Scispace (Formerly Typeset)
  1. Home
  2. Topics
  3. Authentication protocol
  4. 2015
  1. Home
  2. Topics
  3. Authentication protocol
  4. 2015
Showing papers on "Authentication protocol published in 2015"
Journal Article•10.1109/TIFS.2015.2439964•
A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards

[...]

Vanga Odelu1, Ashok Kumar Das2, Adrijit Goswami1•
Indian Institute of Technology Kharagpur1, International Institute of Information Technology, Hyderabad2
01 Jun 2015-IEEE Transactions on Information Forensics and Security
TL;DR: This paper first analyzes He-Wang's scheme, then proposes a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities and shows that the proposed scheme provides secure authentication.
Abstract: Recently, in 2014, He and Wang proposed a robust and efficient multi-server authentication scheme using biometrics-based smart card and elliptic curve cryptography (ECC). In this paper, we first analyze He–Wang’s scheme and show that their scheme is vulnerable to a known session-specific temporary information attack and impersonation attack. In addition, we show that their scheme does not provide strong user’s anonymity. Furthermore, He–Wang’s scheme cannot provide the user revocation facility when the smart card is lost/stolen or user’s authentication parameter is revealed. Apart from these, He–Wang’s scheme has some design flaws, such as wrong password login and its consequences, and wrong password update during password change phase. We then propose a new secure multi-server authentication protocol using biometric-based smart card and ECC with more security functionalities. Using the Burrows–Abadi–Needham logic, we show that our scheme provides secure authentication. In addition, we simulate our scheme for the formal security verification using the widely accepted and used automated validation of Internet security protocols and applications tool, and show that our scheme is secure against passive and active attacks. Our scheme provides high security along with low communication cost, computational cost, and variety of security features. As a result, our scheme is very suitable for battery-limited mobile devices as compared with He–Wang’s scheme.

417 citations

Journal Article•10.1109/JSYST.2014.2301517•
Robust Biometrics-Based Authentication Scheme for Multiserver Environment

[...]

Debiao He1, Ding Wang2•
Wuhan University1, Peking University2
01 Sep 2015-IEEE Systems Journal
TL;DR: This paper proposes a biometrics-based authentication scheme for multiserver environment using elliptic curve cryptography and demonstrates the completeness of the proposed scheme using the Burrows-Abadi-Needham logic.
Abstract: The authentication scheme is an important cryptographic mechanism, through which two communication parties could authenticate each other in the open network environment To satisfy the requirement of practical applications, many authentication schemes using passwords and smart cards have been proposed However, passwords might be divulged or forgotten, and smart cards might be shared, lost, or stolen In contrast, biometric methods, such as fingerprints or iris scans, have no such drawbacks Therefore, biometrics-based authentication schemes gain wide attention In this paper, we propose a biometrics-based authentication scheme for multiserver environment using elliptic curve cryptography To the best of our knowledge, the proposed scheme is the first truly three-factor authenticated scheme for multiserver environment We also demonstrate the completeness of the proposed scheme using the Burrows–Abadi–Needham logic

415 citations

Journal Article•10.1007/S00530-013-0346-9•
Robust anonymous authentication protocol for health-care applications using wireless medical sensor networks

[...]

Debiao He1, Neeraj Kumar2, Jianhua Chen3, Cheng-Chi Lee4, Naveen Chilamkurti5, Seng-Soo Yeo6 •
Chinese Academy of Sciences1, Thapar University2, Wuhan University3, Fu Jen Catholic University4, La Trobe University5, Mokwon University6
01 Feb 2015-Multimedia Systems
TL;DR: A robust anonymous authentication protocol for health-care applications using WMSNs is proposed, which has strong security and computational efficiency and is more suitable for Health-Care applications usingWMSNs.
Abstract: With the fast development of wireless communication technologies and semiconductor technologies, the wireless sensor network (WSN) has been widely used in many applications As an application of the WSN, the wireless medical sensor network (WMSN) could improve health-care quality and has become important in the modern medical system In the WMSN, physiological data are collected by sensors deployed in the patient's body and sent to health professionals' mobile devices through wireless communication Then health professionals could get the status of the patient anywhere and anytime The data collected by sensors are very sensitive and important The leakage of them could compromise the patient's privacy and their malicious modification could harm the patient's health Therefore, both security and privacy are two important issues in WMSNs Recently, Kumar et al proposed an efficient authentication protocol for health-care applications using WMSNs and claimed that it could withstand various attacks However, we find that their protocol is vulnerable to the off-line password guessing attack and the privileged insider attack We also point out that their protocol cannot provide user anonymity In this paper, we will propose a robust anonymous authentication protocol for health-care applications using WMSNs Compared with Kumar et al's protocol, the proposed protocol has strong security and computational efficiency Therefore, it is more suitable for health-care applications using WMSNs

336 citations

Journal Article•10.1109/JSYST.2014.2322973•
A Privacy-Aware Authentication Scheme for Distributed Mobile Cloud Computing Services

[...]

