Client-Server Multi-Factor Authentication Using Pairings
نویسنده
چکیده
What would be the ideal attributes of a client-server authentication scheme? One might like an identity based scheme not requiring PKI, plus support for multi-factor authentication based on a token, a PIN number, and optionally a biometric. The former might hold a high-entropy secret, and the latter may be represented as relatively lowentropy parameters. However it would be preferred if the token could be in the form of a relatively inexpensive USB stick rather than a SmartCard. The user should be at complete liberty to choose and change a PIN number, but if they forget it a recovery mechanism should be available. A fuzzy biometric measurement could be supported and accepted if accurate within certain limits. However the Server should not be required to store any information derived from client secrets, so there should be no equivalent of a vulnerable “password file”. In fact neither the PIN nor the biometric should be stored anywhere (other than in the client’s brain or as part of the client’s body respectively). Reasonable performance on relatively low-powered devices should be possible. The damage caused by compromise of the Server and the loss of its long term secrets should be mitigated as much as possible. The property of Perfect Forward Secrecy, a requirement for clients concerned about long-term privacy, should be supported. In this paper we aim to deliver such a scheme.
منابع مشابه
A New Secure Mutual Authentication Scheme with Smart Cards Using Bilinear Pairings
Mutual authentication is an important security property for providing secure remote communication in client-server environment. Up to now, various remote user authentication schemes with smart card using bilinear pairings were proposed by different researchers. Unfortunately, most previously proposed authentication schemes do not provide mutual authentication and session key agreement. This pap...
متن کاملThree Attacks on Jia et al.’s Remote User Authentication Scheme using Bilinear Pairings and ECC
Recently, Jia et al. proposed a remote user authentication scheme using bilinear pairings and an Elliptic Curve Cryptosystem (ECC). However, the scheme is vulnerable to privileged insider attack at their proposed registration phase and to forgery attack at their proposed authentication phase. In addition, the scheme can be vulnerable to server spoofing attack because it does not provide mutual ...
متن کاملM-Pin: A Multi-Factor Zero Knowledge Authentication Protocol
Here we introduce the M-Pin client-server protocol, which features two-factor client authentication as an alternative to Username/Password. Despite the mathematical complexity of the protocol we demonstrate that an M-Pin client can be implemented in an environment with limited computational capability.
متن کاملThreshold Password-Based Authentication Using Bilinear Pairings
We present a new threshold password-based authentication protocol that allows a roaming user(a user who accesses a network from different client terminals) to download a private key from remote servers with knowledge of only his identity and password. He does not carry the smart card storing user’s private information. We note that as a goal of a multi-server roaming system, a protocol has to a...
متن کاملA biometric-based Password Authentication with key Exchange Scheme using Mobile Device for Multi-Server Environment
Remote authentication for multi-server environment can help users register only once and access arbitrary services conveniently in the same registry realm. However, most of the solutions are plagued by security problems. In this paper, we point out that ‘a novel smart card and dynamic ID based remote user authentication scheme for multi-server environment’ is vulnerable to user impersonation at...
متن کامل