{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,2]],"date-time":"2026-05-02T06:50:59Z","timestamp":1777704659031,"version":"3.51.4"},"reference-count":43,"publisher":"SAGE Publications","issue":"6","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IFS"],"published-print":{"date-parts":[[2020,12,4]]},"abstract":"<jats:p>With the agile development of the Internet era, starting from the message transmission to money transactions, everything is online now. Remote user authentication (RUA) is a mechanism in which a remote server verifies the user\u2019s correctness over the shared or public channel. In this paper, we analyze an RUA scheme proposed by Chen for the multi-server environment and prove that their scheme is not secured. We also find numerous vulnerabilities such as password guessing attack, replay attack, Registration Center (RC) spoofing attack, session key verification attack, and perfect forward secrecy attack for Chen\u2019s scheme. After performing the cryptanalysis of Chen\u2019s scheme, we propose a biometric-based RUA scheme for the same multi-server environment. We prove that the proposed authentication scheme achieves higher security than Chen\u2019s scheme with the use of informal security analysis as well as formal security analysis. The formal security analysis of the proposed scheme is done using a widely adopted random oracle method.<\/jats:p>","DOI":"10.3233\/jifs-189177","type":"journal-article","created":{"date-parts":[[2020,9,8]],"date-time":"2020-09-08T10:03:14Z","timestamp":1599559394000},"page":"8609-8620","source":"Crossref","is-referenced-by-count":10,"title":["An enhanced approach for three factor remote user authentication in multi - server environment"],"prefix":"10.1177","volume":"39","author":[{"given":"Chintan","family":"Patel","sequence":"first","affiliation":[{"name":"School of Technology, Pandit Deendayal Petroleum University, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dhara","family":"Joshi","sequence":"additional","affiliation":[{"name":"School of Engineering, Marwadi University, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nishant","family":"Doshi","sequence":"additional","affiliation":[{"name":"School of Technology, Pandit Deendayal Petroleum University, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"A.","family":"Veeramuthu","sequence":"additional","affiliation":[{"name":"School of Computing, Sathyabama Institute of Science and Technology, Chennai"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rutvij","family":"Jhaveri","sequence":"additional","affiliation":[{"name":"School of Technology, Pandit Deendayal Petroleum University, Gujarat, India"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","reference":[{"key":"10.3233\/JIFS-189177_ref1","first-page":"264","article-title":"Anonymity authentication method in multi-server environments","volume":"9","author":"Chen.","year":"2016","journal-title":"US Patent"},{"key":"10.3233\/JIFS-189177_ref2","doi-asserted-by":"publisher","DOI":"10.1145\/358790.358797"},{"key":"10.3233\/JIFS-189177_ref3","first-page":"136","article-title":"One-time logon method for distributed computing systems","volume":"7","author":"Aoshima","year":"2006","journal-title":"US Patent"},{"issue":"2","key":"10.3233\/JIFS-189177_ref4","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1016\/j.csi.2004.06.001","article-title":"Improved remote authentication scheme with smart card","volume":"27","author":"Yih -Lee","year":"2005","journal-title":"Computer Standards and Interfaces"},{"key":"10.3233\/JIFS-189177_ref5","first-page":"010","article-title":"Sys-tems and methods providing interactions between multiple servers and an end use device","volume":"7","author":"Cheng","year":"2006","journal-title":"US Patent"},{"key":"10.3233\/JIFS-189177_ref6","doi-asserted-by":"publisher","DOI":"10.1007\/1168952224"},{"issue":"4","key":"10.3233\/JIFS-189177_ref7","doi-asserted-by":"publisher","first-page":"723","DOI":"10.1016\/j.csi.2008.09.006","article-title":"An improved smart card based password authentication