Moon Jongho, Choi Younsung, Jung Jaewook, Won Dongho
Department of Computer Engineering, Sungkyunkwan University, Suwon, Gyeonggido 16419, Korea.
PLoS One. 2015 Dec 28;10(12):e0145263. doi: 10.1371/journal.pone.0145263. eCollection 2015.
In multi-server environments, user authentication is a very important issue because it provides the authorization that enables users to access their data and services; furthermore, remote user authentication schemes for multi-server environments have solved the problem that has arisen from user's management of different identities and passwords. For this reason, numerous user authentication schemes that are designed for multi-server environments have been proposed over recent years. In 2015, Lu et al. improved upon Mishra et al.'s scheme, claiming that their remote user authentication scheme is more secure and practical; however, we found that Lu et al.'s scheme is still insecure and incorrect. In this paper, we demonstrate that Lu et al.'s scheme is vulnerable to outsider attack and user impersonation attack, and we propose a new biometrics-based scheme for authentication and key agreement that can be used in multi-server environments; then, we show that our proposed scheme is more secure and supports the required security properties.
在多服务器环境中,用户认证是一个非常重要的问题,因为它提供了授权,使用户能够访问他们的数据和服务;此外,针对多服务器环境的远程用户认证方案解决了因用户管理不同身份和密码而产生的问题。因此,近年来已经提出了许多为多服务器环境设计的用户认证方案。2015年,Lu等人改进了Mishra等人的方案,声称他们的远程用户认证方案更安全、更实用;然而,我们发现Lu等人的方案仍然不安全且不正确。在本文中,我们证明了Lu等人的方案容易受到外部攻击和用户假冒攻击,并且我们提出了一种新的基于生物特征的认证和密钥协商方案,该方案可用于多服务器环境;然后,我们表明我们提出的方案更安全,并支持所需的安全属性。