Robust anonymous two‐factor authenticated key exchange scheme for mobile client‐server environment
Yanrong Lu, Lixiang Li, Haipeng Peng, Yixian Yang · Security and Communication Networks · 2016
Abstract With the greatest advancement of information technology, mobile communication has become more widespread and prevalent. When a mobile user intends to enjoy the services offered by a remote server, he needs to be authenticated before constructing a session key with the corresponding server. Numerous authentication schemes have been provided with the purpose of validating the legitimacy of a mobile user. Recently, Xieet al.presented a modified two‐factor authenticated key exchange to eliminate the security flaws of Chenet al.Xieet al.claimed that the enhanced design was more secure than the design of Chenet al.Unfortunately, we identified that the proposed scheme by Xieet al.was insecure against user impersonation, insider and trace attacks and did fail to provide verification in login phase. To enhance the security and efficiency, we then proposed an anonymous authenticated key exchange scheme for mobile client‐server environment. We demonstrated that the proposed scheme was immune to many attacks including attacks observed in the scheme of Xieet al.We also use a formal proof, namely Burrows–Abadi–Needham logic, to analyze the proposed scheme. In addition, the proposed scheme possesses a lower computation overheads than the other related schemes. Copyright © 2016 John Wiley & Sons, Ltd.