Jia-Lun Tsai1, Nai-Wei Lo1•
National Taiwan University of Science and Technology1
21 May 2015-IEEE Systems Journal
TL;DR: The proposed scheme provides security and convenience for mobile users to access multiple mobile cloud computing services from multiple service providers using only a single private key.
Abstract: In modern societies, the number of mobile users has dramatically risen in recent years. In this paper, an efficient authentication scheme for distributed mobile cloud computing services is proposed. The proposed scheme provides security and convenience for mobile users to access multiple mobile cloud computing services from multiple service providers using only a single private key. The security strength of the proposed scheme is based on bilinear pairing cryptosystem and dynamic nonce generation. In addition, the scheme supports mutual authentication, key exchange, user anonymity, and user untraceability. From system implementation point of view, verification tables are not required for the trusted smart card generator (SCG) service and cloud computing service providers when adopting the proposed scheme. In consequence, this scheme reduces the usage of memory spaces on these corresponding service providers. In one mobile user authentication session, only the targeted cloud service provider needs to interact with the service requestor (user). The trusted SCG serves as the secure key distributor for distributed cloud service providers and mobile clients. In the proposed scheme, the trusted SCG service is not involved in individual user authentication process. With this design, our scheme reduces authentication processing time required by communication and computation between cloud service providers and traditional trusted third party service. Formal security proof and performance analyses are conducted to show that the scheme is both secure and efficient.

298 citations

Journal Article•10.1016/J.PMCJ.2015.08.001•
Secure authentication scheme for IoT and cloud servers

[...]

Sheetal Kalra1, Sandeep K. Sood1•
Guru Nanak Dev University1
01 Dec 2015-Pervasive and Mobile Computing
TL;DR: A secure ECC based mutual authentication protocol for secure communication of embedded devices and cloud servers using Hyper Text Transfer Protocol (HTTP) cookies has been proposed and achieves mutual authentication and provides essential security requirements.

296 citations

Proceedings Article•
Sound-proof: usable two-factor authentication based on ambient sound

[...]

Nikolaos Karapanos1, Claudio Marforio1, Claudio Soriente1, Srdjan Capkun1•
ETH Zurich1
12 Aug 2015
TL;DR: Sound-Proof as discussed by the authors is a two-factor authentication scheme that does not require interaction between the user and his phone, and can be easily deployed as it works with current phones and major browsers without plugins.
Abstract: Two-factor authentication protects online accounts even if passwords are leaked. Most users, however, prefer password-only authentication. One reason why two-factor authentication is so unpopular is the extra steps that the user must complete in order to log in. Currently deployed two-factor authentication mechanisms require the user to interact with his phone to, for example, copy a verification code to the browser. Two-factor authentication schemes that eliminate user-phone interaction exist, but require additional software to be deployed. In this paper we propose Sound-Proof, a usable and deployable two-factor authentication mechanism. Sound-Proof does not require interaction between the user and his phone. In Sound-Proof the second authentication factor is the proximity of the user's phone to the device being used to log in. The proximity of the two devices is verified by comparing the ambient noise recorded by their microphones. Audio recording and comparison are transparent to the user, so that the user experience is similar to the one of password-only authentication. Sound-Proof can be easily deployed as it works with current phones and major browsers without plugins. We build a prototype for both Android and iOS. We provide empirical evidence that ambient noise is a robust discriminant to determine the proximity of two devices both indoors and outdoors, and even if the phone is in a pocket or purse. We conduct a user study designed to compare the perceived usability of Sound-Proof with Google 2-Step Verification. Participants ranked Sound-Proof as more usable and the majority would be willing to use Sound-Proof even for scenarios in which two-factor authentication is optional.

211 citations

Journal Article•10.1109/TIFS.2015.2414399•
Revocable and Scalable Certificateless Remote Authentication Protocol With Anonymity for Wireless Body Area Networks

[...]

