IEEE Access (Jan 2016)

A Secure Anonymous Authentication Protocol for Mobile Services on Elliptic Curve Cryptography

  • Alavalapati Goutham Reddy,
  • Ashok Kumar Das,
  • Eun-Jun Yoon,
  • Kee-Young Yoo

DOI
https://doi.org/10.1109/ACCESS.2016.2596292
Journal volume & issue
Vol. 4
pp. 4394 – 4407

Abstract

Read online

Mobile user authentication is an essential topic to consider in the current communications technology due to greater deployment of handheld devices and advanced technologies. Memon et al. recently proposed an efficient and secure two-factor authentication protocol for location-based services using asymmetric key cryptography. Unlike their claims, the vigilant analysis of this paper substantiates that Memon et al.'s protocol has quite a few limitations such as vulnerability to key compromised impersonation attack, insecure password changing phase, imperfect mutual authentication, and vulnerability to insider attack. Furthermore, this paper proposes an enhanced secure authentication protocol for roaming services on elliptic curve cryptography. The proposed protocol is also a two-factor authentication protocol and is suitable for practical applications due to the composition of light-weight operations. The proposed protocol's formal security is verified using Automated Validation of Internet Security Protocols and Applications tool to certify that the proposed protocol is free from security threats. The informal and formal security analyses along with the performance analysis sections determine that the proposed protocol performs better than Memon et al.'s protocol and other related protocols in terms of security and efficiency.

Keywords