<p>We show that the Mehta-Parne-Patel authentication and key agreement scheme [Peer Peer Netw. Appl., 2023, 16:1513-1535] cannot be practically implemented. (1) It misunderstands the fuzzy extractor, and falsely requires the user to transfer his biometric <InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12083_2025_1998_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(B_U\)</EquationSource> <EquationSource Format="MATHML"><math> <msub> <mi>B</mi> <mi>U</mi> </msub> </math></EquationSource> </InlineEquation> to the service provider. But the biometric extracted by fuzzy extractor cannot be stored and transferred, and can only be imprinted on the spot. To fix the flaw, the user needs to securely transfer the derived key <InlineEquation ID="IEq2"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12083_2025_1998_Article_IEq2.gif" Format="GIF" Height="12" Rendition="HTML" Resolution="72" Type="Linedraw" Width="21" /> </InlineMediaObject> <EquationSource Format="TEX">\(\sigma _U\)</EquationSource> <EquationSource Format="MATHML"><math> <msub> <mi>σ</mi> <mi>U</mi> </msub> </math></EquationSource> </InlineEquation> by the fuzzy extractor, instead of the biometric <InlineEquation ID="IEq3"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="12083_2025_1998_Article_IEq1.gif" Format="GIF" Height="16" Rendition="HTML" Resolution="72" Type="Linedraw" Width="25" /> </InlineMediaObject> <EquationSource Format="TEX">\(B_U\)</EquationSource> <EquationSource Format="MATHML"><math> <msub> <mi>B</mi> <mi>U</mi> </msub> </math></EquationSource> </InlineEquation> itself. (2) The scheme provides only unidirectional authentication, not mutual authentication. The service provider cannot authenticate the user.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Corrigendum to “SE-LAKAF: Security Enhanced Lightweight Authentication and Key Agreement Framework for Smart Grid Network”

  • Zhengjun Cao

摘要

We show that the Mehta-Parne-Patel authentication and key agreement scheme [Peer Peer Netw. Appl., 2023, 16:1513-1535] cannot be practically implemented. (1) It misunderstands the fuzzy extractor, and falsely requires the user to transfer his biometric \(B_U\) B U to the service provider. But the biometric extracted by fuzzy extractor cannot be stored and transferred, and can only be imprinted on the spot. To fix the flaw, the user needs to securely transfer the derived key \(\sigma _U\) σ U by the fuzzy extractor, instead of the biometric \(B_U\) B U itself. (2) The scheme provides only unidirectional authentication, not mutual authentication. The service provider cannot authenticate the user.