An extended chaotic-maps-based protocol with key agreement for multiserver environments |
| |
Authors: | Cheng-Chi Lee Der-Chyuan Lou Chun-Ta Li Che-Wei Hsu |
| |
Affiliation: | 1. Department of Library and Information Science, Fu Jen Catholic University, 510 Jhongjheng Rd., Sinjhuang Dist., New Taipei City, 24205, Taiwan, ROC 2. Department of Photonics & Communication Engineering, Asia University, No. 500, Lioufeng Road, Wufeng Shiang, Taichung, 402, Taiwan, ROC 3. Department of Computer Science and Information Engineering, Chang Gung University, Tao-Yuan, 33302, Taiwan, ROC 4. Department of Information Management, Tainan University of Technology, 529 Zhongzheng Road, Tainan, 71002, Taiwan, ROC
|
| |
Abstract: | Due to the rapid development and growth of computer networks, there have been greater and greater demands for remote password authentication protocols. Recently, the focus has been on protocols for multiserver environments that run on smart cards. These protocols typically count on the nonce or timestamp to provide protection against the replay attack. However, as Tsaur et al. pointed out, these protocols have some security issues such as disturbance in clock synchronization and vulnerability to the man-in-the-middle attack. In order to solve the above problems, Tsaur et al. proposed a multiserver authentication scheme with key agreement in 2012, and they claimed that their scheme could effectively achieve password-authenticated key agreement while getting around the technical difficulty of implementing clock synchronization in multiserver environments. Unfortunately, we found out that Tsaur et al.’s protocol still has the following weaknesses: (1) inability to resist privileged insider attack, (2) inability to resist known-plaintext attack, (3) inability to provide user anonymity, and (4) lack of perfect forward secrecy. To fix these secure flaws of Tsaur et al.’s protocol, in this paper, we shall propose an improved multiserver authentication protocol with key agreement based on extended chaotic maps. We shall also offer formal proof of smooth execution of the improved authenticated key agreement protocol. |
| |
Keywords: | |
本文献已被 SpringerLink 等数据库收录! |
|