection on the relevant security Attacks, provides relatively better complexities than the existing schemes, achieves proper mutual authentication along with user-friendly password change phase.

Dongho Won - One of the best experts on this subject based on the ideXlab platform.

  • security enhanced anonymous user authenticated key agreement scheme using smart card
    Journal of Electronic Science and Technology, 2018
    Co-Authors: Jaewook Jung, Dong Hoon Lee, Hakjun Lee, Dongho Won
    Abstract:

    Nowadays, the password-based remote user authentication mechanism using smart card is one of the simplest and convenient authentication ways to ensure secure communications over the public network environments. Recently, Liu et al. proposed an efficient and secure smart card based password authentication scheme. However, we find that Liu et al.’s scheme is vulnerable to the off-line password guessing Attack and user impersonation Attack. Furthermore, it also cannot provide user anonymity. In this paper, we cryptanalyze Liu et al.’s scheme and propose a security enhanced user authentication scheme to overcome the aforementioned problems. Especially, in order to preserve the user anonymity and prevent the guessing Attack, we use the dynamic identity technique. The analysis shows that the proposed scheme is more secure and efficient than other related authentication schemes.

  • efficient and security enhanced anonymous authentication with key agreement scheme in wireless sensor networks
    Sensors, 2017
    Co-Authors: Jaewook Jung, Dong Hoon Lee, Jongho Moon, Dongho Won
    Abstract:

    At present, users can utilize an authenticated key agreement protocol in a Wireless Sensor Network (WSN) to securely obtain desired information, and numerous studies have investigated authentication techniques to construct efficient, robust WSNs. Chang et al. recently presented an authenticated key agreement mechanism for WSNs and claimed that their authentication mechanism can both prevent various types of Attacks, as well as preserve security properties. However, we have discovered that Chang et al’s method possesses some security weaknesses. First, their mechanism cannot guarantee protection against a password guessing Attack, user impersonation Attack or session key compromise. Second, the mechanism results in a high load on the gateway node because the gateway node should always maintain the verifier tables. Third, there is no session key verification process in the authentication phase. To this end, we describe how the previously-stated weaknesses occur and propose a security-enhanced version for WSNs. We present a detailed analysis of the security and performance of our authenticated key agreement mechanism, which not only enhances security compared to that of related schemes, but also takes efficiency into consideration.

  • cryptanalysis of dynamic id based user authentication scheme using smartcards without verifier tables
    CSA CUTE, 2015
    Co-Authors: Jaewook Jung, Younsung Choi, Jiye Kim, Dong Hoon Lee, Jongho Mun, Dongho Won
    Abstract:

    Password-based remote user authentication technique is the most commonly used for secure communication over insecure network environments. Due to its simplicity and efficiency, it is widely used in many fields such as e-commerce, distributed system, remote host login system, etc. In recent years, several dynamic ID-based user authentication schemes using password and smart card have been proposed to provide mutual authentication between the user and server. Recently, Lee proposed an efficient dynamic ID-based user authentication scheme without verifier tables. Lee claimed that his scheme can resist off-line password guessing Attack, user impersonation Attack and provide user anonymity. In this paper, we demonstrate that Lee’s enhanced scheme is not secure against off-line password guessing Attack and user impersonation Attack in violation of its security claim as well as it fails to preserve user anonymity.

  • cryptanalysis of a secure remote user authentication scheme
    The Journal of Korean Institute of Communications and Information Sciences, 2012
    Co-Authors: Kwangwoo Lee, Jin Qiuyan, Dongho Won
    Abstract:

    In 2011, C.-T. Li et al. proposed a secure user authentication scheme, which is an improvement over Kim et al.’s scheme to resolve several security flaws such as off-line password guessing Attack and masquerading Attack. C.-T. Li et al. claimed that their scheme prevents smart card security related Attacks. Moreover, it provides mutual authentication and session key establishment. However, we found that their scheme is vulnerable to password guessing Attack through password change phase, smart card forgery Attack and stolen verifier Attack. Moreover, C.-T. Li et al.’s scheme is not secure against password guessing Attack as they claimed. In this paper, we also point out that their scheme is not practical to use.

  • off line password guessing Attack to yang s and huang s authentication schemes for session initiation protocol
    Networked Computing and Advanced Information Management, 2009
    Co-Authors: Yunho Lee, Mijin Kim, Seungjoo Kim, Dongho Won
    Abstract:

    The Session Initiation Protocol(SIP) is an application-layer control protocol for creating, modifying, and terminating sessions with one or more participants in the IP-based telephony environment.Yang et al. and Huang et al. proposed a secure authentication scheme for session initiation protocol.Yang's scheme is based on Deffi-Hellman key agreement scheme and a combination of hash functions. In 2006, Huang et al. pointed out that Yang's scheme is insecure, and proposed an improved authentication scheme for SIP. In this paper, the secure of Yang's and Huang's scheme is analyzed. It is demonstrated that both schemes still have some weaknesses: it cannot withstand against the off-line Password-Guessing Attack. Based on our analysis, we found the security problem with these schemes and, in addition, shows how to fix it.