Abstract
Abstract In distributed network environments, secure communication in insecure channels is a very important issue. Thus, authentication and secret key distribution become the most important security services in distributed environments. Most of the remote mutual authentication and key agreement schemes are based on static ID; the static ID may leak partial information about the user’s login message so that the adversary may trace a particular user according to the transmitted ID and start some attacking actions. It is unsatisfactory for its use in real life applications, such as e-commerce. Therefore, protecting user’s privacy in insecure networks becomes an important issue. In addition, majority of these schemes are designed for the single-server architecture. If conventional password authentication methods are applied to multi-servers environment, each network user does not only need to login various remote servers repetitively but also need to remember different identifications and passwords for accessing different servers. It is inefficient and easily evokes the compromise of the identities and passwords. Hence, this study reviews several related researches, and points out the security flaws of these researches. Then, we present several remote user authentication schemes to enhance the security of theses reviewed schemes. In addition, we propose an RFID authentication system and a mCoupons scheme for practical m-commerce environments. The proposed schemes may satisfy the essential security requirements. In the secure mCoupon scheme, NFC in combination with inexpensive passive tags and some servers is used to prevent attacks on an m-commerce application. Therefore, the proposed schemes are well suited to the real applications environment.