Netinfo Security ›› 2019, Vol. 19 ›› Issue (6): 45-52.doi: 10.3969/j.issn.1671-1122.2019.06.006

Previous Articles     Next Articles

Research on a Biometrics-based Multi-cloud Server Authentication Scheme

Baoyuan KANG, Mingming XIE(), Lin SI   

  1. School of Computer Science and Technology, Tianjin Polytechnic University, Tianjin 300387
  • Received:2018-05-02 Online:2019-06-10 Published:2020-05-11

Abstract:

The progress of wireless communication technology has promoted the development of mobile services. The traditional single server has been unable to accept the multi-user large-scale access. In order to solve this problem, a lot of cloud server authentication scheme are proposed. Based on passwords and smart cards authentication schemes are less security in multi-cloud server environment. Due to biometric technology is closely related to the physical characteristics of the individual, so it has been become the first choice to enhance security. Recently, KUMARI put forward an authentication scheme based on biometric technology in cloud server environment. However, we find that their schemes cannot resist replay attacks. At the same time, the scheme also has loopholes in the mutual authentication stage and lack the mutual authentication key parameters, which lead to users and servers cannot authenticate each other. Therefore, this paper improves KUMARI’s scheme by adding time-stamp and necessary parameter storage. Security analysis shows that the improved scheme not only resists replay attacks, offline password guessing attacks and other common attacks, but also enables users and servers to perform effective authentication.

Key words: authentication scheme, cloud server, smart card, biometric technology, security

CLC Number: