Title
Provably Secure Multi-Server Authentication Protocol Using Fuzzy Commitment.
Abstract
Remote user authentication is a cryptographic mechanism through which a remote server verifies the legitimacy of an authorized user over an insecure communication channel. Most of the existing authentication schemes consider single-server environments and require multiple registrations of the same user for multiple servers. Moreover, most of these schemes do not consider biometric template revocation and error correction for noisy biometric signals. In addition, the existing schemes have several weaknesses, including stolen smart card attack, lack of user anonymity, user impersonation attack, and non-diversification of biometric data. To overcome these disadvantages, we propose a new three-factor authenticated key agreement scheme using a fuzzy commitment approach. The three factors used in the proposed scheme are the user's password, smart card, and personal biometrics. The security of the proposed scheme is verified using a formal security analysis under the broadly accepted Real-Or-Random model for the session key security. The widely accepted Burrows-Abadi-Needham logic is also applied for mutual authentication between a legally registered user and a server, and formal security verification using the broadly accepted Automated Validation of Internet Security Protocols and Applications is performed for the proposed scheme through simulation to show that it is secure. In addition, the informal security analysis of the proposed scheme shows that the scheme can resist other known attacks. Finally, a comparative study of the proposed scheme with the existing related schemes is conducted to measure the tradeoff among the security and functionality features and the communication and computation costs.
Year
DOI
Venue
2018
10.1109/ACCESS.2018.2854798
IEEE ACCESS
Keywords
Field
DocType
Multi-server authentication,fuzzy commitment,security,BAN logic,AVISPA
Mutual authentication,Internet security,Authentication,Cryptography,Computer science,Computer network,Smart card,Security analysis,Authentication protocol,Password
Journal
Volume
ISSN
Citations 
6
2169-3536
2
PageRank 
References 
Authors
0.36
0
6
Name
Order
Citations
PageRank
Subhas Barman1123.22
Ashok Kumar Das22250122.93
Debasis Samanta322737.98
Samiran Chattopadhyay417434.02
JOEL J. P. C. RODRIGUES53484341.72
Young-ho Park68411.76