Visible to the public An Enhanced and Secure Multiserver-based User Authentication Protocol

TitleAn Enhanced and Secure Multiserver-based User Authentication Protocol
Publication TypeConference Paper
Year of Publication2020
AuthorsHassan, Mehmood, Sultan, Aiman, Awan, Ali Afzal, Tahir, Shahzaib, Ihsan, Imran
Conference Name2020 International Conference on Cyber Warfare and Security (ICCWS)
Date Publishedoct
Keywordsauthentication, composability, compositionality, cryptanalysis, cryptography, Multiserver, password, policy-based governance, privacy, protocol, protocol verification, Protocols, ProVerif, pubcrawl, security, Servers, smart cards
AbstractThe extensive use of the internet and web-based applications spot the multiserver authentication as a significant component. The users can get their services after authenticating with the service provider by using similar registration records. Various protocol schemes are developed for multiserver authentication, but the existing schemes are not secure and often lead towards various vulnerabilities and different security issues. Recently, Zhao et al. put forward a proposal for smart card and user's password-based authentication protocol for the multiserver environment and showed that their proposed protocol is efficient and secure against various security attacks. This paper points out that Zhao et al.'s authentication scheme is susceptive to traceability as well as anonymity attacks. Thus, it is not feasible for the multiserver environment. Furthermore, in their scheme, it is observed that a user while authenticating does not send any information with any mention of specific server identity. Therefore, this paper proposes an enhanced, efficient and secure user authentication scheme for use in any multiserver environment. The formal security analysis and verification of the protocol is performed using state-of-the-art tool "ProVerif" yielding that the proposed scheme provides higher levels of security.
DOI10.1109/ICCWS48432.2020.9292383
Citation Keyhassan_enhanced_2020