A novel and provably secure authentication and key agreement scheme with user anonymity for global mobility networks

作者:Wu, Fan*; Xu, Lili; Kumari, Saru; Li, Xiong; Das, Ashok Kumar; Khan, Muhammad Khurram; Karuppiah, Marimuthu; Baliyan, Renuka
来源:Security and Communication Networks, 2016, 9(16): 3527-3542.
DOI:10.1002/sec.1558

摘要

Ubiquitous networks support the roaming service for mobile communication devices. The mobile user can use the services in the foreign network with the help of the home network. Mutual authentication plays an important role in the roaming services, and researchers put their interests on the authentication schemes. Recently, in 2016, Gope and Hwang found that mutual authentication scheme of He et al. for global mobility networks had security disadvantages such as vulnerability to forgery attacks, unfair key agreement, and destitution of user anonymity. Then, they presented an improved scheme. However, we find that the scheme cannot resist the off-line guessing attack and the de-synchronization attack. Also, it lacks strong forward security. Moreover, the session key is known to HA in that scheme. To get over the weaknesses, we propose a new two-factor authentication scheme for global mobility networks. We use formal proof with random oracle model, formal verification with the tool Proverif, and informal analysis to demonstrate the security of the proposed scheme. Compared with some very recent schemes, our scheme is more applicable.