scheme with provable security","volume":"31","author":"Xu","year":"2009","journal-title":"Computer Standards and Interfaces"},{"key":"10.3233\/JIFS-189177_ref8","first-page":"021","article-title":"Anonymity authentication method for global mobility networks","volume":"9","author":"Chen","year":"2015","journal-title":"US Patent"},{"issue":"1","key":"10.3233\/JIFS-189177_ref9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.jnca.2009.08.001","article-title":"An efficient biometricsbased remote user authentication scheme us-ing smart cards","volume":"33","author":"Li","year":"2010","journal-title":"Journal of Network and Computer Applications"},{"issue":"1","key":"10.3233\/JIFS-189177_ref10","doi-asserted-by":"publisher","first-page":"73","DOI":"10.1016\/j.jnca.2010.09.003","article-title":"Cryptanalysis and improvement of a biometrics-based remote user authentication scheme us-ing smart cards","volume":"34","author":"Li","year":"2011","journal-title":"Journal of Network and Computer Applications"},{"key":"10.3233\/JIFS-189177_ref11","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-45204-85"},{"issue":"3","key":"10.3233\/JIFS-189177_ref12","doi-asserted-by":"publisher","first-page":"816","DOI":"10.1109\/JSYST.2014.2301517","article-title":"Robust Biometrics-Based Authentication Scheme for Multiserver Environment","volume":"9","author":"He","year":"2015","journal-title":"IEEE Systems Journal"},{"issue":"3","key":"10.3233\/JIFS-189177_ref13","doi-asserted-by":"publisher","first-page":"427","DOI":"10.1007\/s12652-015-0338-z","article-title":"An enhanced biometrics-based user authentication scheme for multi-server environments in critical systems","volume":"7","author":"Li","year":"2016","journal-title":"Journal of Ambient Intelligence and Humanized Computing"},{"key":"10.3233\/JIFS-189177_ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCT.2014.7001479"},{"issue":"3","key":"10.3233\/JIFS-189177_ref15","doi-asserted-by":"publisher","first-page":"1095","DOI":"10.1007\/s11277-015-2975-0","article-title":"Design and Analysis of a Provably Secure Multi-server Authentication Scheme","volume":"86","author":"Mishra","year":"2016","journal-title":"Wireless Personal Communications"},{"issue":"11","key":"10.3233\/JIFS-189177_ref16","doi-asserted-by":"publisher","first-page":"13401","DOI":"10.1007\/s11042-016-3704-8","article-title":"A lightweight authentication and key agreement protocol preserving user anonymity","volume":"76","author":"Nikooghadam","year":"2017","journal-title":"Multimedia Tools and Applications"},{"issue":"9","key":"10.3233\/JIFS-189177_ref17","doi-asserted-by":"crossref","first-page":"1953","DOI":"10.1109\/TIFS.2015.2439964","article-title":"A Secure Biometrics-Based Multi-Server Authentication Protocol Using Smart Cards","volume":"10","author":"Odelu","year":"2015","journal-title":"IEEE Transactions on Informa-tion Forensics and Security"},{"issue":"1","key":"10.3233\/JIFS-189177_ref18","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1007\/s11227-010-0512-1","article-title":"Robust biometricsbased multi-server authentication with key agreement scheme for smart cards on elliptic curve cryptosystem","volume":"63","author":"Yoon","year":"2013","journal-title":"The Journal of Supercomputing"},{"issue":"4","key":"10.3233\/JIFS-189177_ref19","doi-asserted-by":"publisher","first-page":"1411","DOI":"10.1016\/j.eswa.2013.08.040","article-title":"An anony-mous multi-server authenticated key agreement scheme based on trust computing using smart cards and biomet-rics","volume":"41","author":"Chuang","year":"2014","journal-title":"Expert Systems with Applications"},{"issue":"4","key":"10.3233\/JIFS-189177_ref20","doi-asserted-by":"publisher","first-page":"1623","DOI":"10.1007\/s11227-016-1688-9","article-title":"An efficient and anonymous multi-server authenticated key agreement based on chaotic map without engaging Registration Centre","volume":"72","author":"Irshad","year":"2016","journal-title":"The Journal of