A lightweight dynamic pseudonym identity based authentication and key agreement protocol without verification tables for multi-server architecture
Kaiping Xue,Peilin Hong,Changsha Ma
DOI: https://doi.org/10.1016/j.jcss.2013.07.004
IF: 1.043
2014-02-01
Journal of Computer and System Sciences
Abstract:Traditional password based authentication schemes are mostly considered in single-server environments. They are unfit for the multi-server environments from two aspects. Recently, base on Sood et al.ʼs protocol (2011), Li et al. proposed an improved dynamic identity based authentication and key agreement protocol for multi-server architecture (2012). Li et al. claim that the proposed scheme can make up the security weaknesses of Sood et al.ʼs protocol. Unfortunately, our further research shows that Li et al.ʼs protocol contains several drawbacks and cannot resist some types of known attacks. In this paper, we further propose a lightweight dynamic pseudonym identity based authentication and key agreement protocol for multi-server architecture. In our scheme, service providing servers donʼt need to maintain verification tables for users. The proposed protocol provides not only the declared security features in Li et al.ʼs paper, but also some other security features, such as traceability and identity protection.
computer science, theory & methods, hardware & architecture