Security enhancement on an improvement on two remote user authentication schemes using smart cards

被引:57
|
作者
Chen, Tien-Ho [1 ]
Hsiang, Han-Cheng [2 ]
Shih, Wei-Kuan [1 ]
机构
[1] Natl Tsing Hua Univ, Dept Comp Sci, Hsingchu 300, Taiwan
[2] Vanung Univ, Dept Informat Management, Chungli, Taiwan
关键词
Authentication; Cryptography; Password; Impersonation attack; Parallel session attack; PASSWORD AUTHENTICATION; EFFICIENT; CRYPTANALYSIS;
D O I
10.1016/j.future.2010.08.007
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the current level of development of network technologies, various business activities take place on the Internet, and therefore how to assure the security of these activities over an insecure communication channel has become one of the most important issues. Authentication is the first step to protect users. Recently, Wang et al. proposed a remote user authentication scheme using smart cards to provide users with secure activities over an insecure Internet environment. Wang et al. claimed that their scheme is secured against guessing attacks, forgery attacks and denial of service (DoS) attacks which Ku et al.'s and Yoon et al.'s schemes suffered from. In this paper, we state that Wang et al.'s scheme is still vulnerable to the impersonation attack and parallel session attack. Furthermore, we propose an enhancement of Wang et al.'s scheme and provide the criteria of authentication scheme which secures a user against the risk of attack over an insecure Internet environment, for instance, session key agreement, mutual authentication and perfect forward secrecy. Moreover, we analyze the security of our scheme and prove that ours is suitable for applications with high security requirements. (C) 2010 Elsevier B.V. All rights reserved.
引用
收藏
页码:377 / 380
页数:4
相关论文
共 50 条
  • [1] Security Enhancement on an Improvement on Two Remote User Authentication Scheme Using Smart Cards
    Hsiang, HanCheng
    Chen, TienHo
    Shih, WeiKuan
    [J]. COMMUNICATION AND NETWORKING, 2009, 56 : 65 - +
  • [2] Security of two remote user authentication schemes using smart cards
    Hsu, CL
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2003, 49 (04) : 1196 - 1198
  • [3] An Improvement on Remote User Authentication Schemes Using Smart Cards
    Chen, Chin-Ling
    Deng, Yong-Yuan
    Tang, Yung-Wen
    Chen, Jung-Hsuan
    Lin, Yu-Fan
    [J]. COMPUTERS, 2018, 7 (01)
  • [4] Security flaws in two improved remote user authentication schemes using smart cards
    Ma, Chun-Guang
    Wang, Ding
    Zhao, Sen-Dong
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (10) : 2215 - 2227
  • [5] Security enhancement of a remote user authentication scheme using smart cards
    Lee, Youngsook
    Nam, Junghyun
    Won, Dongho
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS 2006: OTM 2006 WORKSHOPS, PT 1, PROCEEDINGS, 2006, 4277 : 508 - +
  • [6] Security Improvement on a Remote User Authentication Scheme Using Smart Cards
    Chen, Tien-Ho
    Hsiang, Han-Cheng
    Shih, Wei-Kuan
    [J]. INFORMATION SECURITY AND ASSURANCE, 2010, 76 : 9 - +
  • [7] Further attacks and comments on 'Security of two remote user authentication schemes using smart cards'
    Phan, RCW
    Goi, BM
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 609 - 611
  • [8] Two secure remote user authentication schemes using smart cards
    Wang, Xue-Guang
    Chai, Zhen-Chuan
    [J]. PROCEEDINGS OF 2006 INTERNATIONAL CONFERENCE ON MACHINE LEARNING AND CYBERNETICS, VOLS 1-7, 2006, : 2653 - +
  • [9] Cryptanalysis and security enhancement of a remote user authentication scheme using smart cards
    WANG DingMA Chunguang College of Computer Science and TechnologyHarbin Engineering UniversityHarbin China Automobile Management Institute of PLABengbu China
    [J]. The Journal of China Universities of Posts and Telecommunications., 2012, 19 (05) - 114