Supercomputing"},{"key":"10.3233\/JIFS-189177_ref21","doi-asserted-by":"crossref","first-page":"2169","DOI":"10.1109\/ACCESS.2016.2596292","article-title":"A Secure Anonymous Authentication Protocol for Mobile Services on Elliptic Curve Cryptog-raphy","volume":"4","author":"Reddy","year":"2016","journal-title":"IEEE Access"},{"key":"10.3233\/JIFS-189177_ref23","first-page":"464","article-title":"Password-based cryptographic method and apparatus","volume":"8","author":"Chen","year":"2013","journal-title":"US Patent"},{"issue":"6","key":"10.3233\/JIFS-189177_ref24","doi-asserted-by":"publisher","first-page":"825","DOI":"10.1007\/s12652-015-0305-8","article-title":"New biometrics-based authentication scheme for multi-server environment in critical systems","volume":"6","author":"Shen","year":"2015","journal-title":"Journal of Ambient Intelligence and Humanized Com-puting"},{"issue":"8","key":"10.3233\/JIFS-189177_ref25","doi-asserted-by":"publisher","first-page":"2035","DOI":"10.1007\/s00500-015-1902-3","article-title":"Flexible neural trees based early stage identification for IP traffic","volume":"21","author":"Chen","year":"2017","journal-title":"Soft Computing"},{"issue":"5","key":"10.3233\/JIFS-189177_ref26","doi-asserted-by":"publisher","first-page":"1417","DOI":"10.1109\/TPDS.2016.2615020","article-title":"Preserving Privacy with Probabilistic Indistinguishability in Weighted Social Networks","volume":"28","author":"Liu","year":"2017","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"issue":"7","key":"10.3233\/JIFS-189177_ref27","doi-asserted-by":"publisher","first-page":"2257","DOI":"10.1007\/s00500-017-2487-9","article-title":"Finger vein secure biometric template generation based on deep learning","volume":"22","author":"Liu","year":"2018","journal-title":"Soft Computing"},{"key":"10.3233\/JIFS-189177_ref28","doi-asserted-by":"publisher","first-page":"165","DOI":"10.1016\/j.ins.2016.08.010","article-title":"Collaborative trajectory privacy preserving scheme in location-based services","volume":"387","author":"Peng","year":"2017","journal-title":"Information Sciences"},{"key":"10.3233\/JIFS-189177_ref29","first-page":"47","article-title":"Lattice-based linearly homomorphic signatures in the standard model","volume":"634","author":"Chen","year":"2016","journal-title":"The-oretical Computer Science"},{"issue":"3","key":"10.3233\/JIFS-189177_ref30","doi-asserted-by":"publisher","first-page":"490","DOI":"10.1007\/s11704-013-3120-4","article-title":"A short non-delegatable strong designated verifier signature","volume":"8","author":"Tian","year":"2014","journal-title":"Frontiers of Computer Science"},{"issue":"8","key":"10.3233\/JIFS-189177_ref31","doi-asserted-by":"publisher","first-page":"2201","DOI":"10.1109\/TPDS.2013.271","article-title":"Securely Outsourcing Attribute-Based Encryp-tion with Checkability","volume":"25","author":"Li","year":"2014","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"key":"10.3233\/JIFS-189177_ref32","doi-asserted-by":"publisher","first-page":"20632","DOI":"10.1109\/ACCESS.2018.2809426","article-title":"An ID-Based Linearly Homomorphic Signature Scheme and Its Application in Blockchain","volume":"6","author":"Lin","year":"2018","journal-title":"IEEE Access"},{"key":"10.3233\/JIFS-189177_ref33","doi-asserted-by":"publisher","first-page":"20085","DOI":"10.1109\/ACCESS.2018.2822945","article-title":"Sensitivity Analysis of an Attack-Pattern Discovery Based Trusted Routing Scheme for Mo-bile Ad-Hoc Networks in Industrial IoT","volume":"6","author":"Jhaveri","year":"2018","journal-title":"IEEE Access"},{"key":"10.3233\/JIFS-189177_ref34","doi-asserted-by":"publisher","first-page":"10179","DOI":"10.1155\/2018\/3680851","article-title":"A Novel Security Scheme Based on Instant Encrypted Transmission for Internet of Things","volume":"2018","author":"Wang","year":"2018","journal-title":"Security and Communication Networks"},{"key":"10.3233\/JIFS-189177_ref35","doi-asserted-by":"publisher","first-page":"10179","DOI":"10.1109\/ACCESS.2018.2799854","article-title":"When Intrusion Detection Meets Blockchain Technology: A