Abstract
Anonymous user authentication is an essential security mechanism for roaming services in global mobility networks (GLOMONET). Recently, Zhao et al. propose a two-factor anonymous authentication scheme to achieve mutual authentication and session key establishment between the mobile user (MU) and a foreign agent (FA). This paper shows that their scheme has some security vulnerabilities and operational inefficiencies: (1) The scheme fails to protect against a strong replay attack, (2) it is impractical because it requires the predistribution of system parameters, and (3) it is inefficient because of unnecessary encryption/decryption operations. To remedy these weaknesses, this paper proposes a novel anonymous authentication scheme using a smart card. The proposed scheme provides security requirements such as user anonymity, perfect forward secrecy, correct password change, authentication when the MU is located in the home network (HN), and no predistribution of system parameters. In addition, the proposed scheme is secure against various attacks such as impersonation attack, replay attack, off-line password attack, insider attack, stolen-verifier attack, and local password attack. A performance analysis and a comparison with existing schemes show that the proposed scheme is more suitable for low-power and resource-limited mobile environments.
Author supplied keywords
Cite
CITATION STYLE
Ha, J. (2015). An efficient and robust anonymous authentication scheme in global mobility networks. International Journal of Security and Its Applications, 9(10), 297–312. https://doi.org/10.14257/ijsia.2015.9.10.27
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.