Journal of Zhejiang University SCIENCE C 2013 Vol.14 No.12 P.909-917


Analysis and design of a smart card based authentication protocol

Author(s):  Kuo-Hui Yeh, Kuo-Yu Tsai, Jia-Li Hou

Affiliation(s):  Department of Information Management, National Dong Hwa University, Taiwan 974, Hualien; more

Corresponding email(s):   khyeh@mail.ndhu.edu.tw, kytsai@cc.hwh.edu.tw

Key Words:  Authentication, Privacy, Security, Smart card

Numerous smart card based authentication protocols have been proposed to provide strong system security and robust individual privacy for communication between parties these days. Nevertheless, most of them do not provide formal analysis proof, and the security robustness is doubtful. Chang and Cheng (2011) proposed an efficient remote authentication protocol with smart cards and claimed that their proposed protocol could support secure communication in a multi-server environment. Unfortunately, there are opportunities for security enhancement in current schemes. In this paper, we identify the major weakness, i.e., session key disclosure, of a recently published protocol. We consequently propose a novel authentication scheme for a multi-server environment and give formal analysis proofs for security guarantees.

