An extended chaotic-maps-based protocol with key agreement for multiserver environments

An extended chaotic-maps-based protocol with key agreement for multiserver environments
复制标题

DOI:
10.1007/s11071-013-1174-3
复制
发表时间:
2014-04-01
期刊:
影响因子:
5.6
通讯作者:
Hsu, Che-Wei
Hsu, Che-Wei
中科院分区:
工程技术2区
文献类型:
--
作者:
Lee, Cheng-Chi;Lou, Der-Chyuan;Hsu, Che-Wei

文献摘要

被引文献

相似文献

由于计算机网络的快速发展和增长,对远程口令认证协议的需求越来越大。最近,焦点一直在智能卡上运行的多服务器环境的协议。这些协议通常依靠随机数或时间戳来提供针对重放攻击的保护。然而,正如Tsaur等人指出的,这些协议存在一些安全问题,例如时钟同步的干扰和对中间人攻击的脆弱性。为了解决上述问题,Tsaur等人在2012年提出了一种带密钥协商的多服务器认证方案,他们声称他们的方案可以有效地实现密码认证密钥协商,同时绕过了在多服务器环境中实现时钟同步的技术难点。不幸的是,我们发现Tsaur等人。的协议仍然存在以下缺陷:(1)不能抵抗特权内部攻击,(2)不能抵抗已知明文攻击,(3)不能提供用户匿名性,(4)缺乏完美的前向保密性。为了修复Tsaur等人的这些安全缺陷,协议的基础上,提出了一种改进的基于扩展混沌映射的多服务器认证协议。我们还将提供形式证明的改进的认证密钥协商协议的顺利执行。
Due to the rapid development and growth of computer networks, there have been greater and greater demands for remote password authentication protocols. Recently, the focus has been on protocols for multiserver environments that run on smart cards. These protocols typically count on the nonce or timestamp to provide protection against the replay attack. However, as Tsaur et al. pointed out, these protocols have some security issues such as disturbance in clock synchronization and vulnerability to the man-in-the-middle attack. In order to solve the above problems, Tsaur et al. proposed a multiserver authentication scheme with key agreement in 2012, and they claimed that their scheme could effectively achieve password-authenticated key agreement while getting around the technical difficulty of implementing clock synchronization in multiserver environments. Unfortunately, we found out that Tsaur et al.'s protocol still has the following weaknesses: (1) inability to resist privileged insider attack, (2) inability to resist known-plaintext attack, (3) inability to provide user anonymity, and (4) lack of perfect forward secrecy. To fix these secure flaws of Tsaur et al.'s protocol, in this paper, we shall propose an improved multiserver authentication protocol with key agreement based on extended chaotic maps. We shall also offer formal proof of smooth execution of the improved authenticated key agreement protocol.