Published November 1, 2015 | Version v1
Journal article

Chaotic maps and biometrics-based anonymous three-party authenticated key exchange protocol without using passwords

  • 1. Hangzhou Key Laboratory of Cryptography and Network Security, Hangzhou Normal University, Hangzhou 311121 (China)

Description

In three-party password authenticated key exchange (AKE) protocol, since two users use their passwords to establish a secure session key over an insecure communication channel with the help of the trusted server, such a protocol may suffer the password guessing attacks and the server has to maintain the password table. To eliminate the shortages of password-based AKE protocol, very recently, according to chaotic maps, Lee et al. [2015 Nonlinear Dyn. 79 2485] proposed a first three-party-authenticated key exchange scheme without using passwords, and claimed its security by providing a well-organized BAN logic test. Unfortunately, their protocol cannot resist impersonation attack, which is demonstrated in the present paper. To overcome their security weakness, by using chaotic maps, we propose a biometrics-based anonymous three-party AKE protocol with the same advantages. Further, we use the pi calculus-based formal verification tool ProVerif to show that our AKE protocol achieves authentication, security and anonymity, and an acceptable efficiency. (paper)

Availability note (English)

Available from http://dx.doi.org/10.1088/1674-1056/24/11/110505

Additional details

Publishing Information

Journal Title
Chinese Physics. B
Journal Volume
24
Journal Issue
11
Journal Page Range
[8 p.]
ISSN
1674-1056

INIS

Country of Publication
China
Country of Input or Organization
International Atomic Energy Agency (IAEA)
INIS RN
47097125
Subject category
S71: CLASSICAL AND QUANTUM MECHANICS, GENERAL PHYSICS;
Descriptors DEI
BIOMETRIC AUTHENTICATION; CHAOS THEORY; COMMUNICATIONS; EFFICIENCY; MAPS; SECURITY; VERIFICATION
Descriptors DEC
IDENTIFICATION SYSTEMS; MATHEMATICS