We have first demonstrated the security pitfalls of Jiang et al.’s
scheme, which includes the vulnerability to on-line and offline
password guessing, insider, and user impersonation attacks.
To overcome the flaws of Jiang et al.’s scheme,we have designed
a secure smart card-based anonymous user authentication
scheme. Our scheme provides the user anonymity property.
Furthermore, our proposed scheme supports the smart
card revocation phase, where a legal user can obtain his/her
lost smart card with the help of server without registering again
to the server. Our proposed scheme satisfies all desirable security
attributes, which are demonstrated in the security
analysis through both the informal and formal security analyses.
In addition, the simulation results for the formal security
analysis using the widely-accepted AVISPA tool clearly indicate
that our scheme is also secure. Considering the security
and efficiency provided by our scheme, we conclude that our
scheme is more appropriate for practical applications in network
security as compared to other existing related schemes.