A lightweight password-based authentication protocol using smart card

被引:16
|
作者
Wang, Chenyu [1 ]
Wang, Ding [2 ]
Xu, Guoai [1 ]
Guo, Yanhui [1 ]
机构
[1] Beijing Univ Posts & Telecommun, Beijing, Peoples R China
[2] Peking Univ, Sch Elect Engn & Comp Sci, Beijing, Peoples R China
基金
中国国家自然科学基金;
关键词
2-factor remote user authentication; discrete logarithm problem; offline-password guessing attack; RAS cryptosystem; smart card; KEY EXCHANGE PROTOCOL; REMOTE; SCHEMES;
D O I
10.1002/dac.3336
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
With its simplicity and feasibility, password-based remote user authentication becomes a popular way to control remote access to network. These years, numerous password-based authentication schemes have been proposed. Recently, Maitra et al proposed a smart card-based scheme which claims to be resistant to various attacks. Unfortunately, we found some important flaws in this scheme. Therefore, in this paper, we will demonstrate that the scheme of Maitra et al is not secure enough as claimed: neither resisting against off-line password guessing attack and insider attack nor preserve forward secrecy. To overcome those flaws, we put forward an improved new scheme which not only is resistant to all known attacks but also provides many attractive attributes, such as user revocation and re-register. Also, we compared the scheme with other related schemes, the result proved the superiority of our scheme. Particularly, we show a new way (beyond the conventional Deffie-Hellman approach) to achieve forward secrecy. Furthermore, we put some efforts into exploring the design principle of authentication schemes.
引用
收藏
页数:11
相关论文
共 50 条
  • [31] Improvement on a Smart Card Based Password Authentication Scheme
    He, Debiao
    Chen, Jianhua
    Hu, Jin
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2012, 13 (03): : 405 - 409
  • [32] An Enhanced Authentication Protocol for Multi-server Environment Using Password and Smart Card
    Sudhakar, T.
    Natarajan, V
    Gopinath, M.
    Saranyadevi, J.
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2020, 115 (04) : 2779 - 2803
  • [33] SSO password-based multi-server authentication protocol
    Sood, Sandeep K.
    Sarje, Anil K.
    Singh, Kuldip
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION NETWORKS AND DISTRIBUTED SYSTEMS, 2012, 9 (1-2) : 161 - 180
  • [34] Smart card based secure password authentication scheme
    Wang, SJ
    Chang, JF
    [J]. COMPUTERS & SECURITY, 1996, 15 (03) : 231 - 237
  • [35] A Threshold Multi-Server Protocol for Password-Based Authentication
    Guan, Mengxiang
    Song, Jiaxing
    Liu, Weidong
    [J]. 2016 IEEE 3RD INTERNATIONAL CONFERENCE ON CYBER SECURITY AND CLOUD COMPUTING (CSCLOUD), 2016, : 108 - 118
  • [36] Password-based access control scheme with remote user authentication using smart cards
    Yang, Chen
    Ma, Wenping
    Huang, Benxiong
    Wang, Xinmei
    [J]. 21ST INTERNATIONAL CONFERENCE ON ADVANCED NETWORKING AND APPLICATIONS WORKSHOPS/SYMPOSIA, VOL 2, PROCEEDINGS, 2007, : 448 - +
  • [37] Lightweight and Secure Password Based Smart Home Authentication Protocol: LSP-SHAP
    Sarra Naoui
    Mohamed Elhoucine Elhdhili
    Leila Azouz Saidane
    [J]. Journal of Network and Systems Management, 2019, 27 : 1020 - 1042
  • [38] Cryptanalysis of Three Password-Based Remote User Authentication Schemes with Non-Tamper-Resistant Smart Card
    Wang, Chenyu
    Xu, Guoai
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2017,
  • [39] Lightweight and Secure Password Based Smart Home Authentication Protocol: LSP-SHAP
    Naoui, Sarra
    Elhdhili, Mohamed Elhoucine
    Saidane, Leila Azouz
    [J]. JOURNAL OF NETWORK AND SYSTEMS MANAGEMENT, 2019, 27 (04) : 1020 - 1042
  • [40] Conformal Chebyshev chaotic map-based remote user password authentication protocol using smart card
    Meshram, Chandrashekhar
    Meshram, Sarita Gajbhiye
    Ibrahim, Rabha W.
    Jalab, Hamid A.
    Jamal, Sajjad Shaukat
    Barve, Sharad Kumar
    [J]. COMPLEX & INTELLIGENT SYSTEMS, 2022, 8 (02) : 973 - 987