Enhancing Biometric and Mutual Verification in Multi-server Three-factor User Remote Authentication Scheme with Elliptic Curve Cryptography

Chih-Hung Wang, Kuei-Ching Hsu · 2019

An elliptic curve based three-factor remote authentication scheme was proposed to provide more protections in multi-server network communications. Recently, many papers have proposed biometric-based three factor remote user authentication protocols (such as Chaturvedi et al.'s, Kumari et al.'s and Feng et al.'s schemes); their schemes achieved user anonymity as well as three-factor authentication. However, some of these schemes did not provide server's verification on biometric information and/or support registration center (RC) in authenticating users independently. Further, most of these papers did not provide strongly mutual authentication to pre-verify the possible threats of replay attacks. Therefore, we proposed a novel protocol using more secure and efficient building element, elliptic curve cryptography (ECC), to create the shared keys among the three parties, in which the remote server can verify biometric information and RC can confirm the registrations. The analysis shows that our proposed scheme has more security considerations than the previous researches.

Read the paper · More papers on PaperTik