An Improvement of Robust Biometrics-Based Authentication and Key Agreement Scheme for Multi-Server Environments Using Smart Cards

PLoS One. 2015 Dec 28;10(12):e0145263. doi: 10.1371/journal.pone.0145263. eCollection 2015.

Abstract

In multi-server environments, user authentication is a very important issue because it provides the authorization that enables users to access their data and services; furthermore, remote user authentication schemes for multi-server environments have solved the problem that has arisen from user's management of different identities and passwords. For this reason, numerous user authentication schemes that are designed for multi-server environments have been proposed over recent years. In 2015, Lu et al. improved upon Mishra et al.'s scheme, claiming that their remote user authentication scheme is more secure and practical; however, we found that Lu et al.'s scheme is still insecure and incorrect. In this paper, we demonstrate that Lu et al.'s scheme is vulnerable to outsider attack and user impersonation attack, and we propose a new biometrics-based scheme for authentication and key agreement that can be used in multi-server environments; then, we show that our proposed scheme is more secure and supports the required security properties.

Publication types

  • Research Support, Non-U.S. Gov't

MeSH terms

  • Biometric Identification / methods*
  • Computer Security*
  • Computers
  • Confidentiality
  • Health Smart Cards / methods*
  • Humans
  • User-Computer Interface*

Grants and funding

This research was supported by the Basic Science Research Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Science, ICT, and Future Planning (2014R1A1A2002775) (http://www.nrf.re.kr/nrf_eng_cms/). The funders had no role in study design, data collection and analysis, decision to publish, or preparation of the manuscript.