User Centric Three-Factor Authentication Protocol for Cloud-Assisted Wearable Devices.

Qi Jiang,Yuanyuan Qian,Jianfeng Ma,Xindi Ma,Qingfeng Cheng,Fushan Wei
DOI: https://doi.org/10.1002/dac.3900
2018-01-01
International Journal of Communication Systems
Abstract:SummaryWearable devices, which provide the services of collecting personal data, monitoring health conditions, and so on, are widely used in many fields, ranging from sports to healthcare. Although wearable devices bring convenience to people's lives, they bring about significant security concerns, such as personal privacy disclosure and unauthorized access to wearable devices. To ensure the privacy and security of the sensitive data, it is critical to design an efficient authentication protocol suitable for wearable devices. Recently, Das et al proposed a lightweight authentication protocol, which achieves secure communication between the wearable device and the mobile terminal. However, we find that their protocol is vulnerable to offline password guessing attack and desynchronization attack. Therefore, we put forward a user centric three‐factor authentication scheme for wearable devices assisted by cloud server. Informal security analysis and formal analysis using ProVerif is executed to demonstrate that our protocol not only remedies the flaws of the protocol of Das et al but also meets desired security properties. Comparison with related schemes shows that our protocol satisfies security and usability simultaneously.
What problem does this paper attempt to address?