{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T17:40:01Z","timestamp":1771609201520,"version":"3.50.1"},"reference-count":37,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2020,2,15]],"date-time":"2020-02-15T00:00:00Z","timestamp":1581724800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100004054","name":"King Abdulaziz University","doi-asserted-by":"publisher","award":["RG-7-611-40"],"award-info":[{"award-number":["RG-7-611-40"]}],"id":[{"id":"10.13039\/501100004054","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Symmetry"],"abstract":"<jats:p>The roaming service enables a remote user to get desired services, while roaming in a foreign network through the help of his home network. The authentication is a pre-requisite for secure communication between a foreign network and the roaming user, which enables the user to share a secret key with foreign network for subsequent private communication of data. Sharing a secret key is a tedious task due to underneath open and insecure channel. Recently, a number of such schemes have been proposed to provide authentication between roaming user and the foreign networks. Very recently, Lu et al. claimed that the seminal Gopi-Hwang scheme fails to resist a session-specific temporary information leakage attack. Lu et al. then proposed an improved scheme based on Elliptic Curve Cryptography (ECC) for roaming user. However, contrary to their claim, the paper provides an in-depth cryptanalysis of Lu et al.\u2019s scheme to show the weaknesses of their scheme against Stolen Verifier and Traceability attacks. Moreover, the analysis also affirms that the scheme of Lu et al. entails incorrect login and authentication phases and is prone to scalability issues. An improved scheme is then proposed. The scheme not only overcomes the weaknesses Lu et al.\u2019s scheme but also incurs low computation time. The security of the scheme is analyzed through formal and informal methods; moreover, the automated tool ProVerif also verifies the security features claimed by the proposed scheme.<\/jats:p>","DOI":"10.3390\/sym12020287","type":"journal-article","created":{"date-parts":[[2020,2,26]],"date-time":"2020-02-26T04:18:29Z","timestamp":1582690709000},"page":"287","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":24,"title":["A Privacy Preserving Authentication Scheme for Roaming in IoT-Based Wireless Mobile Networks"],"prefix":"10.3390","volume":"12","author":[{"given":"Bander A.","family":"Alzahrani","sequence":"first","affiliation":[{"name":"Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shehzad Ashraf","family":"Chaudhry","sequence":"additional","affiliation":[{"name":"Department of Computer Engineering, Faculty of Engineering and Architecture Istanbul Gelisim University Istanbul, Avc\u0131lar, 34310 Istanbul, Turkey"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ahmed","family":"Barnawi","sequence":"additional","affiliation":[{"name":"Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6784-3278","authenticated-orcid":false,"given":"Abdullah","family":"Al-Barakati","sequence":"additional","affiliation":[{"name":"Faculty of Computing and Information Technology, King Abdulaziz University, Jeddah 21589, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8579-5444","authenticated-orcid":false,"given":"Mohammed H.","family":"Alsharif","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, College of Electronics and Information Engineering, Sejong University, 209 Neungdong-ro, Gwangjin-gu, Seoul 05006, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2020,2,15]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"811","DOI":"10.1109\/TCE.2013.6689693","article-title":"Anonymous two-factor authentication for consumer roaming service in global mobility networks","volume":"59","author":"He","year":"2013","journal-title":"IEEE Trans. Consum. Electron."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"4755","DOI":"10.1109\/JIOT.2018.2874473","article-title":"Privacy Preserving Data Aggregation Scheme for Mobile Edge Computing Assisted IoT Applications","volume":"6","author":"Li","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_3","unstructured":"Wei, F., Vijayakumar, P., Jiang, Q., and Zhang, R. (2018). A Mobile Intelligent Terminal Based Anonymous Authenticated Key Exchange Protocol for Roaming Service in Global Mobility Networks. IEEE Trans. Sustain. Comput., 1-1."