Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks

In global mobility networks, a mobile user can access roaming services using a mobile device at anytime and anywhere. However, mobile users can be vulnerable to various attacks by adversaries, because the roaming services are provided through public network. Therefore, an anonymous mobile user authe...

Full description

Bibliographic Details
Main Authors: Kisung Park, Youngho Park, Yohan Park, Alavalapati Goutham Reddy, Ashok Kumar Das
Format: Article
Language:English
Published: IEEE 2017-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8107484/
_version_ 1818924249259180032
author Kisung Park
Youngho Park
Yohan Park
Alavalapati Goutham Reddy
Ashok Kumar Das
author_facet Kisung Park
Youngho Park
Yohan Park
Alavalapati Goutham Reddy
Ashok Kumar Das
author_sort Kisung Park
collection DOAJ
description In global mobility networks, a mobile user can access roaming services using a mobile device at anytime and anywhere. However, mobile users can be vulnerable to various attacks by adversaries, because the roaming services are provided through public network. Therefore, an anonymous mobile user authentication for roaming services is an essential security issue in global mobility networks. Recently, Lee et al. pointed out the security weaknesses of a previous scheme and proposed an advanced secure anonymous authentication scheme for roaming services in global mobility networks. However, we found that the scheme proposed by Lee et al. is vulnerable to password guessing and user impersonation attacks, and that it cannot provide perfect forward secrecy and secure password altered phase. In this paper, to overcome the security weaknesses of the scheme proposed by Lee et al., we propose an improved secure anonymous authentication scheme using shared secret keys between home agent and foreign agent. In addition, we analyze the security of our proposed scheme against various attacks and prove that it provides secure mutual authentication using Burrows-Abadi-Needham logic. In addition, the formal security analysis using the broadly-accepted real-or-random (ROR) random oracle model and the formal security verification using the widely accepted automated validation of the Internet security protocols and applications tool show that the proposed scheme provides the session key security and protection against replay as well as man-in-the-middle attacks, respectively. Finally, we compare the performance of the proposed scheme with the related schemes, and the results show that the proposed scheme provides better security and comparable efficiency as compared with those for the existing schemes.
first_indexed 2024-12-20T02:22:19Z
format Article
id doaj.art-66a34f073c6c4dc99681fa43a12c4bb9
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-20T02:22:19Z
publishDate 2017-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-66a34f073c6c4dc99681fa43a12c4bb92022-12-21T19:56:48ZengIEEEIEEE Access2169-35362017-01-015251102512510.1109/ACCESS.2017.27735358107484Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility NetworksKisung Park0Youngho Park1https://orcid.org/0000-0002-0406-6547Yohan Park2Alavalapati Goutham Reddy3https://orcid.org/0000-0002-4335-8331Ashok Kumar Das4https://orcid.org/0000-0002-5196-9589School of Electronics Engineering, Kyungpook National University, Daegu, South KoreaSchool of Electronics Engineering, Kyungpook National University, Daegu, South KoreaDivision of IT Convergence, Korea Nazarene University, Cheonan, South KoreaDepartment of Computer and Information Security, Sejong University, Seoul, South KoreaCenter for Security, Theory and Algorithmic Research, International Institute of Information Technology, Hyderabad, IndiaIn global mobility networks, a mobile user can access roaming services using a mobile device at anytime and anywhere. However, mobile users can be vulnerable to various attacks by adversaries, because the roaming services are provided through public network. Therefore, an anonymous mobile user authentication for roaming services is an essential security issue in global mobility networks. Recently, Lee et al. pointed out the security weaknesses of a previous scheme and proposed an advanced secure anonymous authentication scheme for roaming services in global mobility networks. However, we found that the scheme proposed by Lee et al. is vulnerable to password guessing and user impersonation attacks, and that it cannot provide perfect forward secrecy and secure password altered phase. In this paper, to overcome the security weaknesses of the scheme proposed by Lee et al., we propose an improved secure anonymous authentication scheme using shared secret keys between home agent and foreign agent. In addition, we analyze the security of our proposed scheme against various attacks and prove that it provides secure mutual authentication using Burrows-Abadi-Needham logic. In addition, the formal security analysis using the broadly-accepted real-or-random (ROR) random oracle model and the formal security verification using the widely accepted automated validation of the Internet security protocols and applications tool show that the proposed scheme provides the session key security and protection against replay as well as man-in-the-middle attacks, respectively. Finally, we compare the performance of the proposed scheme with the related schemes, and the results show that the proposed scheme provides better security and comparable efficiency as compared with those for the existing schemes.https://ieeexplore.ieee.org/document/8107484/Global mobility networksauthenticationroaming servicesformal securitykey agreementROR model
spellingShingle Kisung Park
Youngho Park
Yohan Park
Alavalapati Goutham Reddy
Ashok Kumar Das
Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
IEEE Access
Global mobility networks
authentication
roaming services
formal security
key agreement
ROR model
title Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
title_full Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
title_fullStr Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
title_full_unstemmed Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
title_short Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
title_sort provably secure and efficient authentication protocol for roaming service in global mobility networks
topic Global mobility networks
authentication
roaming services
formal security
key agreement
ROR model
url https://ieeexplore.ieee.org/document/8107484/
work_keys_str_mv AT kisungpark provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks
AT younghopark provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks
AT yohanpark provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks
AT alavalapatigouthamreddy provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks
AT ashokkumardas provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks