A lightweight password-based authentication protocol using smart card

被引:16
|
作者
Wang, Chenyu [1 ]
Wang, Ding [2 ]
Xu, Guoai [1 ]
Guo, Yanhui [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing, Peoples R China
[2] Peking Univ, Sch Elect Engn & Comp Sci, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
2-factor remote user authentication; discrete logarithm problem; offline-password guessing attack; RAS cryptosystem; smart card; KEY EXCHANGE PROTOCOL; REMOTE; SCHEMES;
D O I
10.1002/dac.3336
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
With its simplicity and feasibility, password-based remote user authentication becomes a popular way to control remote access to network. These years, numerous password-based authentication schemes have been proposed. Recently, Maitra et al proposed a smart card-based scheme which claims to be resistant to various attacks. Unfortunately, we found some important flaws in this scheme. Therefore, in this paper, we will demonstrate that the scheme of Maitra et al is not secure enough as claimed: neither resisting against off-line password guessing attack and insider attack nor preserve forward secrecy. To overcome those flaws, we put forward an improved new scheme which not only is resistant to all known attacks but also provides many attractive attributes, such as user revocation and re-register. Also, we compared the scheme with other related schemes, the result proved the superiority of our scheme. Particularly, we show a new way (beyond the conventional Deffie-Hellman approach) to achieve forward secrecy. Furthermore, we put some efforts into exploring the design principle of authentication schemes.
引用
收藏
页数:11
相关论文
共 50 条
  • [1] An Improvement Password-based Authentication Protocol Using Smart Card
    Hui, Liu
    [J]. SENSORS, MEASUREMENT AND INTELLIGENT MATERIALS, PTS 1-4, 2013, 303-306 : 2182 - 2185
  • [2] Advanced smart card based password authentication protocol
    Song, Ronggong
    [J]. COMPUTER STANDARDS & INTERFACES, 2010, 32 (5-6) : 321 - 325
  • [3] A robust smart card and remote user password-based authentication protocol using extended chaotic maps under smart cities environment
    Meshram, Chandrashekhar
    Ibrahim, Rabha W.
    Deng, Lunzhi
    Shende, Shailendra W.
    Meshram, Sarita Gajbhiye
    Barve, Sharad Kumar
    [J]. SOFT COMPUTING, 2021, 25 (15) : 10037 - 10051
  • [4] A robust smart card and remote user password-based authentication protocol using extended chaotic maps under smart cities environment
    Chandrashekhar Meshram
    Rabha W. Ibrahim
    Lunzhi Deng
    Shailendra W. Shende
    Sarita Gajbhiye Meshram
    Sharad Kumar Barve
    [J]. Soft Computing, 2021, 25 : 10037 - 10051
  • [5] A Protocol to Strengthen Password-Based Authentication
    Sandoval, Itzel Vazquez
    Stojkovski, Borce
    Lenzini, Gabriele
    [J]. EMERGING TECHNOLOGIES FOR AUTHORIZATION AND AUTHENTICATION, ETAA 2018, 2018, 11263 : 38 - 46
  • [6] Notes on "A Password-Based Remote User Authentication Scheme without Smart Card"
    Kumari, Saru
    Li, Xiong
    Khan, Muhammad Khurram
    Kumar, Rahul
    [J]. 2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 116 - 119
  • [7] Enhancing of a Password-Based Authentication Scheme Using Smart Cards
    Lee, Youngsook
    Won, Dongho
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS: OTM 2009, PT 2, 2009, 5871 : 879 - +
  • [8] An anonymous and untraceable password-based authentication scheme for session initiation protocol using smart cards
    Farash, Mohammad Sabzinejad
    Attari, Mahmoud Ahmadian
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2016, 29 (13) : 1956 - 1967
  • [9] An Improved Password-Based Remote User Authentication Protocol without Smart Cards
    Jiang, Qi
    Ma, Jianfeng
    Li, Guangsong
    Ma, Zhuo
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2013, 42 (02): : 150 - 158
  • [10] Cryptanalysis of two password-based authentication schemes using smart cards
    Phan, RCW
    [J]. COMPUTERS & SECURITY, 2006, 25 (01) : 52 - 54