Hu Xiong1, Zhiguang Qin1•
University of Electronic Science and Technology of China1
18 Mar 2015-IEEE Transactions on Information Forensics and Security
TL;DR: A remote authentication protocol featured with nonrepudiation, client anonymity, key escrow resistance, and revocability for extra-body communication in the WBANs, and a certificateless anonymous remote authentication with revocation is constructed by incorporating the proposed encryption scheme and signature scheme.
Abstract: To ensure the security and privacy of the patient’s health status in the wireless body area networks (WBANs), it is critical to secure the extra-body communication between the smart portable device held by the WBAN client and the application providers, such as the hospital, physician or medical staff. Based on certificateless cryptography, this paper proposes a remote authentication protocol featured with nonrepudiation, client anonymity, key escrow resistance, and revocability for extra-body communication in the WBANs. First, we present a certificateless encryption scheme and a certificateless signature scheme with efficient revocation against short-term key exposure, which we believe are of independent interest. Then, a certificateless anonymous remote authentication with revocation is constructed by incorporating the proposed encryption scheme and signature scheme. Our revocation mechanism is highly scalable, which is especially suitable for the large-scale WBANs, in the sense that the key-update overhead on the side of trusted party increased logarithmically in the number of users. As far as we know, this is the first time considering the revocation functionality of anonymous remote authentication for the WBANs. Both theoretic analysis and experimental simulations show that the proposed authentication protocol is provably secure in the random oracle model and highly practical.

191 citations

Patent•
Method of handling wireless charging authentication

[...]

Feng-Seng Chu1•
HTC1
11 Feb 2015
TL;DR: In this article, a method of handling wireless charging authentication for an electronic device of a wireless charging system is described, which includes sending a first message to a controller of the wireless charging systems to notify the controller that an authentication is required by a wireless charger of the system; receiving a second message including authentication information from the controller; and sending a third message including the authentication information to the wireless charger, in order to satisfy the authentication.
Abstract: A method of handling wireless charging authentication for an electronic device of a wireless charging system includes sending a first message to a controller of the wireless charging system to notify the controller that an authentication is required by a wireless charger of the wireless charging system; receiving a second message including authentication information from the controller; and sending a third message including the authentication information to the wireless charger, in order to satisfy the authentication.

190 citations

Journal Article•10.1007/S10916-015-0258-7•
A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity

[...]

Ruhul Amin1, G. P. Biswas1•
Indian Institute of Technology Dhanbad1
01 Aug 2015-Journal of Medical Systems
TL;DR: This paper has scrutinized two remote user authentication protocols using smart card and explained that both the protocols are suffering against several security weaknesses, and presented three-factor user authentication and key agreement protocol usable for TMIS, which fix the security pitfalls.
Abstract: Telecare medical information system (TMIS) makes an efficient and convenient connection between patient(s)/user(s) and doctor(s) over the insecure internet. Therefore, data security, privacy and user authentication are enormously important for accessing important medical data over insecure communication. Recently, many user authentication protocols for TMIS have been proposed in the literature and it has been observed that most of the protocols cannot achieve complete security requirements. In this paper, we have scrutinized two (Mishra et al., Xu et al.) remote user authentication protocols using smart card and explained that both the protocols are suffering against several security weaknesses. We have then presented three-factor user authentication and key agreement protocol usable for TMIS, which fix the security pitfalls of the above mentioned schemes. The informal cryptanalysis makes certain that the proposed protocol provides well security protection on the relevant security attacks. Furthermore, the simulator AVISPA tool confirms that the protocol is secure against active and passive attacks including replay and man-in-the-middle attacks. The security functionalities and performance comparison analysis confirm that our protocol not only provide strong protection on security attacks, but it also achieves better complexities along with efficient login and password change phase as well as session key verification property.

133 citations

Journal Article•10.1109/TPDS.2014.2311791•
Aggregated-Proof Based Hierarchical Authentication Scheme for the Internet of Things

[...]

Huansheng Ning1, Hong Liu2, Laurence T. Yang3•
University of Science and Technology Beijing1, Beihang University2, Huazhong University of Science and Technology3
01 Mar 2015-IEEE Transactions on Parallel and Distributed Systems
TL;DR: This work focuses on an existing U2IoT architecture, to design an aggregated-proof based hierarchical authentication scheme (APHA) for the layered networks, and proves that the BAN logic formal analysis is performed to prove that the proposed APHA has no obvious security defects.
Abstract: The Internet of Things (IoT) is becoming an attractive system paradigm to realize interconnections through the physical, cyber, and social spaces. During the interactions among the ubiquitous things, security issues become noteworthy, and it is significant to establish enhanced solutions for security protection. In this work, we focus on an existing U2IoT architecture (i.e., unit IoT and ubiquitous IoT), to design an aggregated-proof based hierarchical authentication scheme (APHA) for the layered networks. Concretely, 1) the aggregated-proofs are established for multiple targets to achieve backward and forward anonymous data transmission; 2) the directed path descriptors, homomorphism functions, and Chebyshev chaotic maps are jointly applied for mutual authentication; 3) different access authorities are assigned to achieve hierarchical access control. Meanwhile, the BAN logic formal analysis is performed to prove that the proposed APHA has no obvious security defects, and it is potentially available for the U2IoT architecture and other IoT applications.

