z-logo
open-access-imgOpen Access
Analysis and Improvement on a Biometric-Based Remote User Authentication Scheme Using Smart Cards
Author(s) -
Fengtong Wen,
Willy Susilo,
Guomin Yang
Publication year - 2014
Publication title -
wireless personal communications
Language(s) - English
Resource type - Journals
SCImago Journal Rank - 0.302
H-Index - 60
eISSN - 1572-834X
pISSN - 0929-6212
DOI - 10.1007/s11277-014-2111-6
Subject(s) - computer science , smart card , anonymity , password , computer security , scheme (mathematics) , biometrics , mutual authentication , password cracking , authentication (law) , challenge–response authentication , authentication protocol , mathematical analysis , mathematics
In a recent paper (BioMed Research International, 2013/491289), Khan et al. proposed an improved biometrics-based remote user authentication scheme with user anonymity. The scheme is believed to be secure against password guessing attack, user impersonation attack, server masquerading attack, and provide user anonymity, even if the secret information stored in the smart card is compromised. In this paper, we analyze the security of Khan et al.'s scheme, and demonstrate that their scheme doesn't provide user anonymity. This also renders that their scheme is insecure against other attacks, such as off-line password guessing attack, user impersonation attacks. Subsequently, we propose a robust biometric-based remote user authentication scheme. Besides, we simulate our scheme for the formal security verification using the wide-accepted BAN logic to ensure our scheme is working correctly by achieving the mutual authentication goals.

The content you want is available to Zendy users.

Already have an account? Click here to sign in.
Having issues? You can contact us here
Accelerating Research

Address

John Eccles House
Robert Robinson Avenue,
Oxford Science Park, Oxford
OX4 4GP, United Kingdom