Secure chaotic maps‐based authenticated key agreement protocol without smartcard for multi‐server environments

Jia‐Lun Tsai, Nai‐Wei Lo · Security and Communication Networks · 2014

Abstract Modern individuals heavily rely on the support of information systems. Various applications and information processing systems provide all kinds of assistance for people's lives such as information search, work scheduling, entertainment, and online shopping. For a user, in order to access an Internet‐connected system or an internal system within an enterprise, in general, a unique password is given to the user to log into the system. Therefore, how to conveniently maintain or remember multiple passwords has become a serious headache for people. In this study, a new chaotic maps‐based authenticated key agreement protocol is first proposed for multi‐server environments. A trusted third party, called the registration center (RC), is introduced in our protocol. Once a legal user has registered with the RC, this user can log into any server with only one memorable password in a multi‐server environment as long as the user has been granted access rights in advance. As security robustness of our protocol is built on randomly generated nonces and chaotic maps, there is no time synchronization issue. Security analyses and comparisons on performance efficiency and security features among existing protocols show that our protocol is computationally efficient, and withstands password‐guessing attacks and other well‐known security threats. Copyright © 2014 John Wiley & Sons, Ltd.

Read the paper · More papers on PaperTik