KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS VOL. 10, NO. 3, Mar. 2016 1289 Copyright ⓒ2016 KSII Forward Anonymity-Preserving Secure Remote Authentication Scheme Hanwook Lee1, Junghyun Nam2, Moonseong Kim3 and Dongho Won1 1 Department of Computer Engineering, Sungkyunkwan University, Korea [e-mail:
[email protected],
[email protected]] 2 Department of Computer Engineering, Konkuk University, Korea [e-mail:
[email protected]] 3 Information Management Division, Korean Intellectual Property Office, Korea [e-mail:
[email protected]] *Corresponding author: Dongho Won Received May 10, 2015; revised October 23, 2015; accepted January 21, 2016; published March 31, 2016 Abstract Dynamic ID-based authentication solves the ID-theft problem by changing the ID in each session instead of using a fixed ID while performing authenticated key exchanges between communicating parties. User anonymity is expected to be maintained and the exchanged key kept secret even if one of the long-term keys is compromised in the future. However, in the conventional dynamic ID-based authentication scheme, if the server’s long-term key is compromised, user anonymity can be broken or the identities of the users can be traced. In addition, these schemes are vulnerable to replay attacks, in which any adversary who captures the authentication message can retransmit it, and eventually cause the legitimate user to be denied service. This paper proposes a novel dynamic ID-based authentication scheme that preserves forward anonymity as well as forward secrecy and obviates replay attacks. Keywords: Forward anonymity, dynamic ID-based authentication, smart card This research was supported by the Basic Science Research Program through the National Research Foundation of Korea (NRF) funded by the Ministry of Science, ICT, and Future Planning (2014R1A1A2002775).