129 citations

Patent•
Method and apparatus for authentication and identity management of communicating devices

[...]

David Gross1, Joshua Lackey1, Donald E. Levy1, Roger Piqueras Jover1, Jayaraman Ramachandran1, Cristina Serban1 •
AT&T1
12 Jun 2015
TL;DR: In this article, a second waveguide system with a non-optical frequency range has been described, where the electromagnetic waves are guided by the transmission medium, and the authentication protocol is based on authentication information contained in the electromagnetic signals.
Abstract: Aspects of the subject disclosure may include, for example, receiving, from a second waveguide system, electromagnetic waves at a physical interface of a transmission medium that propagate without utilizing an electrical return path where the electromagnetic waves are guided by the transmission medium and where the electromagnetic waves have a non-optical frequency range, and authenticating the second waveguide system according to an authentication protocol based on authentication information contained in the electromagnetic waves. Other embodiments are disclosed.
Journal Article•10.1016/J.COSE.2015.06.001•
Continuous user authentication using multi-modal biometrics

[...]

Hataichanok Saevanee1, Nathan Clarke2, Steven Furnell2, Valerio Biscione1•
University of Plymouth1, Edith Cowan University2
01 Sep 2015-Computers & Security
TL;DR: A novel text-based multimodal biometric approach utilizing linguistic analysis, keystroke dynamics and behavioural profiling, designed to provide continuous transparent mobile authentication, is proposed to increase mobile handset security.
Journal Article•10.1007/S10916-015-0217-3•
A Novel User Authentication and Key Agreement Protocol for Accessing Multi-Medical Server Usable in TMIS

[...]

Ruhul Amin1, G. P. Biswas1•
Indian Institute of Technology Dhanbad1
01 Mar 2015-Journal of Medical Systems
TL;DR: The security and performance comparison analysis confirm that the proposed protocol not only provides security protection on the above mentioned attacks, but it also achieves better complexities along with efficient login and password change phase.
Abstract: Telecare Medical Information System (TMIS) makes an efficient and convenient connection between patient(s)/user(s) at home and doctor(s) at a clinical center. To ensure secure connection between the two entities (patient(s)/user(s), doctor(s)), user authentication is enormously important for the medical server. In this regard, many authentication protocols have been proposed in the literature only for accessing single medical server. In order to fix the drawbacks of the single medical server, we have primarily developed a novel architecture for accessing several medical services of the multi-medical server, where a user can directly communicate with the doctor of the medical server securely. Thereafter, we have developed a smart card based user authentication and key agreement security protocol usable for TMIS system using cryptographic one-way hash function. We have analyzed the security of our proposed authentication scheme through both formal and informal security analysis. Furthermore, we have simulated the proposed scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and showed that the scheme is secure against the replay and man-in-the-middle attacks. The informal security analysis is also presented which confirms that the protocol has well security protection on the relevant security attacks. The security and performance comparison analysis confirm that the proposed protocol not only provides security protection on the above mentioned attacks, but it also achieves better complexities along with efficient login and password change phase.
Journal Article•10.1109/TPDS.2014.2308218•
Shared Authority Based Privacy-Preserving Authentication Protocol in Cloud Computing

[...]

Hong Liu1, Huansheng Ning2, Qingxu Xiong1, Laurence T. Yang3•
Beihang University1, University of Science and Technology Beijing2, Huazhong University of Science and Technology3
01 Jan 2015-IEEE Transactions on Parallel and Distributed Systems
TL;DR: A shared authority based privacy-preserving authentication protocol (SAPA) is proposed to address above privacy issue for cloud storage and universal composability model is established to prove that the SAPA theoretically has the design correctness.
Abstract: Cloud computing is an emerging data interactive paradigm to realize users' data remotely stored in an online cloud server. Cloud services provide great conveniences for the users to enjoy the on-demand cloud applications without considering the local infrastructure limitations. During the data accessing, different users may be in a collaborative relationship, and thus data sharing becomes significant to achieve productive benefits. The existing security solutions mainly focus on the authentication to realize that a user's privative data cannot be illegally accessed, but neglect a subtle privacy issue during a user challenging the cloud server to request other users for data sharing. The challenged access request itself may reveal the user's privacy no matter whether or not it can obtain the data access permissions. In this paper, we propose a shared authority based privacy-preserving authentication protocol (SAPA) to address above privacy issue for cloud storage. In the SAPA, 1) shared access authority is achieved by anonymous access request matching mechanism with security and privacy considerations (e.g., authentication, data anonymity, user privacy, and forward security); 2) attribute based access control is adopted to realize that the user can only access its own data fields; 3) proxy re-encryption is applied to provide data sharing among the multiple users. Meanwhile, universal composability (UC) model is established to prove that the SAPA theoretically has the design correctness. It indicates that the proposed protocol is attractive for multi-user collaborative cloud applications.
Patent•
Authentication in ubiquitous environment

[...]

