| Literature DB >> 24350272 |
Muhammad Khurram Khan1, Saru Kumari2.
Abstract
The authors review the biometrics-based user authentication scheme proposed by An in 2012. The authors show that there exist loopholes in the scheme which are detrimental for its security. Therefore the authors propose an improved scheme eradicating the flaws of An's scheme. Then a detailed security analysis of the proposed scheme is presented followed by its efficiency comparison. The proposed scheme not only withstands security problems found in An's scheme but also provides some extra features with mere addition of only two hash operations. The proposed scheme allows user to freely change his password and also provides user anonymity with untraceability.Entities:
Mesh:
Year: 2013 PMID: 24350272 PMCID: PMC3856130 DOI: 10.1155/2013/491289
Source DB: PubMed Journal: Biomed Res Int Impact factor: 3.411
Notations with their description.
| Notations | Description |
|---|---|
|
| Trusted registration centre |
|
| Server |
|
| User |
| ID | Identity of |
| PW | Password of |
|
| Biometric template of |
| SC | Smart card of |
|
| Random number chosen by |
|
| Random number generated by SC |
|
| Random number generated by |
|
| Attacker |
|
| Secret keys maintained by |
|
| One-way hash function |
| ⊕ | Bitwise XOR operator |
| || | Concatenation operator |
Figure 1The proposed scheme.
Comparison of security attributes.
| Security attributes | Schemes | |||
|---|---|---|---|---|
| Li-Hwang's [ | Das's [ | An's [ | Ours | |
| Resist online PW | No | No | No | Yes |
| Resist offline PW | No | No | No | Yes |
| Resist user impersonation attack | No | No | No | Yes |
| Resist server impersonation attack | No | No | No | Yes |
| Provides mutual authentication | No | No | No | Yes |
| Provides PW | Yes | Yes | No | Yes |
| Provides user anonymity | No | No | No | Yes |
Comparison of computational load in terms of hash functions.
| Phases | Schemes | |||
|---|---|---|---|---|
| Li-Hwang's [ | Das's [ | An's [ | Ours | |
| Registration phase | 3 | 3 | 3 | 4 |
| Login phase | 2 | 2 | 3 | 3 |
| Authentication phase | 5 | 8 | 6 | 7 |
|
| ||||
| Total | 10 | 13 | 12 | 14 |