On the Security of a Privacy-Aware Authentication Scheme for Distributed Mobile Cloud Computing Services

On the Security of a Privacy-Aware Authentication Scheme for Distributed Mobile Cloud Computing Services
复制标题

分布式移动云计算服务隐私感知认证方案的安全性研究

DOI:
10.1109/jsyst.2016.2574719
复制
发表时间:
2018-06-01
影响因子:
4.4
通讯作者:
Wei, Fushan
Wei, Fushan
中科院分区:
计算机科学2区
文献类型:
--
作者:
Jiang, Qi;Ma, Jianfeng;Wei, Fushan

文献摘要

被引文献

相似文献

最近,Tsai和Lo提出了一种用于分布式移动的云计算服务的隐私感知认证方案。该方案实现了双向认证,能够抵御所有主要的安全威胁。然而,我们首先发现,他们的计划未能实现相互认证,因为它是容易受到服务提供者冒充攻击。除了这个主要缺陷之外,它还存在一些小的设计缺陷,包括生物识别技术滥用,错误密码和指纹登录的问题,当智能卡丢失/被盗时没有用户撤销设施。最后给出了一些建议,以避免这些设计缺陷在未来的认证方案的设计。
Recently, Tsai and Lo proposed a privacy aware authentication scheme for distributed mobile cloud computing services. It is claimed that the scheme achieves mutual authentication and withstands all major security threats. However, we first identify that their scheme fails to achieve mutual authentication, because it is vulnerable to the service provider impersonation attack. Beside this major defect, it also suffers from some minor design flaws, including the problem of biometrics misuse, wrong password, and fingerprint login, no user revocation facility when the smart card is lost/stolen. Some suggestions are provided to avoid these design flaws in the future design of authentication schemes.