Three-factor authentication scheme for multi-server environments based on elliptic curve cryptography

Pengzhen Xia,Jianhua Chen
DOI: https://doi.org/10.3969/j.issn.1001-3695.2017.10.041
2017-01-01
Abstract:With the increasing of the multi-server application,researches on three-factor authentication scheme which based on password,smart card and biometrics continue ensure the information safety of the communcation parties.Recently,Chaudhry proposed a new three-factor authentication scheme based on elliptic curve cryptosystem.This paper showed that his scheme was vulnerable to not only denial of service attacks,but also user impersonation attack.In addition,users didn't have a unique identifier in his protocol,and they were unable to change the password.To solve these safety deficiencies,this paper proposed an improved scheme,reasonably used the elliptic curve cryptosystem and fuzzy extractor technology to combine three-factor.This paper proves that the proposed scheme is feasible and safe through Burrows-Abadi-Needham (BAN) logic and the analysis of the known attacks.As compared with the previous multi-server authentication schemes,the proposed scheme is more secure and practical.
What problem does this paper attempt to address?