针对Xu等近期提出的一个基于智能卡的动态身份用户远程认证方案(简称XJWM)进行分析,指出其不能抵抗冒充攻击和密钥泄露攻击,且不能实现前向安全和后向安全。利用Diffie-Hellman密钥协商算法及生物认证技术,提出一个新的多服务器环境下多因子远程匿名认证密钥协商协议。新方案不仅有效弥补了XJWM方案存在的安全缺陷,而且增加了智能卡对持卡者的口令与生物信息的认证,避免了智能卡丢失引起的冒充攻击。最后,用改进的BAN逻辑证明了新方案密钥协商的正确性、会话密钥机密性与新鲜性以及双向认证性。安全性和性能分析说明,新方案在少量增加计算量的情况下具有良好的安全性。
In order to efficiently eliminate the security shortcomings of the dynamic ID based remote user authentication scheme using smart cards( short for XJWM scheme) proposed by Xu et al.,a new multi-server and multi-factor anonymous remote authenticated key agreement protocol was presented,based on Diffie-Hellman key agreement algorithm and biometrical authentication technology. The new protocol can not only overcome the security flaws of XJWM scheme,but also add smart card's password and bio information authentication for the cardholder to avoid the smart card stolen attack. The security of the new protocol was proved by the improved BAN logic and the result showed that the new scheme can ensure the correctness of key agreement,key confidentiality,key freshness and mutual authentication. The security and performance analysis demonstrated that the proposed protocol provides better security without increasing too much computation overhead.