A New Dynamic ID-based User Authentication Scheme to Resist Smart-Card-Theft Attack

被引:0
|
作者
Lee, Yung-Cheng [1 ]
机构
[1] WuFeng Univ, Dept Secur Technol & Management, Chiayi 62153, Taiwan
来源
关键词
Password Authentication; Dynamic ID; Smart-Card-Theft Attack; PASSWORD AUTHENTICATION; REMOTE; EFFICIENT;
D O I
暂无
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
Password-based remote authentication schemes provide users with convenient and secure mechanisms to access resources through networks. Such schemes can be further divided into static ID and dynamic ID schemes. The main drawback of the static ID scheme is that an adversary can intercept the fixed login ID and masquerade as a legal user to log into the system. On the other hand, dynamic ID schemes can eliminate the risk of ID-theft and protect user's privacy. In 2004, Das et al. proposed a dynamic ID-based remote user authentication scheme. Their scheme allows users to select and update their passwords freely, and the server does not need to maintain a verifier table. In this paper, we first demonstrate that their scheme is not secure. We then propose an improved scheme for security enhancement. This improved scheme has a dynamic advantage such that an adversary cannot trace the users. Because the smart card generates a different random number for each authentication session, the forward messages are always different for each login. This causes the guessing attacks to fail, because the adversary has not enough information to verify his/her guess. Further, the adversary cannot successfully guess the correct password even if he/she obtains the smart card. Therefore, the proposed scheme can withstand smart-card-theft attack.
引用
下载
收藏
页码:355S / 361S
页数:7
相关论文
共 50 条
  • [1] Cryptanalysis of a New Dynamic ID-based User Authentication Scheme to Resist Smart-Card-Theft Attack
    Wen, Fengtong
    Guo, Dianli
    Li, Xuelei
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2014, 8 (04): : 1855 - 1858
  • [2] Modified Dynamic ID-based User Authentication Scheme Resisting Smart-Card-Theft Attack
    Toan Thinh Truong
    Minh Triet Tran
    Anh Duc Duong
    APPLIED MATHEMATICS & INFORMATION SCIENCES, 2014, 8 (03): : 967 - 976
  • [3] IMPROVED ID-BASED REMOTE USER AUTHENTICATION SCHEME USING SMART CARD
    Toan-Thinh Truong
    Minh-Triet Tran
    Anh-Duc Duong
    2013 9TH INTERNATIONAL WIRELESS COMMUNICATIONS AND MOBILE COMPUTING CONFERENCE (IWCMC), 2013, : 1672 - 1677
  • [4] Impersonation attack on a dynamic ID-based remote user authentication scheme using smart cards
    Ku, WC
    Chang, ST
    IEICE TRANSACTIONS ON COMMUNICATIONS, 2005, E88B (05) : 2165 - 2167
  • [5] An ID-based authentication scheme to achieve the security of smart card
    Xu N.
    Huang H.
    Li Z.
    Wang Y.
    Sha C.
    International Journal of Security and Networks, 2018, 13 (01) : 42 - 50
  • [6] An Improvement of Dynamic ID-Based Remote User Authentication Scheme with Smart Cards
    Gao, Zhengxian
    Tu, Yaqing
    2008 7TH WORLD CONGRESS ON INTELLIGENT CONTROL AND AUTOMATION, VOLS 1-23, 2008, : 4562 - 4567
  • [7] A dynamic ID-based remote user authentication scheme
    Das, ML
    Saxena, A
    Gulati, VP
    IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 629 - 631
  • [8] A Dynamic ID-based authentication scheme with smart token
    Hamza, Nermin
    Hassan, Bahaa El-Din M.
    2009 INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND SYSTEMS (ICCES 2009), 2009, : 294 - +
  • [9] Improved Dynamic ID-Based Remote User Authentication Scheme Using Smart cards
    Li Jian
    Hu Lan-lan
    2008 4TH INTERNATIONAL CONFERENCE ON WIRELESS COMMUNICATIONS, NETWORKING AND MOBILE COMPUTING, VOLS 1-31, 2008, : 4607 - 4610
  • [10] Robust dynamic ID-based remote user authentication scheme using smart cards
    Li, Xiong
    Niu, Jianwei
    Liu, Yazhi
    Liao, Junguo
    Liang, Wei
    INTERNATIONAL JOURNAL OF AD HOC AND UBIQUITOUS COMPUTING, 2014, 17 (04) : 254 - 264