TY - JOUR
T1 - SUAA
T2 - A Secure User Authentication Scheme with Anonymity for the Single & Multi-server Environments
AU - Lwamo, Nassoro M.R.
AU - Zhu, Liehuang
AU - Xu, Chang
AU - Sharif, Kashif
AU - Liu, Ximeng
AU - Zhang, Chuan
N1 - Publisher Copyright:
© 2018 Elsevier Inc.
PY - 2019/3
Y1 - 2019/3
N2 - The rapid increase in user base and technological penetration has enabled the use of a wide range of devices and applications. The services are rendered to these devices from single-server or highly distributed server environments, irrespective of their location. As the information exchanged between servers and clients is private, numerous forms of attacks can be launched to compromise it. To ensure the security, privacy, and availability of the services, different authentication schemes have been proposed for both single-server and multi-server environments. The primary performance objective of such schemes is to prevent most (if not all) attacks, with minimal computational costs at the server and user ends. To address this challenge, this paper presents a secure user authentication scheme with anonymity (SUAA) for single-server and multi-server environments. It works on 3-factor authentication, involving passwords, smart cards, and biometric data. We use symmetric and asymmetric encryption for single-server and multi-server architectures respectively, to reduce the computational costs. Through a comprehensive security analysis, we show that the proposed scheme is reliable through mutual authentication, and is resilient to attacks addressed by state of the art solutions. Time cost analysis also shows less time required to complete the authentication process.
AB - The rapid increase in user base and technological penetration has enabled the use of a wide range of devices and applications. The services are rendered to these devices from single-server or highly distributed server environments, irrespective of their location. As the information exchanged between servers and clients is private, numerous forms of attacks can be launched to compromise it. To ensure the security, privacy, and availability of the services, different authentication schemes have been proposed for both single-server and multi-server environments. The primary performance objective of such schemes is to prevent most (if not all) attacks, with minimal computational costs at the server and user ends. To address this challenge, this paper presents a secure user authentication scheme with anonymity (SUAA) for single-server and multi-server environments. It works on 3-factor authentication, involving passwords, smart cards, and biometric data. We use symmetric and asymmetric encryption for single-server and multi-server architectures respectively, to reduce the computational costs. Through a comprehensive security analysis, we show that the proposed scheme is reliable through mutual authentication, and is resilient to attacks addressed by state of the art solutions. Time cost analysis also shows less time required to complete the authentication process.
KW - Authentication
KW - BAN logic
KW - Multi-server
KW - Single server
KW - Smart card
UR - http://www.scopus.com/inward/record.url?scp=85055905607&partnerID=8YFLogxK
U2 - 10.1016/j.ins.2018.10.037
DO - 10.1016/j.ins.2018.10.037
M3 - Article
AN - SCOPUS:85055905607
SN - 0020-0255
VL - 477
SP - 369
EP - 385
JO - Information Sciences
JF - Information Sciences
ER -