Skip to main navigation Skip to search Skip to main content

An improved authentication protocol–based dynamic identity for multi-server environments

  • Jianming Cui
  • , Xiaojun Zhang*
  • , Ning Cao
  • , Dexue Zhang
  • , Jianrui Ding
  • , Guofu Li
  • *Corresponding author for this work
  • Shandong University of Science and Technology
  • Qingdao Binhai University
  • Harbin Institute of Technology Weihai
  • University of Shanghai for Science and Technology

Research output: Contribution to journalArticlepeer-review

Abstract

The age of Internet of things gives rise to more challenges to various secure demands when designing the protocols, such as object identification and tracking, and privacy control. In many of the current protocols, a malicious server may cheat users as if it was a legal server, making it vital to verify the legality of both users and servers with the help of a trusted third-party, such as a registration center. Li et al. proposed an authentication protocol based on dynamic identity for multi-server environment, which is still susceptible to password-guessing attack, eavesdropping attack, masquerade attack, and insider attack etc. Besides, their protocol does not provide the anonymity of users, which is an essential request to protect users’ privacy. In this article, we present an improved authentication protocol, depending on the registration center in multi-server environments to remedy these security flaws. Different from the previous protocols, registration center in our proposed protocol is one of parties in authentication phase to verify the legality of the users and the servers, thus can effectively avoid the server spoofing attack. Our protocol only uses nonce, exclusive-OR operation, and one-way hash function in its implementation. Formal analysis has been performed using the Burrows–Abadi–Needham logic to show its security.

Original languageEnglish
JournalInternational Journal of Distributed Sensor Networks
Volume14
Issue number5
DOIs
StatePublished - 1 May 2018
Externally publishedYes

Keywords

  • Burrows–Abadi–Needham logic
  • Dynamic identity
  • multi-server
  • registration center
  • smart card

Fingerprint

Dive into the research topics of 'An improved authentication protocol–based dynamic identity for multi-server environments'. Together they form a unique fingerprint.

Cite this