Review","volume":"6","author":"Meng","year":"2018","journal-title":"IEEE Access"},{"key":"10.3233\/JIFS-189177_ref36","doi-asserted-by":"publisher","first-page":"1084","DOI":"10.1016\/j.jnca.2018.01.014","article-title":"Dynamic Fully Homomorphic encryption-based Merkle Tree for lightweight streaming authenticated data structures","volume":"107","author":"Xu","year":"2018","journal-title":"Journal of Network and Computer Applications"},{"key":"10.3233\/JIFS-189177_ref37","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1016\/j.jnca.2017.12.017","article-title":"A remotely keyed file encryption scheme under mobile cloud computing","volume":"106","author":"Yang","year":"2018","journal-title":"Journal of Network and Computer Applications"},{"key":"10.3233\/JIFS-189177_ref38","doi-asserted-by":"crossref","unstructured":"Yan H. , et al., Centralized Duplicate Removal Video Storage System with Privacy Preservation in IoT. In: Sensors 18(6) (2018).","DOI":"10.3390\/s18061814"},{"issue":"8","key":"10.3233\/JIFS-189177_ref39","doi-asserted-by":"publisher","first-page":"3243","DOI":"10.1007\/s00500-015-1699-0","article-title":"Cloud-based electronic health record system supporting fuzzy keyword search","volume":"20","author":"Liu","year":"2016","journal-title":"Soft Computing"},{"issue":"3","key":"10.3233\/JIFS-189177_ref40","doi-asserted-by":"publisher","first-page":"2415","DOI":"10.1007\/s10586-017-0796-5","article-title":"Towards Secure and Flexible HER Sharing in Mobile Health Cloud Under Static Assumptions","volume":"20","author":"Cai","year":"2017","journal-title":"Cluster Computing"},{"issue":"4","key":"10.3233\/JIFS-189177_ref42","doi-asserted-by":"crossref","first-page":"2884","DOI":"10.1109\/JIOT.2017.2714179","article-title":"Chaoticmap-based anonymous user authentication scheme with user biometrics and fuzzyextractor for crowdsourcing internet of things","volume":"5","author":"Roy","year":"2018","journal-title":"IEEE Internet of Things Journal"},{"issue":"5","key":"10.3233\/JIFS-189177_ref44","doi-asserted-by":"crossref","first-page":"5379","DOI":"10.3233\/JIFS-169820","article-title":"A PKC-based user authentication scheme without smart card","volume":"35","author":"Kumar","year":"2018","journal-title":"Journal of Intelligent and Fuzzy Systems"},{"issue":"3","key":"10.3233\/JIFS-189177_ref45","doi-asserted-by":"crossref","first-page":"1403","DOI":"10.3233\/JIFS-169435","article-title":"An efficient biometric based remote user authentication scheme for secure internet of things environment","volume":"34","author":"Roy","year":"2018","journal-title":"Journal of Intelligent Fuzzy Systems"},{"issue":"1","key":"10.3233\/JIFS-189177_ref46","doi-asserted-by":"crossref","first-page":"28","DOI":"10.1109\/30.826377","article-title":"A new remote user authentication scheme using smart cards","volume":"46","author":"Hwang","year":"2000","journal-title":"IEEE Transactions on consumer Electronics"}],"container-title":["Journal of Intelligent &amp; Fuzzy Systems"],"original-title":[],"link":[{"URL":"https:\/\/content.iospress.com\/download?id=10.3233\/JIFS-189177","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T09:41:43Z","timestamp":1777455703000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/full\/10.3233\/JIFS-189177"}},"subtitle":[],"editor":[{"given":"Vijayakumar","family":"Varadarajan","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]},{"given":"Piet","family":"Kommers","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]},{"given":"Vincenzo","family":"Piuri","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]},{"given":"V.","family":"Subramaniyaswamy","sequence":"additional","affiliation":[],"role":[{"role":"editor","vocabulary":"crossref"}]}],"short-title":[],"issued":{"date-parts":[[2020,12,4]]},"references-count":43,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.3233\/jifs-189177","relation":{},"ISSN":["1064-1246","1875-8967"],"issn-type":[{"value":"1064-1246","type":"print"},{"value":"1875-8967","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,12,4]]}}}