A multiserver environment can improve the efficiency of mobile network services more effectively than a single server in managing the increase in users. Because of the large number of users, the security of users' personal information and communication information is more important in a multiserver environment. Recently, Wang et al. proposed a multiserver authentication scheme based on biometrics and proved the security of their scheme. However, we first demonstrate that their scheme is insecure against a known session-specific temporary information attacks, user impersonation attacks, and server impersonation attacks. To solve the security weakness, we propose an improved scheme based on Wang et al.'s scheme. The security of our improved scheme is also validated based on the formal security analysis, Burrows-Abadi-Needham (BAN) logic, ProVerif, and informal security analysis. Security and performance comparisons prove the security and efficiency of our scheme.
CITATION STYLE
Wu, T. Y., Yang, L., Lee, Z., Chen, C. M., Pan, J. S., & Islam, S. K. H. (2021). Improved ECC-Based Three-Factor Multiserver Authentication Scheme. Security and Communication Networks, 2021. https://doi.org/10.1155/2021/6627956
Mendeley helps you to discover research relevant for your work.