Skip to main content

2018 | OriginalPaper | Buchkapitel

Improved Two-Factor Authentication Protocol Based on Biometric Feature and Password for Cloud Service

verfasst von : Jian Song, Bo-ru Xu, Guo-chao Zhang, Guang-song Li, Chuan-gui Ma, Ai-jun Ge

Erschienen in: Cloud Computing and Security

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Secure and efficient authentication protocols are necessary for cloud service. Multi-factor authentication protocols taking advantage of smart card, user’s password and biometric, are more secure than password-based single-factor authentication protocols which are widely used in practice. However, almost all the existed two-factor authentication protocols and multi-factor authentication protocols are based on smart cards, which will inevitably lead to a series of security problems caused by the loss of smart cards. Recently, Li et al. proposed a two-factor authenticated key agreement protocol based on biometric feature and password innovatively without using smart card. But we demonstrate that Li et al.’s protocol can’t resist the privileged-insider attack and the stolen verifier attack. Moreover, their protocol failed to provide user anonymity. To overcome the weaknesses of Li et al.’s scheme, we then proposed an improved two-factor authentication protocol based on the extended Chebyshev chaotic mapping. To illustrate the security of our scheme, we give a standard formal proof with the sequence of games (SOG) technique. Furthermore, we also present a comprehensive heuristic security analysis to demonstrate that the proposed protocol is capable of withstanding all the possible various attacks and provides the desired security features. Compared with other schemes, ours is more secure and efficient.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Armbrust, M., Fox, A., Griffith, R., et al.: A view of cloud computing. Commun. ACM 53(4), 50–58 (2010)CrossRef Armbrust, M., Fox, A., Griffith, R., et al.: A view of cloud computing. Commun. ACM 53(4), 50–58 (2010)CrossRef
2.
Zurück zum Zitat Takabi, H., Joshi, J.B.D., Ahn, G.J.: Security and privacy challenges in cloud computing environments. IEEE Secur. Priv. 8(6), 24–31 (2010)CrossRef Takabi, H., Joshi, J.B.D., Ahn, G.J.: Security and privacy challenges in cloud computing environments. IEEE Secur. Priv. 8(6), 24–31 (2010)CrossRef
3.
Zurück zum Zitat Bonneau, J., Herley, C., Oorschot, P.C.V., et al.: The quest to replace passwords: a framework for comparative evaluation of web authentication schemes. In: Security and Privacy, pp. 553–567. IEEE (2012) Bonneau, J., Herley, C., Oorschot, P.C.V., et al.: The quest to replace passwords: a framework for comparative evaluation of web authentication schemes. In: Security and Privacy, pp. 553–567. IEEE (2012)
5.
Zurück zum Zitat Chang, C.C., Wu, T.C.: Remote password authentication with smart cards. IEE Proc. E – Comput. Digit. Techn. 138(3), 165–168 (2005)CrossRef Chang, C.C., Wu, T.C.: Remote password authentication with smart cards. IEE Proc. E – Comput. Digit. Techn. 138(3), 165–168 (2005)CrossRef
6.
Zurück zum Zitat Xie, Q., Wong, D., Wang, G., et al.: Provably secure dynamic ID-based anonymous two-factor authenticated key exchange protocol with extended security model. IEEE Trans. Inf. Forensics Secur. 12(6), 1382–1392 (2017)CrossRef Xie, Q., Wong, D., Wang, G., et al.: Provably secure dynamic ID-based anonymous two-factor authenticated key exchange protocol with extended security model. IEEE Trans. Inf. Forensics Secur. 12(6), 1382–1392 (2017)CrossRef
7.
Zurück zum Zitat Ding, W., Ping, W.: Two birds with one stone: two-factor authentication with security beyond conventional bound. IEEE Trans. Depend. Secur. Comput. PP(99), 1 (2016) Ding, W., Ping, W.: Two birds with one stone: two-factor authentication with security beyond conventional bound. IEEE Trans. Depend. Secur. Comput. PP(99), 1 (2016)
8.
Zurück zum Zitat Wang, D., Wang, N., Wang, P., et al.: Preserving privacy for free: efficient and provably secure two-factor authentication scheme with user anonymity. Inf. Sci. 321, 162–178 (2015)CrossRef Wang, D., Wang, N., Wang, P., et al.: Preserving privacy for free: efficient and provably secure two-factor authentication scheme with user anonymity. Inf. Sci. 321, 162–178 (2015)CrossRef
9.
Zurück zum Zitat He, D., Zeadally, S., Kumar, N., et al.: Anonymous authentication for wireless body area networks with provable security. IEEE Syst. J. PP(99), 1–12 (2016) He, D., Zeadally, S., Kumar, N., et al.: Anonymous authentication for wireless body area networks with provable security. IEEE Syst. J. PP(99), 1–12 (2016)
10.
Zurück zum Zitat Jiang, Q., Zeadally, S., Ma, J., et al.: Lightweight three-factor authentication and key agreement protocol for internet-integrated wireless sensor networks. IEEE Access 5, 3376–3392 (2017)CrossRef Jiang, Q., Zeadally, S., Ma, J., et al.: Lightweight three-factor authentication and key agreement protocol for internet-integrated wireless sensor networks. IEEE Access 5, 3376–3392 (2017)CrossRef
11.
Zurück zum Zitat Wu, F., Xu, L., Kumari, S., et al.: An improved and provably secure three-factor user authentication scheme for wireless sensor networks. Peer-to-Peer Netw. Appl. 11, 1–20 (2016)CrossRef Wu, F., Xu, L., Kumari, S., et al.: An improved and provably secure three-factor user authentication scheme for wireless sensor networks. Peer-to-Peer Netw. Appl. 11, 1–20 (2016)CrossRef
12.
Zurück zum Zitat Li, X.W., Yang, D.Q., Chen, B.X., et al.: Two-factor authenticated key agreement protocol based on biometric feature and password. J. Commun. 38(7), 89–95 (2017) Li, X.W., Yang, D.Q., Chen, B.X., et al.: Two-factor authenticated key agreement protocol based on biometric feature and password. J. Commun. 38(7), 89–95 (2017)
14.
Zurück zum Zitat Shoup, V.: Sequences of games: a tool for taming complexity in security proofs. IACR Cryptology ePrint Archive, p. 332 (2004) Shoup, V.: Sequences of games: a tool for taming complexity in security proofs. IACR Cryptology ePrint Archive, p. 332 (2004)
16.
Zurück zum Zitat Kanso, A., Yahyaoui, H., Almulla, M.: Keyed hash function based on a chaotic map. Inf. Sci. 186(1), 249–264 (2012)MathSciNetCrossRef Kanso, A., Yahyaoui, H., Almulla, M.: Keyed hash function based on a chaotic map. Inf. Sci. 186(1), 249–264 (2012)MathSciNetCrossRef
Metadaten
Titel
Improved Two-Factor Authentication Protocol Based on Biometric Feature and Password for Cloud Service
verfasst von
Jian Song
Bo-ru Xu
Guo-chao Zhang
Guang-song Li
Chuan-gui Ma
Ai-jun Ge
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-030-00012-7_9