an efficient biometrics-based remote user authentication scheme using smart cards

10
An efficient biometrics-based remote user authentication scheme using smart cards Source: Journal of Network and Computer Applications, Vol. 33, No. 1, pp. 1-5, January 2010 Authors: Chun-Ta Li and Min-Shiang Hwang Reporter: Ya-Chieh Huang Date: 2009/11/05

Upload: kevin-mabini

Post on 27-Oct-2014

15 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

An efficient biometrics-based remote user authentication scheme using smart cards

Source: Journal of Network and Computer Applications, Vol. 33, No. 1, pp. 1-5, January 2010

Authors: Chun-Ta Li and Min-Shiang Hwang

Reporter: Ya-Chieh Huang

Date: 2009/11/05

Page 2: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

2

Introduction

Page 3: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

3

The proposed protocol (1/5)

The protocol is divided into three phases: Registration Phase Login Phase Authentication Phase

Two participants: User (U) Server (S)

Page 4: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

U User

S Server

ID Identity of user

PW Password generated by user (U)

B Biometric template of the user

h( . ) One-way hash function

XS A secret information maintained by the server

|| Concatenation of messages

⊕ XOR operation4

The proposed protocol (2/5)

Notations

Page 5: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

5

The proposed protocol (3/5)Registration Phase

U

rXIDhe

fPWhr

Bhf

S

)(

)||(

)( Computes

},),(,{ cardsmart efhID

PWBID ,,

S

Page 6: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

6

The proposed protocol (4/5)Login Phase

U S

U

S

R

XIDhre

fPWhr

PW

fBh

B

random Selects

)('

)||( Computes

Inputs

)( Verifies

inputs and cardsmart theInserts?

US RXIDhID )(,

Page 7: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

7

The proposed protocol (5/5)Authentication Phase

U S

S

UUS

S

R

RARXIDh

XIDhA

random Selects

)(

)( Computes

SSUUS RXIDhRRXIDhh )(),||)((

SSSS

UUS

RXIDhRXIDh

RRXIDhh

)()( Computes

)||)(( Verifies

)||)(( SS RRXIDhh S

)||)(( Verifies SSS RRXIDhh

Page 8: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

Change password

8

U

)||()(

)('

)||( Computes

Inputs

)( Verifies

inputs and cardsmart theInserts?

fPWhXIDhe

XIDhre

fPWhr

PW

fBh

B

newSnew

S

Page 9: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

9

Comparisons

Lee–Chiu (2005) Khan et al. (2008) Our scheme

Registration phase 2H + 1E 2H 3H

Login phase 2H + 1E 2H 2H

Authentication phase 2H 5H 5H

Change password Yes Yes Yes

Mutual authentication No Yes Yes

Synchronized clocks Yes Yes No

Non-repudiation No Yes Yes

Page 10: An Efficient Biometrics-based Remote User Authentication Scheme Using Smart Cards

10

Conclusions

Non-repudiation

Low computation costs

Without synchronized clocks

Mutual authentication

Freely change password