arrow
返回

A design of provably secure multi-factor ECC-based authentication protocol in multi-server cloud architecture

delete2023-05-29
delete9
PRE
AI
S
Shivangi Shukla *
S
Sankita J. Patel
DOI:10.1007/s10586-023-04034-6delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
The emerging cloud infrastructure has escalated number of servers offering flexible and diverse remote services through public channels. However, user authentication in conventional single-server architecture necessitates multiple smart cards maintenance and passwords memorization to access different cloud servers. To address this limitation, researchers devised authentication protocols for multi-server architecture that offers scalable platform wherein users can access multiple servers with single registration. The multi-factor authentication protocols leverage biometric keys to bind users' physical characteristics with their identity, offering higher security than two-factor authentication protocols. However, the existing protocols for multi-server architecture are prone to replay, user impersonation, denial of service, server spoofing attacks and lack security functionalities such as user anonymity and untraceability, backward and forward secrecy, and session key security. Moreover, the incorporation of registration center (RC) to authenticate each pair of user-server in multi-server architecture can lead to computational bottleneck and single-point failure issues on RC. To overcome these security loopholes, we design a novel provably secure multi-factor elliptic curve cryptography (ECC) based authentication protocol for multi-server architecture with offline RC for cloud environment. The formal security analysis under widely accepted real-or-random (ROR) model and informal security analysis of proposed protocol demonstrate provision of security functionalities and resilience against potential security attacks. Furthermore, we adopt Scyther security verification tool to verify our protocol's correctness and security properties. The performance evaluation demonstrates that our protocol offers robust security functionalities with reasonable communication and computation overheads than state-of-the-art protocols.
Keyword:
Multi-factor authentication
Anonymity
Untraceability
Elliptic curve cryptography
Multi-server
Cloud computing

期刊

C
Cluster Computing-The Journal of Networks Software Tools and Applications
IF:
4.1
论文数:
5.1K
被引数:
7.5K

机构

N
national institute of technology (nit system)
学者数:
4.0W
论文数: 3.7W
被引数: 31
引用论文

引用论文

A Privacy-Preserving RLWE-Based Remote Biometric Authentication Scheme for Single and Multi-Server Environments
err2019-01-01
err19
errOAAI
errYao, Hailong; Wang, Caifen; Fu, Xingbing; Liu, Chao; Wu, Bin; Li, Fagen
err分享
err收藏
A Secure Authentication Protocol for Multi-Sever-Based E-Healthcare Using a Fuzzy Commitment Scheme
err2019-01-01
err48
errOAAI
errBarman, Subhas; Shum, Hubert P. H.; Chattopadhyay, Samiran; Samanta, Debasis
err分享
err收藏
Survival of patients with breast cancer attending Bristol Cancer Help Centre
err1990-09-01
err0
PREAI
errC.E.D. Chilvers; F.S. Bagenal; D.F. Easton; E. Harris; T.J. McElwain
err分享
err收藏
A robust and lightweight secure access scheme for cloud based E-healthcare services
err2021-05-03
err48
errOAAI
errMasud, Mehedi; Gaba, Gurjot Singh; Choudhary, Karanjeet; Alroobaea, Roobaea; Hossain, M. Shamim
err分享
err收藏
学者 查看更多内容