A SECURE PASSWORD-BASED REMOTE USER AUTHENTICATION SCHEME WITHOUT SMART CARDS

被引:25
|
作者
Chen, Bae-Ling [2 ]
Kuo, Wen-Chung [1 ]
Wuu, Lih-Chyau [3 ]
机构
[1] Natl Yunlin Univ Sci & Technol, Dept Comp Sci & Informat Engn, Touliu 64002, Yunlin, Taiwan
[2] Natl Yunlin Univ Sci & Technol, Grad Sch Engn Sci & Technol, Touliu 64002, Yunlin, Taiwan
[3] Natl Yunlin Univ Sci & Technol, Inst Comp Sci & Informat Engn, Touliu 64002, Yunlin, Taiwan
来源
INFORMATION TECHNOLOGY AND CONTROL | 2012年 / 41卷 / 01期
关键词
password-based; remote access; tamper-resistant; mutual authentication; impersonation attack; EFFICIENT; CRYPTANALYSIS; NONCE;
D O I
10.5755/j01.itc.41.1.975
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
There are many remote user authentication schemes proposed in literature for preventing unauthorized parties from accessing resources in an insecure environment. Due to inherent tamper-resistance, most of them are based on smart card authentication schemes. Unfortunately, the cost of cards and readers makes these schemes costly. In the real world, common storage devices, such as universal serial bus (USB) thumb drives, portable HDDs, mobile phones, Laptop or Desktop PCs, are widely used, and they are much cheaper or more convenient for storing user authentication information. However, since these devices do not provide tamper-resistance, it is a challenge to design a secure authentication scheme using these kinds of memory devices. In this paper, we will propose a secure password-based remote user authentication and key agreement scheme without using smart cards. According to our analysis, the proposed scheme guarantees mutual authentication and also resists off-line dictionary, replay, forgery, and impersonation attacks. Compared to related scheme, the proposed scheme's computation cost is lower and the total message length is shorter. Therefore, our scheme is suitable even for applications in limited power computing environments.
引用
收藏
页码:53 / 59
页数:7
相关论文
共 50 条
  • [1] Cryptanalysis and Improvement of a Password-Based Remote User Authentication Scheme without Smart Cards
    He, Debiao
    Wang, Ding
    Wu, Shuhua
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2013, 42 (02): : 170 - 177
  • [2] Secure Password-Based Remote User Authentication Scheme with Non-tamper Resistant Smart Cards
    Wang, Ding
    Ma, Chun-guang
    Wu, Peng
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 114 - 121
  • [3] An Improved Password-Based Remote User Authentication Protocol without Smart Cards
    Jiang, Qi
    Ma, Jianfeng
    Li, Guangsong
    Ma, Zhuo
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2013, 42 (02): : 150 - 158
  • [4] Password-based access control scheme with remote user authentication using smart cards
    Yang, Chen
    Ma, Wenping
    Huang, Benxiong
    Wang, Xinmei
    [J]. 21ST INTERNATIONAL CONFERENCE ON ADVANCED NETWORKING AND APPLICATIONS WORKSHOPS/SYMPOSIA, VOL 2, PROCEEDINGS, 2007, : 448 - +
  • [5] Notes on "A Password-Based Remote User Authentication Scheme without Smart Card"
    Kumari, Saru
    Li, Xiong
    Khan, Muhammad Khurram
    Kumar, Rahul
    [J]. 2014 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2014, : 116 - 119
  • [7] A Secure and Robust Password-Based Remote User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Ashok Kumar Das
    [J]. Journal of Medical Systems, 2015, 39
  • [8] A secure password-based authentication and key agreement scheme using smart cards
    Mishra, Dheerendra
    Das, Ashok Kumar
    Chaturvedi, Ankita
    Mukhopadhyay, Sourav
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2015, 23 : 28 - 43
  • [9] Secure password-based remote user authentication scheme against smart card security breach
    [J]. Wang, D. (wangdingg@mail.nankai.edu.cn), 1600, Academy Publisher (08):
  • [10] A Secure and Efficient Password-Based User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Tian-Fu Lee
    I-Pin Chang
    Tsung-Hung Lin
    Ching-Cheng Wang
    [J]. Journal of Medical Systems, 2013, 37