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"2569","DOI":"10.1109\/TWC.2006.05063","article-title":"Mutual Authentication and Key Exchange Protocols for Roaming Services in Wireless Mobile Networks","volume":"5","author":"Jiang","year":"2006","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"1469","DOI":"10.1109\/TMC.2013.134","article-title":"Efficient Privacy-Preserving Authentication in Wireless Mobile Networks","volume":"13","author":"Jo","year":"2014","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"449","DOI":"10.1109\/TIFS.2017.2756567","article-title":"GRAAD: Group Anonymous and Accountable D2D Communication in Mobile Networks","volume":"13","author":"Hsu","year":"2018","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Alezabi, K.A., Hashim, F., Hashim, S.J., and Ali, B.M. (2014, January 14\u201316). An efficient authentication and key agreement protocol for 4G (LTE) networks. Proceedings of the 2014 IEEE REGION 10 SYMPOSIUM, Kuala Lumpur, Malaysia.","DOI":"10.1109\/TENCONSpring.2014.6863085"},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1016\/j.mcm.2011.04.036","article-title":"Enhanced secure anonymous authentication scheme for roaming service in global mobility networks","volume":"55","author":"Mun","year":"2012","journal-title":"Math. Comput. Model."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"272","DOI":"10.1049\/iet-ifs.2015.0390","article-title":"Lightweight authentication with key-agreement protocol for mobile network environment using smart cards","volume":"10","author":"Yoon","year":"2016","journal-title":"IET Inf. Secur."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Sabir, E., Garc\u00eda Armada, A., Ghogho, M., and Debbah, M. (2017). An Efficient Authentication Protocol for 5G Heterogeneous Networks. Ubiquitous Networking, Springer International Publishing.","DOI":"10.1007\/978-3-319-68179-5"},{"key":"ref_11","first-page":"83","article-title":"Universally Composable RFID Mutual Authentication","volume":"14","author":"Su","year":"2017","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"607","DOI":"10.1016\/j.future.2017.04.012","article-title":"A robust biometrics based three-factor authentication scheme for Global Mobility Networks in smart city","volume":"83","author":"Li","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"48","DOI":"10.1109\/TWC.2011.110811.111240","article-title":"Secure and Efficient Handover Authentication Based on Bilinear Pairing Functions","volume":"11","author":"He","year":"2012","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1477","DOI":"10.1007\/s11277-012-0535-4","article-title":"An enhanced authentication scheme with privacy preservation for roaming service in global mobility networks","volume":"68","author":"Jiang","year":"2013","journal-title":"Wirel. Pers. Commun."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"231","DOI":"10.1109\/TCE.2004.1277867","article-title":"A new authentication scheme with anonymity for wireless environments","volume":"50","author":"Zhu","year":"2004","journal-title":"IEEE Trans. Consum. Electron."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1037","DOI":"10.1007\/s11277-013-1246-1","article-title":"Secure Handover Authentication Protocol Based on Bilinear Pairings","volume":"73","author":"Tsai","year":"2013","journal-title":"Wirel. Pers. Commun."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"611","DOI":"10.1016\/j.comcom.2008.11.032","article-title":"Enhanced authentication scheme with anonymity for roaming service in global mobility networks","volume":"32","author":"Chang","year":"2009","journal-title":"Comput. Commun."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"1223","DOI":"10.1007\/s10586-017-0783-x","article-title":"A privacy preserving authentication scheme for roaming in ubiquitous networks","volume":"20","author":"Chaudhry","year":"2017","journal-title":"Clust. Comput."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"12047","DOI":"10.1109\/ACCESS.2019.2891105","article-title":"A secure authentication protocol for internet of vehicles","volume":"7","author":"Chen","year":"2019","journal-title":"IEEE Access"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"3133","DOI":"10.1007\/s12652-018-1029-3","article-title":"Attacks and solutions on a three-party password-based authenticated key exchange protocol for wireless communications","volume":"10","author":"Chen","year":"2019","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"41","DOI":"10.1016\/j.comnet.2014.07.010","article-title":"On the anonymity of two-factor authentication schemes for wireless sensor networks: Attacks, principle and solutions","volume":"73","author":"Wang","year":"2014","journal-title":"Comput. Netw."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"471","DOI":"10.1109\/LCOMM.2009.090488","article-title":"Weaknesses in an Anonymous Authentication Scheme for Roaming Service in Global Mobility Networks","volume":"13","author":"Youn","year":"2009","journal-title":"IEEE Commun. Lett."