JISE


  [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13] [14] [15] [16] [17]


Journal of Information Science and Engineering, Vol. 31 No. 6, pp. 1975-1992


A Secure Dynamic Identity Based Authentication Protocol with Smart Cards for Multi-Server Architecture


CHUN-TA LI1, CHENG-CHI LEE2,3,*, CHI-YAO WENG4 AND CHUN-I FAN5 
1Department of Information Management 
Tainan University of Technology 
Tainan City, 710 Taiwan 
E-mail: th0040@mail.tut.edu.tw 
2Department of Library and Information Science 
Fu Jen Catholic University 
New Taipei City, 242 Taiwan 
E-mail: cclee@mail.fju.edu.tw 
3Department of Photonics and Communication Engineering 
Asia University 
Taichung City, 413 Taiwan 
4Department of Computer Science 
National Pingtung University 
Pingtung City, 900 Taiwan 
E-mail: cyweng@mail.nptu.edu.tw 
5Department of Computer Science and Engineering 
National Sun Yat-sen University 
Kaohsiung City, 804 Taiwan 
E-mail: cifan@cse.nsysu.edu.tw


    Due to the rapid growth of computer networks and service providing servers, many network environments have been becoming multi-server architecture and various multiserver authentication protocols have been proposed. In such an environment, a user can obtain different network services from multiple network servers without repeating registration to each server. Recently, Li et al. proposed a secure dynamic ID based authentication protocol for multi-server architecture using smart cards. They claimed that their protocol preserves mutual authentication and protected from several attacks. However, in this paper, we find that Li et al.’s protocol cannot provide the protection against leakof- verifier attack, impersonation attack, session key disclosure attack and many logged-in users’ attack. To remedy these security flaws, we propose an improved version of dynamic ID based authentication protocol, which covers all the identified weaknesses of Li et al.’s protocol and is more secure and efficient for practical multi-server environments.


Keywords: dynamic identity, password authentication, smart card, multi-server architecture, user anonymity

  Retrieve PDF document (JISE_201506_09.pdf)