Unho Choi
22 Apr 2015
TL;DR: In this article, an authentication mechanism including the first user authentication and the second user authentication is applied to control an access to the IoT device, including one time password, keystroke, dynamic signature, location information, and the like.
Abstract: In some embodiments, encrypted biometric data are stored in advance in a device that is possessed or carried by a user (for example, a smartcard, a communication terminal, or the like) based on a public key certificate, and a user authentication (first user authentication) is performed by a biometric matching in the device. A public key certificate matching the encrypted biometric data is used to perform a user authentication (second user authentication) for a transaction authorization in a service providing server. According to some embodiments, one time password, keystroke, dynamic signature, location information, and the like are employed as additional authentication factors to tighten the security of the first and second user authentications. According to some embodiments, an authentication mechanism including the first user authentication and the second user authentication is applied to control an access to the IoT device.
Proceedings Article•10.1145/2753476.2753477•
Key Management Protocol with Implicit Certificates for IoT systems

[...]

Savio Sciancalepore1, Angelo Capossele2, Giuseppe Piro1, Gennaro Boggia1, Giuseppe Bianchi2 •
Instituto Politécnico Nacional1, Sapienza University of Rome2
18 May 2015
TL;DR: This paper proposes a Key Management Protocol for mobile and industrial Internet of Things systems, targeting, at the same time, robust key negotiation, lightweight node authentication, fast re-keying, and efficient protection against replay attacks.
Abstract: This paper proposes a Key Management Protocol for mobile and industrial Internet of Things systems, targeting, at the same time, robust key negotiation, lightweight node authentication, fast re-keying, and efficient protection against replay attacks. The proposed approach pragmatically leverages widely accepted Elliptic Curve Cryptography constructions, specifically the (Elliptic Curve) "Fixed" Diffie Hellman key exchange and the (Elliptic Curve) Qu-Vanstone implicit certificates. Our value added is their suitable integration into a security protocol exchange, designed at layer 2, in the 802.15.4 protocol stack, which permits to i) avoid Elliptic Point multiplications upon rekeying of previously paired devices, and ii) support mutual authentication while securing the protocol exchange. To prove its viability, the proposed Key Management Protocol has been implemented and assessed on severely constrained devices. As expected, but made explicit and quantified by our experimental performance evaluation, the usage of implicit certificates in conjunction with an optimized message exchange yields impressive gains in terms of airtime consumption with respect to state of the art schemes.
Patent•
Continuous authentication with a mobile device

[...]

Eliza Yingzi Du1, Suryaprakash Ganti1, Muhammed Ibrahim Sezan1, Jonathan Charles Griffiths1, David William Burns1, Samir Kumar Gupta1 •
Qualcomm1
20 Feb 2015
TL;DR: In this article, a mobile device may perform continuous authentication with an authenticating entity, including a set of biometric and non-biometric sensors and a processor, and the processor may be configured to receive sensor data from the set of sensors, form authentication information from the received sensor data, and continuously update the authentication information.
Abstract: A mobile device may perform continuous authentication with an authenticating entity. The mobile device may include a set of biometric and non-biometric sensors and a processor. The processor may be configured to receive sensor data from the set of sensors, form authentication information from the received sensor data, and continuously update the authentication information.
Journal Article•10.1007/S12083-014-0248-4•
An improved authentication protocol for session initiation protocol using smart card

[...]

Hang Tu1, Neeraj Kumar2, Naveen Chilamkurti3, Seungmin Rho•
Wuhan University1, Thapar University2, La Trobe University3
01 Sep 2015-Peer-to-peer Networking and Applications
TL;DR: Security analysis and performance analysis shows that the improved protocol proposed could overcome the weaknesses in Zhang et al.
Abstract: The session initiation protocol (SIP) is the most widely used signaling protocol for controlling communication on the Internet, establishing, maintaining, and terminating the sessions. To get secure communication, many authentication protocols for SIP have been proposed. Very recently, Zhang et al. proposed a new authenticated key agreement protocol for SIP using smart card. They also show their protocol could withstand various attacks. However, in this paper, we point out that their protocol is vulnerable to the impersonation attack. We also propose an improved protocol to overcome the weakness. Security analysis shows that our protocol could overcome the weaknesses in Zhang et al.’s protocol. Performance analysis shows that the computational cost in the authentication phase of our protocol is about 75 % of Zhang et al.’s protocol.
Patent•
Systems and methods for personal identification and verification

[...]

