A New Dynamic ID-based User Authentication Scheme to Resist Smart-Card-Theft Attack

被引:0
|
作者
Lee, Yung-Cheng [1 ]
机构
[1] WuFeng Univ, Dept Secur Technol & Management, Chiayi 62153, Taiwan
来源
关键词
Password Authentication; Dynamic ID; Smart-Card-Theft Attack; PASSWORD AUTHENTICATION; REMOTE; EFFICIENT;
D O I
暂无
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
Password-based remote authentication schemes provide users with convenient and secure mechanisms to access resources through networks. Such schemes can be further divided into static ID and dynamic ID schemes. The main drawback of the static ID scheme is that an adversary can intercept the fixed login ID and masquerade as a legal user to log into the system. On the other hand, dynamic ID schemes can eliminate the risk of ID-theft and protect user's privacy. In 2004, Das et al. proposed a dynamic ID-based remote user authentication scheme. Their scheme allows users to select and update their passwords freely, and the server does not need to maintain a verifier table. In this paper, we first demonstrate that their scheme is not secure. We then propose an improved scheme for security enhancement. This improved scheme has a dynamic advantage such that an adversary cannot trace the users. Because the smart card generates a different random number for each authentication session, the forward messages are always different for each login. This causes the guessing attacks to fail, because the adversary has not enough information to verify his/her guess. Further, the adversary cannot successfully guess the correct password even if he/she obtains the smart card. Therefore, the proposed scheme can withstand smart-card-theft attack.
引用
下载
收藏
页码:355S / 361S
页数:7
相关论文
共 50 条
  • [31] A New Dynamic ID-Based User Authentication Scheme Using Mobile Device: Cryptanalysis, the Principles and Design
    Xiong Li
    Junguo Liao
    Saru Kumari
    Wei Liang
    Fan Wu
    Muhammad Khurram Khan
    Wireless Personal Communications, 2015, 85 : 263 - 288
  • [32] A New Dynamic ID-Based User Authentication Scheme Using Mobile Device: Cryptanalysis, the Principles and Design
    Li, Xiong
    Liao, Junguo
    Kumari, Saru
    Liang, Wei
    Wu, Fan
    Khan, Muhammad Khurram
    WIRELESS PERSONAL COMMUNICATIONS, 2015, 85 (01) : 263 - 288
  • [33] A novel smart card and dynamic ID based remote user authentication scheme for multi-server environments
    Li, Xiong
    Ma, Jian
    Wang, Wendong
    Xiong, Yongping
    Zhang, Junsong
    MATHEMATICAL AND COMPUTER MODELLING, 2013, 58 (1-2) : 85 - 95
  • [34] Attacks and Improvement of "Security Enhancement for a Dynamic ID-based Remote User Authentication Scheme"
    Cheikrouhou, Omar
    Boujelben, Manel
    Koubaa, Anis
    Abid, Mohamed
    2009 IEEE/ACS INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS, VOLS 1 AND 2, 2009, : 517 - +
  • [35] Comment on 'Efficient and secure dynamic ID-based remote user authentication scheme for distributed systems using smart cards'
    Reddy, Alavalapati Goutham
    Yoon, Eun-Jun
    Yoo, Kee-Young
    IET INFORMATION SECURITY, 2017, 11 (04) : 220 - 221
  • [36] AN IMPROVED DOS-RESISTANT ID-BASED PASSWORD AUTHENTICATION SCHEME WITHOUT USING SMART CARD
    Wen Fengtong Li Xuelei Cui Shenjun(School of Mathematics
    Journal of Electronics(China), 2011, (Z1) : 580 - 586
  • [37] AN IMPROVED DOS-RESISTANT ID-BASED PASSWORD AUTHENTICATION SCHEME WITHOUT USING SMART CARD
    Wen Fengtong Li Xuelei Cui ShenjunSchool of MathematicsUniversity of JinanJinan China
    Journal of Electronics(China), 2011, 28(Z1) (China) : 580 - 586
  • [38] A smart card based remote user authentication scheme
    Centre for Development of Advanced Computing, 68, Electronic City, Bangalore, India
    不详
    不详
    J. Digit. Inf. Manage., 2008, 3 (256-261):
  • [39] Smart Card Based User Authentication Scheme with Anonymity
    Toan-Thinh Truong
    Minh-Triet Tran
    Anh-Duc Duong
    FUTURE DATA AND SECURITY ENGINEERING, FDSE 2014, 2014, 8860 : 220 - 233
  • [40] Cryptanalysis of Three Dynamic ID-Based Remote User Authentication Schemes Using Smart Cards
    Gao, Zhengxian
    Huang, Shou Hsuan Stephen
    Ding, Wei
    2016 IEEE INTERNATIONAL CONFERENCE OF ONLINE ANALYSIS AND COMPUTING SCIENCE (ICOACS), 2016, : 44 - 52