传统的单服务器环境下基于智能卡认证方案,单个服务器对所有的注册远程用户提供服务。如果用户想要从不同的服务器获得网络服务,必须分别在不同的服务器注册。为解决以上问题,研究者提出了多服务器认证方案,然而,文献中的大部分方案都不能实现强安全特性。受到切比雪夫映射的半群特性和基于扩展混沌映射的密钥协商协议启发,提出一种多服务器环境中的认证方案。新方案不需要使用验证表并且允许用户访问不同的服务器而不需要分别注册;新方案不仅可以抵抗各类攻击,还实现了用户的强匿名性。与以前的相关协议相比,新协议具有高效性和安全性,因而适合在实际环境中应用。
In a traditional single server smart card authentication scheme, one server is responsible for providing services to all the registered remote users. If a user wishes to access network services from different servers, he or she has to register with these servers separately. To handle this issue, multi-server authentication scheme has been proposed. However, most of these schemes available in the literature couldn' t achieve strong security. Inspired by the semi-group property of Chebshev maps and key agreement protocols based on extended chaotic maps, this paper proposed an authentication scheme for multiserver envi- ronment that not only resisted various attacks but also achieved strong anonymity for hiding login user' s real identity from other servers. It eliminated the use of verification table and pennited the registered users to access multiple servers without separate registration. Compared with other previous related schemes, the proposed scheme keeps the efficiency and security, thus it is more suitable for the practical applications.