| Literature DB >> 25302330 |
Abstract
An anonymous authentication scheme for roaming services in global mobility networks allows a mobile user visiting a foreign network to achieve mutual authentication and session key establishment with the foreign-network operator in an anonymous manner. In this work, we revisit He et al.'s anonymous authentication scheme for roaming services and present previously unpublished security weaknesses in the scheme: (1) it fails to provide user anonymity against any third party as well as the foreign agent, (2) it cannot protect the passwords of mobile users due to its vulnerability to an offline dictionary attack, and (3) it does not achieve session-key security against a man-in-the-middle attack. We also show how the security weaknesses of He et al.'s scheme can be addressed without degrading the efficiency of the scheme.Entities:
Mesh:
Year: 2014 PMID: 25302330 PMCID: PMC4180899 DOI: 10.1155/2014/687879
Source DB: PubMed Journal: ScientificWorldJournal ISSN: 1537-744X
System parameters.
|
| The identities of |
|
| Two large primes such that |
|
| The master secret key of |
|
| A (cryptographically strong) key shared between |
| ( | A pair of symmetric encryption and decryption algorithms |
|
| A cryptographic hash function |
Algorithm 1Login and key agreement phase of He et al.'s scheme [12].
Figure 1A man-in-the-middle attack on He et al.'s scheme.
Algorithm 2The login and key agreement phase of our improved scheme.