About: Authentication protocol is a research topic. Over the lifetime, 13268 publications have been published within this topic receiving 250163 citations.
TL;DR: A new BAN-like logic and a new formal semantics for logics of authentication that is able to handle most kinds of protocols used in practice and able to detect flaws in previous logics is presented.
Abstract: We present a new BAN-like logic and a new formal semantics for logics of authentication. The main focus of this paper is on the foundation of this logic by a possible-worlds semantics. The logic was designed for implementation in the tool AUTLOG and is able to handle most kinds of protocols used in practice. The underlying logic is a K45-logic, including negation. We replace the critical idealization step by changing the set of premises. The formal semantics enables us to detect flaws in previous logics. We apply the logic to a new authentication protocol designed for UMTS.
TL;DR: A robust conditional privacy-preserving authentication protocol without loss of efficiency as compared with ECPP, where RSUs can issue multiple anonymous certificates to an OBU to alleviate system overheads for validity check of RSUs.
Abstract: Recently, Lu et al. proposed an efficient conditional privacy preservation protocol, named ECPP, based on group signature scheme for secure vehicular communications. However, ECPP dose not provide unlinkability and traceability when multiple RSUs are compromised. In this paper, we make up for the limitations and propose a robust conditional privacy-preserving authentication protocol without loss of efficiency as compared with ECPP. Furthermore, in our protocol, RSUs can issue multiple anonymous certificates to an OBU to alleviate system overheads for validity check of RSUs. In order to achieve these goals, we consider a universal re-encryption scheme as our building block.
TL;DR: It is shown how modern verification tools can be used for the falsification and certified verification of security standards, and two design principles for security protocols that suffice to prevent all the weaknesses are proposed.
Abstract: We formally analyze the family of entity authentication protocols defined by the ISO/IEC 9798 standard and find numerous weaknesses, both old and new, including some that violate even the most basic authentication guarantees. We analyze the cause of these weaknesses, propose repaired versions of the protocols, and provide automated, machine-checked proofs of their correctness. From an engineering perspective, we propose two design principles for security protocols that suffice to prevent all the weaknesses. Moreover, we show how modern verification tools can be used for the falsification and certified verification of security standards. Based on our findings, the ISO working group responsible for the ISO/IEC 9798 standard has released an updated version of the standard.
TL;DR: In this article, an authentication system for controlling a person's access to a resource, which may be a physical resource or a network resource, is described, where the authentication system obtains credential information for the person (e.g., using a coded card or keypad for username and password), a voice print from the person, and the current geographical location of the user.
Abstract: An authentication system is described for controlling a person's access to a resource, which may be a physical resource or a network resource. The authentication system obtains credential information for the person (e.g., using a coded card or keypad for username and password), a voice print from the person, and the current geographical location of the user. The voice print and geographic location are preferably obtained from a telephone call that occurs between the person and the authentication system. The call can take the form of a cell phone call placed by the person to the authentication system. The authentication system includes a user profile database. If the credential information and voice print match those of persons authorized to access the resource, and the user is at a registered permissible location to access the resource, the authentication system sends a signal to the resource indicating that the authentication was successful.
TL;DR: The authors shall show that the OSPA protocol is vulnerable to the guessing attacks in this paper.
Abstract: Password authentication is the most important and convenient protocol for verifying users to get the system’s resources Lin et al had proposed an optimal strongpassword authentication protocol (OSPA) which is a onetime password method It can protect against the replaying attacks, impersonation attacks, and denial of service attacks However, the authors shall show that the OSPA protocol is vulnerable to the guessing attacks in this paper