Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures

To support more complex and robust online services, enterprise-class applications prefer to interconnect multiple servers as the pedestal to enhance the system’s interoperability. However, the multiserver architecture always struggles to reconcile the trade-off between convenience and security, leav...

Full description

Bibliographic Details
Main Authors: Qi Xie, Yuanyuan Zhao
Format: Article
Language:English
Published: MDPI AG 2023-12-01
Series:Mathematics
Subjects:
Online Access:https://www.mdpi.com/2227-7390/12/1/79
_version_ 1827384642446032896
author Qi Xie
Yuanyuan Zhao
author_facet Qi Xie
Yuanyuan Zhao
author_sort Qi Xie
collection DOAJ
description To support more complex and robust online services, enterprise-class applications prefer to interconnect multiple servers as the pedestal to enhance the system’s interoperability. However, the multiserver architecture always struggles to reconcile the trade-off between convenience and security, leaving users exposed to a variety of network attack threats. Existing security authentication schemes based on the Chebyshev Chaotic Map for multiserver architectures cannot provide three-factor (including password, biometric feature, and smart card) security. Therefore, we propose a novel Physical-Unclonable-Function-based Lightweight Three-Factor Authentication (PUF-LTA) scheme, which can achieve three-factor security. The PUF-LTA scheme mainly includes two components: (1) PUF-assisted registration and (2) lightweight mutual authentication with one-time interaction. During the PUF-assisted registration process, to defend against side-channel attacks on smart cards, the login credentials of users are XORed with the unique identifier generated by the PUF so that the adversary cannot obtain these secret login credentials. During the lightweight mutual authentication process, we combine the Chebyshev polynomial map and symmetric encryption/decryption to negotiate the session key between users and servers, which only needs one interaction. The security performance of PUF-LTA is theoretically proved by leveraging the random oracle model. In contrast with relevant multiserver authentication schemes, PUF-LTA is more efficient and suitable for resource-constrained multiserver environments because it can ensure secure three-factor authentication and support flexible biometrics and password updates with less computation cost.
first_indexed 2024-03-08T15:01:59Z
format Article
id doaj.art-041395b947b14f00b249b55da000dbff
institution Directory Open Access Journal
issn 2227-7390
language English
last_indexed 2024-03-08T15:01:59Z
publishDate 2023-12-01
publisher MDPI AG
record_format Article
series Mathematics
spelling doaj.art-041395b947b14f00b249b55da000dbff2024-01-10T15:03:32ZengMDPI AGMathematics2227-73902023-12-011217910.3390/math12010079Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver ArchitecturesQi Xie0Yuanyuan Zhao1Key Laboratory of Cryptography of Zhejiang Province, Hangzhou Normal University, Hangzhou 311121, ChinaKey Laboratory of Cryptography of Zhejiang Province, Hangzhou Normal University, Hangzhou 311121, ChinaTo support more complex and robust online services, enterprise-class applications prefer to interconnect multiple servers as the pedestal to enhance the system’s interoperability. However, the multiserver architecture always struggles to reconcile the trade-off between convenience and security, leaving users exposed to a variety of network attack threats. Existing security authentication schemes based on the Chebyshev Chaotic Map for multiserver architectures cannot provide three-factor (including password, biometric feature, and smart card) security. Therefore, we propose a novel Physical-Unclonable-Function-based Lightweight Three-Factor Authentication (PUF-LTA) scheme, which can achieve three-factor security. The PUF-LTA scheme mainly includes two components: (1) PUF-assisted registration and (2) lightweight mutual authentication with one-time interaction. During the PUF-assisted registration process, to defend against side-channel attacks on smart cards, the login credentials of users are XORed with the unique identifier generated by the PUF so that the adversary cannot obtain these secret login credentials. During the lightweight mutual authentication process, we combine the Chebyshev polynomial map and symmetric encryption/decryption to negotiate the session key between users and servers, which only needs one interaction. The security performance of PUF-LTA is theoretically proved by leveraging the random oracle model. In contrast with relevant multiserver authentication schemes, PUF-LTA is more efficient and suitable for resource-constrained multiserver environments because it can ensure secure three-factor authentication and support flexible biometrics and password updates with less computation cost.https://www.mdpi.com/2227-7390/12/1/79authentication protocolmultiserver architecturethree-factor securityphysical unclonable function
spellingShingle Qi Xie
Yuanyuan Zhao
Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
Mathematics
authentication protocol
multiserver architecture
three-factor security
physical unclonable function
title Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
title_full Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
title_fullStr Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
title_full_unstemmed Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
title_short Physical-Unclonable-Function-Based Lightweight Three-Factor Authentication for Multiserver Architectures
title_sort physical unclonable function based lightweight three factor authentication for multiserver architectures
topic authentication protocol
multiserver architecture
three-factor security
physical unclonable function
url https://www.mdpi.com/2227-7390/12/1/79
work_keys_str_mv AT qixie physicalunclonablefunctionbasedlightweightthreefactorauthenticationformultiserverarchitectures
AT yuanyuanzhao physicalunclonablefunctionbasedlightweightthreefactorauthenticationformultiserverarchitectures