Marcus Andrade
12 Nov 2015
TL;DR: The legal identity-linked credential authentication protocol as mentioned in this paper is a protocol providing a practical solution for the issues related to cryptocurrency theft, KYC and AML, while maintaining user privacy.
Abstract: A personal/client identification and verification process, pseudonymous system and transaction network for monitoring and restricting transactions of cryptography-based electronic money. The present invention—“legal identity-linked credential authentication protocol” is a protocol providing a practical solution for the issues related to cryptocurrency theft, KYC and AML, while maintaining user privacy.
Journal Article•10.1007/S10916-015-0262-Y•
An Improved RSA Based User Authentication and Session Key Agreement Protocol Usable in TMIS

[...]

Ruhul Amin1, G. P. Biswas1•
Indian Institute of Technology Dhanbad1
01 Aug 2015-Journal of Medical Systems
TL;DR: This paper proposes an improved scheme over Giri et al.
Abstract: Recently, Giri et al.'s proposed a RSA cryptosystem based remote user authentication scheme for telecare medical information system and claimed that the protocol is secure against all the relevant security attacks. However, we have scrutinized the Giri et al.'s protocol and pointed out that the protocol is not secure against off-line password guessing attack, privileged insider attack and also suffers from anonymity problem. Moreover, the extension of password guessing attack leads to more security weaknesses. Therefore, this protocol needs improvement in terms of security before implementing in real-life application. To fix the mentioned security pitfalls, this paper proposes an improved scheme over Giri et al.'s scheme, which preserves user anonymity property. We have then simulated the proposed protocol using widely-accepted AVISPA tool which ensures that the protocol is SAFE under OFMC and CL-AtSe models, that means the same protocol is secure against active and passive attacks including replay and man-in-the-middle attacks. The informal cryptanalysis has been also presented, which confirmed that the proposed protocol provides well security protection on the relevant security attacks. The performance analysis section compares the proposed protocol with other existing protocols in terms of security and it has been observed that the protocol provides more security and achieves additional functionalities such as user anonymity and session key verification.
Journal Article•10.1016/J.COMPELECENG.2015.03.030•
An end-to-end secure key management protocol for e-health applications

[...]

Mohammed Riyadh Abdmeziem1, Djamel Tandjaoui•
University of the Sciences1
01 May 2015-Computers & Electrical Engineering
TL;DR: A new lightweight key management protocol based on collaboration to establish a secure end-to-end communication channel between a highly resource constrained node and a remote entity and shows that its security properties are ensured.
Journal Article•10.1007/S11042-013-1807-Z•
A single round-trip SIP authentication scheme for Voice over Internet Protocol using smart card

[...]

Azeem Irshad1, Muhammad Sher1, Eid Rehman1, Shehzad Ashraf Ch1, Mahmood Ul Hassan1, Anwar Ghani1 •
International Islamic University, Islamabad1
01 Jun 2015-Multimedia Tools and Applications
TL;DR: The server can now authenticate the user on the request message received, rather than the response received upon sending the challenge message, saving another round-trip of exchanged messages and hence escapes a possible denial of service attack.
Abstract: The Session Initiation Protocol (SIP) has revolutionized the way of controlling Voice over Internet Protocol (VoIP) based communication sessions over an open channel. The SIP protocol is insecure for being an open text-based protocol inherently. Different solutions have been presented in the last decade to secure the protocol. Recently, Zhang et al. authentication protocol has been proposed with a sound feature that authenticates the users without any password-verifier database using smart card. However, the scheme has a few limitations and can be made more secure and optimized regarding cost of exchanged messages, with a few modifications. Our proposed key-agreement protocol makes a use of two server secrets for robustness and is also capable of authenticating the involved parties in a single round-trip of exchanged messages. The server can now authenticate the user on the request message received, rather than the response received upon sending the challenge message, saving another round-trip of exchanged messages and hence escapes a possible denial of service attack.
Proceedings Article•10.5555/2840819.2840867•
PUF-Based Authentication

[...]

