<p>Several multiserver authentication protocols have recently been proposed that require one-time user registration at a dedicated registration server to access multiple servers securely. However, due to centralized architecture, most of these protocols are susceptible to various attacks and do not address the threat of a single-point failure. This paper presents a novel authentication protocol based on blockchain technology, enabling secure access to distributed services in a multiserver environment. The proposed protocol ensures robust security and flexibility by integrating a multi-factor authentication mechanism and supporting additional features, such as realizing user impersonation attacks, enhancing server scalability, access control, service revocation, and re-registration. Furthermore, the protocol provides enhanced security by enabling the revocation of compromised credentials, resistance to single-point failure, and secure addition of new servers. The automated ProVerif tool and thorough security analysis demonstrate that our protocol defends against a variety of attacks, including replay, insider, impersonation, password guessing, server spoofing, and stolen smartcard attacks. The protocol is evaluated based on its computational cost, communication overhead, and security strength. Our comparative study reveals that the protocol significantly reduces communication overhead to 1728 bits compared to existing protocols, while maintaining an optimal balance between security and efficiency. Although the computational cost is higher at 112.06 ms, this is justified by the enhanced security features and flexibility offered. Overall, our protocol addresses critical security concerns and boosts user trust in distributed services by guaranteeing secure and effective user authentication in a decentralized environment.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Hybrid Blockchain-Based Authentication Protocol for a Multiserver Environment

  • Ashish Kumar,
  • Hari Om

摘要

Several multiserver authentication protocols have recently been proposed that require one-time user registration at a dedicated registration server to access multiple servers securely. However, due to centralized architecture, most of these protocols are susceptible to various attacks and do not address the threat of a single-point failure. This paper presents a novel authentication protocol based on blockchain technology, enabling secure access to distributed services in a multiserver environment. The proposed protocol ensures robust security and flexibility by integrating a multi-factor authentication mechanism and supporting additional features, such as realizing user impersonation attacks, enhancing server scalability, access control, service revocation, and re-registration. Furthermore, the protocol provides enhanced security by enabling the revocation of compromised credentials, resistance to single-point failure, and secure addition of new servers. The automated ProVerif tool and thorough security analysis demonstrate that our protocol defends against a variety of attacks, including replay, insider, impersonation, password guessing, server spoofing, and stolen smartcard attacks. The protocol is evaluated based on its computational cost, communication overhead, and security strength. Our comparative study reveals that the protocol significantly reduces communication overhead to 1728 bits compared to existing protocols, while maintaining an optimal balance between security and efficiency. Although the computational cost is higher at 112.06 ms, this is justified by the enhanced security features and flexibility offered. Overall, our protocol addresses critical security concerns and boosts user trust in distributed services by guaranteeing secure and effective user authentication in a decentralized environment.