A lightweight password-based authentication protocol using smart card

被引:16
|
作者
Wang, Chenyu [1 ]
Wang, Ding [2 ]
Xu, Guoai [1 ]
Guo, Yanhui [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing, Peoples R China
[2] Peking Univ, Sch Elect Engn & Comp Sci, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
2-factor remote user authentication; discrete logarithm problem; offline-password guessing attack; RAS cryptosystem; smart card; KEY EXCHANGE PROTOCOL; REMOTE; SCHEMES;
D O I
10.1002/dac.3336
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
With its simplicity and feasibility, password-based remote user authentication becomes a popular way to control remote access to network. These years, numerous password-based authentication schemes have been proposed. Recently, Maitra et al proposed a smart card-based scheme which claims to be resistant to various attacks. Unfortunately, we found some important flaws in this scheme. Therefore, in this paper, we will demonstrate that the scheme of Maitra et al is not secure enough as claimed: neither resisting against off-line password guessing attack and insider attack nor preserve forward secrecy. To overcome those flaws, we put forward an improved new scheme which not only is resistant to all known attacks but also provides many attractive attributes, such as user revocation and re-register. Also, we compared the scheme with other related schemes, the result proved the superiority of our scheme. Particularly, we show a new way (beyond the conventional Deffie-Hellman approach) to achieve forward secrecy. Furthermore, we put some efforts into exploring the design principle of authentication schemes.
引用
收藏
页数:11
相关论文
共 50 条
  • [21] Privacy Preserving Password-Based Multi-server Authenticated Key Agreement Protocol Using Smart Card
    Mishra, Dheerendra
    Dhal, Subhasish
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2018, 99 (01) : 1 - 21
  • [22] Privacy Preserving Password-Based Multi-server Authenticated Key Agreement Protocol Using Smart Card
    Dheerendra Mishra
    Subhasish Dhal
    [J]. Wireless Personal Communications, 2018, 99 : 1 - 21
  • [23] Comments on "Insider Attack Protection: Lightweight Password-Based Authentication Techniques Using ECC"
    Shamshad, Salman
    Mahmood, Khalid
    Kumari, Saru
    Khan, Muhammad Khurram
    [J]. IEEE SYSTEMS JOURNAL, 2021, 15 (01): : 877 - 880
  • [24] An improved password-based authentication scheme for session initiation protocol using smart cards without verification table
    Farash, Mohammad Sabsinejad
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (01)
  • [25] Robust password and smart card based authentication scheme with smart card revocation
    Xie Q.
    Liu W.-H.
    Wang S.-B.
    Hu B.
    Dong N.
    Yu X.-Y.
    [J]. Journal of Shanghai Jiaotong University (Science), 2014, 19 (04) : 418 - 424
  • [26] A secure password-based authentication and key agreement scheme using smart cards
    Mishra, Dheerendra
    Das, Ashok Kumar
    Chaturvedi, Ankita
    Mukhopadhyay, Sourav
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2015, 23 : 28 - 43
  • [27] Robust Password and Smart Card Based Authentication Scheme with Smart Card Revocation
    谢琪
    刘文浩
    王圣宝
    胡斌
    董娜
    于秀源
    [J]. Journal of Shanghai Jiaotong University(Science), 2014, 19 (04) : 418 - 424
  • [28] Cryptanalysis of two efficient password-based authentication schemes using smart cards
    Department of computer science and technology, Taiyuan University of Technology, Taiyuan
    030024, China
    [J]. Int. J. Netw. Secur., 6 (728-735):
  • [29] Security analysis and improvement of the efficient password-based authentication protocol
    Kwon, T
    Park, YH
    Lee, HJ
    [J]. IEEE COMMUNICATIONS LETTERS, 2005, 9 (01) : 93 - 95
  • [30] An Enhanced Authentication Protocol for Multi-server Environment Using Password and Smart Card
    T. Sudhakar
    V. Natarajan
    M. Gopinath
    J. Saranyadevi
    [J]. Wireless Personal Communications, 2020, 115 : 2779 - 2803