Wenjie Che1, Fareena Saqib2, Jim Plusquellic1•
University of New Mexico1, Florida Institute of Technology2
2 Nov 2015
TL;DR: The requirements for PUF-based authentication are described, and a PUF primitive and protocol designed for authentication in resource constrained devices are presented, derived from a 28 nm Xilinx FPGA.
Abstract: In the context of hardware systems, authentication refers to the process of confirming the identity and authenticity of chip, board and system components such as RFID tags, smart cards and remote sensors. The ability of physical unclonable functions (PUF) to provide bitstrings unique to each component can be leveraged as an authentication mechanism to detect tamper, impersonation and substitution of such components. However, authentication requires a strong PUF, i.e., one capable of producing a large, unique set of bits per device, and, unlike secret key generation for encryption, has additional challenges that relate to machine learning attacks, protocol attacks and constraints on device resources. In this paper, we describe the requirements for PUF-based authentication, and present a PUF primitive and protocol designed for authentication in resource constrained devices. Our experimental results are derived from a 28 nm Xilinx FPGA.1
Journal Article•10.1007/S11277-015-2616-7•
Design and Analysis of Bilinear Pairing Based Mutual Authentication and Key Agreement Protocol Usable in Multi-server Environment

[...]

Ruhul Amin1, G. P. Biswas1•
Indian Institute of Technology Dhanbad1
01 Sep 2015-Wireless Personal Communications
TL;DR: A bilinear pairing based three factors remote user authentication scheme using smart card for providing security weaknesses free protocol and BAN logic is used which ensures that the same protocol achieves mutual authentication and session key agreement property securely.
Abstract: With the increasing popularity and demand for various applications, the internet user accesses remote server by performing remote user authentication protocol using smart card over the insecure channel. In order to resist insider attack, most of the users remember a set of identity and password for accessing different application servers. Therefore, remembering set of identity and password is an extra overhead to the user. To avoid the mentioned shortcoming, many remote user authentication and key agreement protocols for multi-server architecture have been proposed in the literature. Recently, Hsieh---Leu proposed an improve protocol of Liao et al. scheme and claimed that the improve protocol is applicable for practical implementation. However, through careful analysis, we found that Hsieh---Leu scheme is still vulnerable to user anonymity, password guessing attack, server masquerading attack and the password change phase is inefficient. Therefore, the main aim of this paper was to design a bilinear pairing based three factors remote user authentication scheme using smart card for providing security weaknesses free protocol. In order to validate security proof of the proposed protocol, this paper uses BAN logic which ensures that the same protocol achieves mutual authentication and session key agreement property securely. Furthermore, this paper also informally illustrates that the proposed protocol is well protected against all the relevant security attacks. The performance analysis and comparison with other schemes are also made, and it has been found that the proposed protocol achieves complete security requirements with comparatively lesser complexities.
Journal Article•10.1016/J.COSE.2015.05.004•
A realistic lightweight authentication protocol preserving strong anonymity for securing RFID system

[...]

Prosanta Gope1, Tzonelih Hwang1•
National Cheng Kung University1
01 Nov 2015-Computers & Security
TL;DR: This article proposes a realistic lightweight authentication protocol for RFID system, which can ensure various imperative security properties such as anonymity of the RFID tag, untraceability, forward security etc.
Journal Article•10.3390/EN81011883•
State of the Art Authentication, Access Control, and Secure Integration in Smart Grid

[...]

Neetesh Saxena, Bong Jun Choi
21 Oct 2015-Energies
TL;DR: This paper addresses the required objectives of an authentication protocol in the smart grid network along with the focus on mutual authentication, access control, and secure integration among different SG components.
Abstract: The smart grid (SG) is a promising platform for providing more reliable, efficient, and cost effective electricity to the consumers in a secure manner. Numerous initiatives across the globe are taken by both industry and academia in order to compile various security issues in the smart grid network. Unfortunately, there is no impactful survey paper available in the literature on authentications in the smart grid network. Therefore, this paper addresses the required objectives of an authentication protocol in the smart grid network along with the focus on mutual authentication, access control, and secure integration among different SG components. We review the existing authentication protocols, and analyze mutual authentication, privacy, trust, integrity, and confidentiality of communicating information in the smart grid network. We review authentications between the communicated entities in the smart grid, such as smart appliance, smart meter, energy provider, control center (CC), and home/building/neighborhood area network gateways (GW). We also review the existing authentication schemes for the vehicle-to-grid (V2G) communication network along with various available secure integration and access control schemes. We also discuss the importance of the mutual authentication among SG entities while providing confidentiality and privacy preservation, seamless integration, and required access control with lower overhead, cost, and delay. This paper will help to provide a better understanding of current authentication, authorization, and secure integration issues in the smart grid network and directions to create interest among researchers to further explore these promising areas.
Proceedings Article•10.1109/NGMAST.2015.31•
A Lightweight Authentication Scheme for E-Health Applications in the Context of Internet of Things

[...]

