
In the password based authenticated protocol, protecting off-line guessing attack is quite intricate owing to its low entropy property. In order to withstand it, three-factor (e.g., biometric, smartcard and password) authentication now becoming an important research paradigm in information security. Cheng et al.'s suggested an authenticated and key negotiation protocol using biometric and Quadratic Residue Problem (QRP), and they claim that it is robust against known attacks. However, our careful observation demonstrates that the protocol endures from a variety of security loopholes. We further observed that the protocol does not hold mutual authentication property. To conquer the security vulnerability, we aim to design an extended authentication protocol. The results obtained from AVISPA simulation assuarence against the security attacks. Further cryptanalysis on our scheme shows that it resists all known attacks. We found satisfactory results by comparing with Cheng et al.'s protocol.
| selected citations These citations are derived from selected sources. This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | 7 | |
| popularity This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network. | Top 10% | |
| influence This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically). | Average | |
| impulse This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network. | Average |
