Cryptanalysis and improvement of a Multi-server Authentication protocol by Lu et al.
Azeem Irshad, Muhammad Sher, Bander A. Alzahrani, Aiiad Ahmad Albeshri, Shehzad Ashraf Chaudhry, Saru Kumari · KSII Transactions on Internet and Information Systems · 2018
The increasing number of subscribers and demand of multiplicity of services has turned Multi-Server Authentication (MSA) into an integral part of remote authentication paradigm.MSA not only offers an efficient mode to register the users by engaging a trusted third party (Registration Centre), but also a cost-effective architecture for service procurement, onwards.Recently, Lu et al.'s scheme demonstrated that Mishra et al.'s scheme is unguarded to perfect forward secrecy compromise, server masquerading, and forgery attacks, and presented a better scheme.However, we discovered that Lu et al.'s scheme is still susceptible to malicious insider attack and non-compliant to perfect forward secrecy.This study presents a critical review on Lu et al.'s scheme and then proposes a secure multi-server authentication scheme.The security properties of contributed work are validated with automated Proverif tool and proved under formal security analysis.