Hamza Khemissa, Djamel Tandjaoui
1 Sep 2015
TL;DR: This paper proposes a new lightweight authentication scheme for an e-health application that provides authentication with less energy consumption, and it terminates with a session key agreement between each sensor and the Base Station.
Abstract: The strong development of the Internet of Things (IoT) is changing traditional perceptions of the current Internet towards a vision of smart objects interacting with each other. In this vision e-health applications are one of the most promising applications in IoT. However, security issues are the major obstacle for their deployment. Among these issues, authentication of the different interconnected entities and exchanged data confidentiality constitutes the main concerns for users that need to be addressed. In this paper, we propose a new lightweight authentication scheme for an e-health application. This scheme allows both of sensors and the Base Station (BS) to authenticate each other in order to secure the collection of health-related data. Our scheme uses nonces and Keyed-Hash message authentication (HMAC) to check the integrity of authentication exchanges. In addition, it provides authentication with less energy consumption, and it terminates with a session key agreement between each sensor and the Base Station. To assess our scheme, we carry out a performance and security analysis. The obtained results show that our scheme saves energy. In addition, it is resistant against different types of attacks.
Journal Article•10.1007/S11042-014-1885-6•
A secure authentication scheme with anonymity for session initiation protocol using elliptic curve cryptography

[...]

Zezhong Zhang1, Qingqing Qi1, Neeraj Kumar2, Naveen Chilamkurti3, Hwa-Young Jeong4 •
North China University of Water Conservancy and Electric Power1, Thapar University2, La Trobe University3, Kyung Hee University4
01 May 2015-Multimedia Tools and Applications
TL;DR: By a sophisticated analysis of the security of the proposed protocol, it is shown that the proposed authentication scheme with anonymity using elliptic curve cryptograph not only overcomes weaknesses in previous schemes but also is very efficient, suitable for applications with higher security requirements.
Abstract: As a signaling protocol for controlling communication on the internet, establishing, maintaining, and terminating the sessions, the Session Initiation Protocol (SIP) is widely used in the world of multimedia communication. To ensure communication security, many authentication schemes for the SIP have been proposed. However, those schemes cannot ensure user privacy since they cannot provide user anonymity. To overcome weaknesses in those authentication schemes with anonymity for SIP, we propose an authentication scheme with anonymity using elliptic curve cryptograph. By a sophisticated analysis of the security of the proposed protocol, we show that the proposed scheme not only overcomes weaknesses in previous schemes but also is very efficient. Therefore, it is suitable for applications with higher security requirements.
Journal Article•10.1016/J.COSE.2014.09.001•
Authentication graphs

[...]

Alexander D. Kent1, Lorie M. Liebrock2, Joshua Neil1•
Los Alamos National Laboratory1, New Mexico Institute of Mining and Technology2
01 Feb 2015-Computers & Security
TL;DR: Graph-based approaches to user classification and intrusion detection with practical results and a method for assessing network authentication trust risk and cyber attack mitigation within an enterprise network using bipartite authentication graphs are shown.
Patent•
Declarative techniques for transaction-specific authentication

[...]

Vikas Pooven Chathoth1, Ramya Kukehalli Subramanya1, Khanna Ranjan1•
Business International Corporation1
27 Mar 2015
TL;DR: In this article, the authors present techniques for transaction-specific authentication using modular authentication via declarative requests from applications, where an application can specify one or more transaction factor values to be used in an authentication, and the authentication, using a transaction-signed one-time password, can be directed by an access manager module without further involvement of the application.
Abstract: Techniques are disclosed for providing and/or implementing utilizing declarative techniques for transaction-specific authentication. Certain techniques are disclosed herein that enable transaction signing using modular authentication via declarative requests from applications. An application can declaratively specify one or more transaction factor values to be used in an authentication, and the authentication, using a transaction-signed one-time password, can be directed by an access manager module without further involvement of the application. Upon a successful or non-successful authentication, the access manager module can provide the result back to the application. Accordingly, an authentication process specific to (and valid only for) a particular transaction can be performed without direct involvement of the application and without application-centric knowledge required by the access manager module.
...

Tools

SciSpace AgentBiomedical AgentSciSpace RecruitSciSpace for EnterpriseAgent GalleryChat with PDFLiterature ReviewAI WriterFind TopicsParaphraserCitation GeneratorExtract DataAI DetectorCitation Booster

Learn

ResourcesLive Workshops

SciSpace

CareersSupportBrowse PapersPricingSciSpace Affiliate ProgramCancellation & Refund PolicyTermsPrivacyData Sources

Directories

PapersTopicsJournalsAuthorsConferencesInstitutionsCitation StylesWriting templates

Extension & Apps

SciSpace Chrome ExtensionSciSpace Mobile App

Contact

support@scispace.com
SciSpace

© 2026 | PubGenius Inc. | Suite # 217 691 S Milpitas Blvd Milpitas CA 95035, USA

soc2
Secured by Delve