Cryptanalysis of 'A Robust Smart-Card-Based Remote User Password Authentication Scheme'A

被引:0
|
作者
Kumari, Saru [1 ]
Bin Muhaya, Fahad [2 ]
Khan, Muhammad Khurram [3 ]
Kumar, Rahul [4 ]
机构
[1] Dr BRA Univ, Agra Coll, Dept Math, Agra, Uttar Pradesh, India
[2] King Saud Univ, Coll Business Adm, MIS Dept, Riyadh 11451, Saudi Arabia
[3] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh 11451, Saudi Arabia
[4] D BS Coll, Dept Math, Agra, Uttar Pradesh, India
关键词
Smart card; Session-key disclosure; Password guessing attack; User anonymity; User impersonation attack; IMPROVEMENT; EFFICIENT;
D O I
10.1109/ISBAST.2013.43
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Smart card is a widely accepted user authentication tool to ensure only authorized access to resources available via open networks. In 2010, Sood et al. and Song independently examined a smart card based authentication scheme proposed by Xu et al. They showed that in Xu et al.'s scheme an internal user of the system could turn hostile to impersonate other users of the system. Sood et al. and Song also proposed schemes in order to improve scheme proposed by Xu et al.'s. Recently, Chen et al. identified some security problems in the improvements proposed by Sood et al. and Song. To fix these problems Chen et al. presented another scheme, which they claimed to provide mutual authentication and withstand, lost smart card attack. Undoubtedly, in their scheme user can also verify the legitimacy of server but we find that the scheme fails to resist impersonation attacks and privileged insider attack. We also show that the scheme does not provide user anonymity and confidentiality to air messages. In addition, an attacker can guess a user's password from his lost/stolen smart card.
引用
收藏
页码:247 / 250
页数:4
相关论文
共 50 条
  • [1] Cryptanalysis and improvement of 'a robust smart-card-based remote user password authentication scheme'
    Kumari, Saru
    Khan, Muhammad Khurram
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (12) : 3939 - 3955
  • [2] Robust smart-card-based remote user password authentication scheme
    Chen, Bae-Ling
    Kuo, Wen-Chung
    Wuu, Lih-Chyau
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (02) : 377 - 389
  • [3] Improvement of robust smart-card-based password authentication scheme
    Jiang, Qi
    Ma, Jianfeng
    Li, Guangsong
    Li, Xinghua
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2015, 28 (02) : 383 - 393
  • [4] A smart-card-based remote authentication scheme
    Chang, CC
    Lee, JS
    [J]. ICESS 2005: SECOND INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2005, : 445 - 449
  • [5] Offline Password Guessing Attacks on Smart-Card-Based Remote User Authentication Schemes
    Li, Xue-lei
    Wen, Qiao-yan
    Zhang, Hua
    Jin, Zheng-ping
    Li, Wen-min
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL ASIA CONFERENCE ON INDUSTRIAL ENGINEERING AND MANAGEMENT INNOVATION, VOL 2: INNOVATION AND PRACTICE OF INDUSTRIAL ENGINEERING AND MANAGMENT, 2016, : 81 - 89
  • [6] Cryptanalysis of a Sensor Smart Card Based Password Authentication Scheme with User Anonymity
    Cao, Tianjie
    Huang, Shi
    [J]. SENSOR LETTERS, 2013, 11 (11) : 2149 - 2151
  • [7] An enhanced smart card based remote user password authentication scheme
    Li, Xiong
    Niu, Jianwei
    Khan, Muhammad Khurram
    Liao, Junguo
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2013, 36 (05) : 1365 - 1371
  • [8] Cryptanalysis of a User Anonymous Password Authentication Scheme Without Smart Card
    Lin, Hao
    Wen, Feng-Tong
    Du, Chun-Xia
    [J]. 2016 INTERNATIONAL CONFERENCE ON SERVICE SCIENCE, TECHNOLOGY AND ENGINEERING (SSTE 2016), 2016, : 293 - 298
  • [9] Secure and Efficient Smart-Card-Based Remote User Authentication Scheme for Multiserver Environment
    Shunmuganathan, Saraswathi
    Saravanan, Renuka Devi
    Palanichamy, Yogesh
    [J]. CANADIAN JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING-REVUE CANADIENNE DE GENIE ELECTRIQUE ET INFORMATIQUE, 2015, 38 (01): : 20 - 30
  • [10] Improvements of a Remote User Password Authentication Scheme using Smart Card
    Shin, Kwang Cheul
    Huh, Won Whoi
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (04): : 119 - 126