Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks
In global mobility networks, a mobile user can access roaming services using a mobile device at anytime and anywhere. However, mobile users can be vulnerable to various attacks by adversaries, because the roaming services are provided through public network. Therefore, an anonymous mobile user authe...
Main Authors: | , , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2017-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/8107484/ |
_version_ | 1818924249259180032 |
---|---|
author | Kisung Park Youngho Park Yohan Park Alavalapati Goutham Reddy Ashok Kumar Das |
author_facet | Kisung Park Youngho Park Yohan Park Alavalapati Goutham Reddy Ashok Kumar Das |
author_sort | Kisung Park |
collection | DOAJ |
description | In global mobility networks, a mobile user can access roaming services using a mobile device at anytime and anywhere. However, mobile users can be vulnerable to various attacks by adversaries, because the roaming services are provided through public network. Therefore, an anonymous mobile user authentication for roaming services is an essential security issue in global mobility networks. Recently, Lee et al. pointed out the security weaknesses of a previous scheme and proposed an advanced secure anonymous authentication scheme for roaming services in global mobility networks. However, we found that the scheme proposed by Lee et al. is vulnerable to password guessing and user impersonation attacks, and that it cannot provide perfect forward secrecy and secure password altered phase. In this paper, to overcome the security weaknesses of the scheme proposed by Lee et al., we propose an improved secure anonymous authentication scheme using shared secret keys between home agent and foreign agent. In addition, we analyze the security of our proposed scheme against various attacks and prove that it provides secure mutual authentication using Burrows-Abadi-Needham logic. In addition, the formal security analysis using the broadly-accepted real-or-random (ROR) random oracle model and the formal security verification using the widely accepted automated validation of the Internet security protocols and applications tool show that the proposed scheme provides the session key security and protection against replay as well as man-in-the-middle attacks, respectively. Finally, we compare the performance of the proposed scheme with the related schemes, and the results show that the proposed scheme provides better security and comparable efficiency as compared with those for the existing schemes. |
first_indexed | 2024-12-20T02:22:19Z |
format | Article |
id | doaj.art-66a34f073c6c4dc99681fa43a12c4bb9 |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-12-20T02:22:19Z |
publishDate | 2017-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-66a34f073c6c4dc99681fa43a12c4bb92022-12-21T19:56:48ZengIEEEIEEE Access2169-35362017-01-015251102512510.1109/ACCESS.2017.27735358107484Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility NetworksKisung Park0Youngho Park1https://orcid.org/0000-0002-0406-6547Yohan Park2Alavalapati Goutham Reddy3https://orcid.org/0000-0002-4335-8331Ashok Kumar Das4https://orcid.org/0000-0002-5196-9589School of Electronics Engineering, Kyungpook National University, Daegu, South KoreaSchool of Electronics Engineering, Kyungpook National University, Daegu, South KoreaDivision of IT Convergence, Korea Nazarene University, Cheonan, South KoreaDepartment of Computer and Information Security, Sejong University, Seoul, South KoreaCenter for Security, Theory and Algorithmic Research, International Institute of Information Technology, Hyderabad, IndiaIn global mobility networks, a mobile user can access roaming services using a mobile device at anytime and anywhere. However, mobile users can be vulnerable to various attacks by adversaries, because the roaming services are provided through public network. Therefore, an anonymous mobile user authentication for roaming services is an essential security issue in global mobility networks. Recently, Lee et al. pointed out the security weaknesses of a previous scheme and proposed an advanced secure anonymous authentication scheme for roaming services in global mobility networks. However, we found that the scheme proposed by Lee et al. is vulnerable to password guessing and user impersonation attacks, and that it cannot provide perfect forward secrecy and secure password altered phase. In this paper, to overcome the security weaknesses of the scheme proposed by Lee et al., we propose an improved secure anonymous authentication scheme using shared secret keys between home agent and foreign agent. In addition, we analyze the security of our proposed scheme against various attacks and prove that it provides secure mutual authentication using Burrows-Abadi-Needham logic. In addition, the formal security analysis using the broadly-accepted real-or-random (ROR) random oracle model and the formal security verification using the widely accepted automated validation of the Internet security protocols and applications tool show that the proposed scheme provides the session key security and protection against replay as well as man-in-the-middle attacks, respectively. Finally, we compare the performance of the proposed scheme with the related schemes, and the results show that the proposed scheme provides better security and comparable efficiency as compared with those for the existing schemes.https://ieeexplore.ieee.org/document/8107484/Global mobility networksauthenticationroaming servicesformal securitykey agreementROR model |
spellingShingle | Kisung Park Youngho Park Yohan Park Alavalapati Goutham Reddy Ashok Kumar Das Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks IEEE Access Global mobility networks authentication roaming services formal security key agreement ROR model |
title | Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks |
title_full | Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks |
title_fullStr | Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks |
title_full_unstemmed | Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks |
title_short | Provably Secure and Efficient Authentication Protocol for Roaming Service in Global Mobility Networks |
title_sort | provably secure and efficient authentication protocol for roaming service in global mobility networks |
topic | Global mobility networks authentication roaming services formal security key agreement ROR model |
url | https://ieeexplore.ieee.org/document/8107484/ |
work_keys_str_mv | AT kisungpark provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks AT younghopark provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks AT yohanpark provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks AT alavalapatigouthamreddy provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks AT ashokkumardas provablysecureandefficientauthenticationprotocolforroamingserviceinglobalmobilitynetworks |