},{"key":"ref_23","first-page":"45","article-title":"Improved secure anonymous authentication scheme for roaming service in global mobility networks","volume":"6","author":"Kim","year":"2012","journal-title":"Int. J. Secur. Its Appl."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Lee, H., Lee, D., Moon, J., Jung, J., Kang, D., Kim, H., and Won, D. (2018). An improved anonymous authentication scheme for roaming in ubiquitous networks. PLoS ONE, 13.","DOI":"10.1371\/journal.pone.0193366"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1370","DOI":"10.1109\/JSYST.2015.2416396","article-title":"Lightweight and energy-efficient mutual authentication and key agreement scheme with user anonymity for secure communication in global mobility networks","volume":"10","author":"Gope","year":"2015","journal-title":"IEEE Syst. J."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Lu, Y., Xu, G., Li, L., and Yang, Y. (2019). Robust Privacy-Preserving Mutual Authenticated Key Agreement Scheme in Roaming Service for Global Mobility Networks. IEEE Syst. J., 1\u201312.","DOI":"10.1109\/JSYST.2018.2883349"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"203","DOI":"10.1007\/978-3-540-85174-5_12","article-title":"On the Power of Power Analysis in the Real World: A Complete Break of the KeeLoq Code Hopping Scheme","volume":"Volume 5157","author":"Wagner","year":"2008","journal-title":"Advances in Cryptology, CRYPTO 2008"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","article-title":"On the security of public key protocols","volume":"29","author":"Dolev","year":"1983","journal-title":"Inf. Theory, IEEE Trans."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"2590","DOI":"10.1109\/JSYST.2016.2544805","article-title":"Anonymous Authentication for Wireless Body Area Networks With Provable Security","volume":"11","author":"He","year":"2016","journal-title":"IEEE Syst. J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"052108","DOI":"10.1007\/s11432-015-5469-5","article-title":"One-to-many authentication for access control in mobile pay-TV systems","volume":"59","author":"He","year":"2016","journal-title":"Sci. China Inf. Sci."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"56","DOI":"10.1016\/j.future.2016.04.016","article-title":"A user friendly mutual authentication and key agreement scheme for wireless sensor networks using chaotic maps","volume":"63","author":"Kumari","year":"2016","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Hoffstein, J. (2008). An introduction to cryptography. An Introduction to Mathematical Cryptography, Springer.","DOI":"10.1007\/978-0-387-77993-5_1"},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Bellare, M., and Rogaway, P. (1993, January 3\u20135). Random oracles are practical: A paradigm for designing efficient protocols. Proceedings of the 1st ACM Conference on Computer and Communications Security, CCS93, Fairfax, VA, USA.","DOI":"10.1145\/168588.168596"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"131","DOI":"10.1016\/j.neucom.2019.03.020","article-title":"Security enhancement of an anonymous roaming authentication scheme with two-factor security in smart city","volume":"347","author":"Xie","year":"2019","journal-title":"Neurocomputing"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Mansoor, K., Ghani, A., Chaudhry, S.A., Shamshirband, S., Ghayyur, S.A.K., and Mosavi, A. (2019). Securing IoT-Based RFID Systems: A Robust Authentication Protocol Using Symmetric Cryptography. Sensors, 19.","DOI":"10.20944\/preprints201907.0298.v1"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"e4139","DOI":"10.1002\/dac.4139","article-title":"Security and key management in IoT-based wireless sensor networks: An authentication protocol using symmetric key","volume":"32","author":"Ghani","year":"2019","journal-title":"Int. J. Commun. Syst."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"1005","DOI":"10.1109\/SURV.2013.091513.00050","article-title":"A Survey of SIP Authentication and Key Agreement Schemes","volume":"16","author":"Kilinc","year":"2014","journal-title":"Commun. Surv. Tutorials IEEE"}],"container-title":["Symmetry"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2073-8994\/12\/2\/287\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T08:58:10Z","timestamp":1760173090000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2073-8994\/12\/2\/287"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,2,15]]},"references-count":37,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2020,2]]}},"alternative-id":["sym12020287"],"URL":"https:\/\/doi.org\/10.3390\/sym12020287","relation":{},"ISSN":["2073-8994"],"issn-type":[{"value":"2073-8994","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,2,15]]}}}