针对现有无后端数据库RFID(radio frequency identification)认证协议存在的安全隐私以及效率低的问题,在Deng等人方案的基础上提出了改进方案。采用组身份标识共享技术,防止读写器穷举搜索,降低读写器搜索时间复杂度;改进读写器成功认...针对现有无后端数据库RFID(radio frequency identification)认证协议存在的安全隐私以及效率低的问题,在Deng等人方案的基础上提出了改进方案。采用组身份标识共享技术,防止读写器穷举搜索,降低读写器搜索时间复杂度;改进读写器成功认证标签后更新共享密钥的方式,实现阅读器和标签密钥的同步更新;引入阅读器和标签产生的随机数种子作为密钥更新的参数,确保密钥的新鲜性和随机性,以保护位置隐私。通过安全性分析和实验分析可知,改进方案有效增强了原协议的安全性,并且提高了读写器的搜索效率,降低了读写器搜索耗时和一轮完整通信所需时间,因此改进方案的实用性更佳。展开更多
As service demands rise and expand single-server user authentication has become unable to satisfy actual application demand. At the same time identity and password based authentication schemes are no longer adequate b...As service demands rise and expand single-server user authentication has become unable to satisfy actual application demand. At the same time identity and password based authentication schemes are no longer adequate because of the insecurity of user identity and password. As a result biometric user authentication has emerged as a more reliable and attractive method. However, existing biometric authentication schemes are vulnerable to some common attacks and provide no security proof, some of these biometric schemes are also either inefficient or lack sufficient concern for privacy. In this paper, we propose an anonymous and efficient remote biometric user authentication scheme for a multi-server architecture with provable security. Through theoretical mathematic deduction, simulation implementation, and comparison with related work, we demonstrate that our approach can remove the aforementioned weaknesses and is well suited for a multi- server environment.展开更多
身份认证是用户访问网络资源时的一个重要安全问题。近来,Xu等(XU C,JIA Z,WEN F,et al.Cryptanalysis and improvement of a dynamic ID based remote user authentication scheme using smart cards[J].Journal of Computational Info...身份认证是用户访问网络资源时的一个重要安全问题。近来,Xu等(XU C,JIA Z,WEN F,et al.Cryptanalysis and improvement of a dynamic ID based remote user authentication scheme using smart cards[J].Journal of Computational Information Systems,2013,9(14):5513-5520)提出了一个基于智能卡的动态身份用户认证方案。分析指出其方案不能抵抗中间人攻击和会话密钥泄露攻击,且无法实现会话密钥前向安全性。此外,指出Choi等(CHOI Y,NAM J,LEE D,et al.Security enhanced anonymous multiserver authenticated key agreement scheme using smart cards and biometrics[J].The Scientific World Journal,2014,2014:281305)提出的基于智能卡和生物特征的匿名多服务器身份认证方案(简称CNL方案)易遭受智能卡丢失攻击、服务器模仿攻击,且不能提保护用户的匿名性。最后,基于生物特征和扩展混沌映射,提出了一个安全的多服务器认证方案,安全分析结果表明,新方案消除了Xu方案和CNL方案的安全漏洞。展开更多
文摘针对现有无后端数据库RFID(radio frequency identification)认证协议存在的安全隐私以及效率低的问题,在Deng等人方案的基础上提出了改进方案。采用组身份标识共享技术,防止读写器穷举搜索,降低读写器搜索时间复杂度;改进读写器成功认证标签后更新共享密钥的方式,实现阅读器和标签密钥的同步更新;引入阅读器和标签产生的随机数种子作为密钥更新的参数,确保密钥的新鲜性和随机性,以保护位置隐私。通过安全性分析和实验分析可知,改进方案有效增强了原协议的安全性,并且提高了读写器的搜索效率,降低了读写器搜索耗时和一轮完整通信所需时间,因此改进方案的实用性更佳。
基金This work was supported by the National Natural Sciences Foundation of China (Grant Nos. 61300181, 61272057, 61202434, 61170270, 61100203 and 61121061), the Fundamental Research Funds for the Central Universities (2012RC0612, 2011YB01), China Postdoctoral Science Foundation (2013M530561).
文摘As service demands rise and expand single-server user authentication has become unable to satisfy actual application demand. At the same time identity and password based authentication schemes are no longer adequate because of the insecurity of user identity and password. As a result biometric user authentication has emerged as a more reliable and attractive method. However, existing biometric authentication schemes are vulnerable to some common attacks and provide no security proof, some of these biometric schemes are also either inefficient or lack sufficient concern for privacy. In this paper, we propose an anonymous and efficient remote biometric user authentication scheme for a multi-server architecture with provable security. Through theoretical mathematic deduction, simulation implementation, and comparison with related work, we demonstrate that our approach can remove the aforementioned weaknesses and is well suited for a multi- server environment.
文摘身份认证是用户访问网络资源时的一个重要安全问题。近来,Xu等(XU C,JIA Z,WEN F,et al.Cryptanalysis and improvement of a dynamic ID based remote user authentication scheme using smart cards[J].Journal of Computational Information Systems,2013,9(14):5513-5520)提出了一个基于智能卡的动态身份用户认证方案。分析指出其方案不能抵抗中间人攻击和会话密钥泄露攻击,且无法实现会话密钥前向安全性。此外,指出Choi等(CHOI Y,NAM J,LEE D,et al.Security enhanced anonymous multiserver authenticated key agreement scheme using smart cards and biometrics[J].The Scientific World Journal,2014,2014:281305)提出的基于智能卡和生物特征的匿名多服务器身份认证方案(简称CNL方案)易遭受智能卡丢失攻击、服务器模仿攻击,且不能提保护用户的匿名性。最后,基于生物特征和扩展混沌映射,提出了一个安全的多服务器认证方案,安全分析结果表明,新方案消除了Xu方案和CNL方案的安全漏洞。