A New Dynamic ID-based User Authentication Scheme to Resist Smart-Card-Theft Attack

被引:0
|
作者
Lee, Yung-Cheng [1 ]
机构
[1] WuFeng Univ, Dept Secur Technol & Management, Chiayi 62153, Taiwan
来源
关键词
Password Authentication; Dynamic ID; Smart-Card-Theft Attack; PASSWORD AUTHENTICATION; REMOTE; EFFICIENT;
D O I
暂无
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
Password-based remote authentication schemes provide users with convenient and secure mechanisms to access resources through networks. Such schemes can be further divided into static ID and dynamic ID schemes. The main drawback of the static ID scheme is that an adversary can intercept the fixed login ID and masquerade as a legal user to log into the system. On the other hand, dynamic ID schemes can eliminate the risk of ID-theft and protect user's privacy. In 2004, Das et al. proposed a dynamic ID-based remote user authentication scheme. Their scheme allows users to select and update their passwords freely, and the server does not need to maintain a verifier table. In this paper, we first demonstrate that their scheme is not secure. We then propose an improved scheme for security enhancement. This improved scheme has a dynamic advantage such that an adversary cannot trace the users. Because the smart card generates a different random number for each authentication session, the forward messages are always different for each login. This causes the guessing attacks to fail, because the adversary has not enough information to verify his/her guess. Further, the adversary cannot successfully guess the correct password even if he/she obtains the smart card. Therefore, the proposed scheme can withstand smart-card-theft attack.
引用
下载
收藏
页码:355S / 361S
页数:7
相关论文
共 50 条
  • [41] Enhancing the Security of a 'More Efficient & Secure Dynamic ID-based Remote User Authentication Scheme'
    Khan, Muhammad Khurram
    NSS: 2009 3RD INTERNATIONAL CONFERENCE ON NETWORK AND SYSTEM SECURITY, 2009, : 420 - 424
  • [42] Dynamic ID-based remote user password authentication schemes using smart cards: A review
    Madhusudhan, R.
    Mittal, R. C.
    JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2012, 35 (04) : 1235 - 1248
  • [43] Weaknesses in a dynamic ID-based remote user authentication scheme for multi-server environment
    He, Debiao
    Huang, Yin
    INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2012, 4 (01) : 43 - 53
  • [44] A NOVEL DYNAMIC ID-BASED REMOTE MUTUAL AUTHENTICATION SCHEME
    Hsiang, Han-Cheng
    INTERNATIONAL JOURNAL OF INNOVATIVE COMPUTING INFORMATION AND CONTROL, 2010, 6 (06): : 2407 - 2415
  • [45] Improving the dynamic ID-based remote mutual authentication scheme
    Yoon, Eun-Jun
    Yoo, Kee-Young
    ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: OTM 2006 WORKSHOPS, PT 1, PROCEEDINGS, 2006, 4277 : 499 - +
  • [46] Security Improvements of Dynamic ID-based Remote User Authentication Scheme with Session Key Agreement
    An, Young-Hwa
    2013 15TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT), 2013, : 1072 - 1076
  • [47] Improvement on timestamp-based user authentication scheme with smart card lost attack resistance
    Wijayanto, Heri
    Hwang, Min-Shiang
    International Journal of Network Security, 2015, 17 (02) : 160 - 164
  • [49] Security weaknesses of dynamic ID-based remote user authentication protocol
    Lee, Hyoungseob
    Choi, Donghyun
    Lee, Yunho
    Won, Dongho
    Kim, Seungjoo
    World Academy of Science, Engineering and Technology, 2009, 35 : 190 - 193
  • [50] Cryptanalysis of Efficient Dynamic ID Based Remote User Authentication Scheme in Multi-server Environment Using Smart Card
    Pan, Hsieh-Tsen
    Tsaur, Shyh-Chang
    Hwang, Min-Shiang
    PROCEEDINGS OF 2016 12TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS), 2016, : 590 - 593