Title
Cryptanalysis of smart-card-based password authenticated key agreement protocol for session initiation protocol of Zhang et al.
Abstract
AbstractAs the core signaling protocol for multimedia services, such as voice over internet protocol, the session initiation protocol SIP is receiving much attention and its security is becoming increasingly important. It is critical to develop a roust user authentication protocol for SIP. The original authentication protocol is not strong enough to provide acceptable security level, and a number of authentication protocols have been proposed to strengthen the security. Recently, Zhang et al. proposed an efficient and flexible smart-card-based password authenticated key agreement protocol for SIP. They claimed that the protocol enjoys many unique properties and can withstand various attacks. However, we demonstrate that the scheme by Zhang et al. is insecure against the malicious insider impersonation attack. Specifically, a malicious user can impersonate other users registered with the same server. We also proposed an effective fix to remedy the flaw, which remedies the security flaw without sacrificing the efficiency. The lesson learned is that the authenticators must be closely coupled with the identity, and we should prevent the identity from being separated from the authenticators in the future design of two-factor authentication protocols. Copyright © 2014 John Wiley & Sons, Ltd.
Year
DOI
Venue
2015
10.1002/dac.2767
Periodicals
Keywords
Field
DocType
session initiation protocol, authentication, key agreement, password, smart card, malicious insider impersonation attack
Wide Mouth Frog protocol,Challenge-Handshake Authentication Protocol,Challenge–response authentication,Computer science,Computer security,Oakley protocol,Computer network,Otway–Rees protocol,Session Initiation Protocol,Authentication protocol,Reflection attack
Journal
Volume
Issue
ISSN
28
7
1074-5351
Citations 
PageRank 
References 
25
0.66
20
Authors
3
Name
Order
Citations
PageRank
Qi Jiang13649.32
Jianfeng Ma234040.21
Youliang Tian326112.42