Department of Computer Science and Information Engineering, National Taichung University of Science and Technology, No.129, Sec. 3, Sanmin Rd., Taichung, 404, Taiwan.
Institute of Communication Engineering, National Yunlin University of Science and Technology, Douliu City, Taiwan.
J Med Syst. 2016 Jan;40(1):26. doi: 10.1007/s10916-015-0360-x. Epub 2015 Nov 7.
People can use their web browser or mobile devices to access web services and applications which are built into these servers. Users have to input their identity and password to login the server. The identity and password may be appropriated by hackers when the network environment is not safe. The multiple secure authentication protocol can improve the security of the network environment. Mobile devices can be used to pass the authentication messages through Wi-Fi or 3G networks to serve as a second communication channel. The content of the message number is not considered in a multiple secure authentication protocol. The more excessive transmission of messages would be easier to collect and decode by hackers. In this paper, we propose two schemes which allow the server to validate the user and reduce the number of messages using the XOR operation. Our schemes can improve the security of the authentication protocol. The experimental results show that our proposed authentication protocols are more secure and effective. In regard to applications of second authentication communication channels for a smart access control system, identity identification and E-wallet, our proposed authentication protocols can ensure the safety of person and property, and achieve more effective security management mechanisms.
人们可以使用他们的网络浏览器或移动设备来访问内置在这些服务器中的网络服务和应用程序。用户必须输入他们的身份和密码才能登录服务器。当网络环境不安全时,身份和密码可能会被黑客盗用。多重安全认证协议可以提高网络环境的安全性。移动设备可以通过 Wi-Fi 或 3G 网络传递认证消息,作为第二个通信通道。在多重安全认证协议中,不考虑消息数量的内容。消息的过度传输更容易被黑客收集和解码。在本文中,我们提出了两种方案,允许服务器使用 XOR 操作验证用户并减少消息数量。我们的方案可以提高认证协议的安全性。实验结果表明,我们提出的认证协议更加安全有效。在智能访问控制系统和电子钱包等二次认证通信通道的应用中,我们提出的认证协议可以确保人身和财产的安全,实现更有效的安全管理机制。