Robust smart-card-based remote user password authentication scheme

被引:135
|
作者
Chen, Bae-Ling [1 ]
Kuo, Wen-Chung [2 ]
Wuu, Lih-Chyau [3 ]
机构
[1] Natl Yunlin Univ Sci & Technol, Grad Sch Engn Sci & Technol, Touliu 64002, Yunlin, Taiwan
[2] Natl Yunlin Univ Sci & Technol, Dept Comp Sci & Informat Engn, Touliu 64002, Yunlin, Taiwan
[3] Natl Yunlin Univ Sci & Technol, Inst Comp Sci & Informat Engn, Touliu 64002, Yunlin, Taiwan
关键词
smart card; session key agreement; mutual authentication; internal attack; stolen-smart-cardattack;
D O I
10.1002/dac.2368
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Smart-card-based remote user password authentication schemes are commonly used for providing authorized users a secure method for remotely accessing resources over insecure networks. In 2009, Xu etal. proposed a smart-card-based password authentication scheme. They claimed their scheme can withstand attacks when the information stored on the smart card is disclosed. Recently, Sood etal. and Song discovered that the smart-card-based password authentication scheme of Xu etal. is vulnerable to impersonation and internal attacks. They then proposed their respective improved schemes. However, we found that there are still flaws in their schemes: the scheme of Sood etal. does not achieve mutual authentication and the secret key in the login phase of Song's scheme is permanent and thus vulnerable to stolen-smart-card and off-line guessing attacks. In this paper, we will propose an improved and efficient smart-card-based password authentication and key agreement scheme. According to our analysis, the proposed scheme not only maintains the original secret requirement but also achieves mutual authentication and withstands the stolen-smart-card attack. Copyright (c) 2012 John Wiley & Sons, Ltd.
引用
收藏
页码:377 / 389
页数:13
相关论文
共 50 条
  • [1] Cryptanalysis of 'A Robust Smart-Card-Based Remote User Password Authentication Scheme'A
    Kumari, Saru
    Bin Muhaya, Fahad
    Khan, Muhammad Khurram
    Kumar, Rahul
    [J]. 2013 INTERNATIONAL SYMPOSIUM ON BIOMETRICS AND SECURITY TECHNOLOGIES (ISBAST), 2013, : 247 - 250
  • [2] Cryptanalysis and improvement of 'a robust smart-card-based remote user password authentication scheme'
    Kumari, Saru
    Khan, Muhammad Khurram
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2014, 27 (12) : 3939 - 3955
  • [3] Improvement of robust smart-card-based password authentication scheme
    Jiang, Qi
    Ma, Jianfeng
    Li, Guangsong
    Li, Xinghua
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2015, 28 (02) : 383 - 393
  • [4] A smart-card-based remote authentication scheme
    Chang, CC
    Lee, JS
    [J]. ICESS 2005: SECOND INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS, 2005, : 445 - 449
  • [5] Offline Password Guessing Attacks on Smart-Card-Based Remote User Authentication Schemes
    Li, Xue-lei
    Wen, Qiao-yan
    Zhang, Hua
    Jin, Zheng-ping
    Li, Wen-min
    [J]. PROCEEDINGS OF THE 6TH INTERNATIONAL ASIA CONFERENCE ON INDUSTRIAL ENGINEERING AND MANAGEMENT INNOVATION, VOL 2: INNOVATION AND PRACTICE OF INDUSTRIAL ENGINEERING AND MANAGMENT, 2016, : 81 - 89
  • [6] An enhanced smart card based remote user password authentication scheme
    Li, Xiong
    Niu, Jianwei
    Khan, Muhammad Khurram
    Liao, Junguo
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2013, 36 (05) : 1365 - 1371
  • [7] Secure and Efficient Smart-Card-Based Remote User Authentication Scheme for Multiserver Environment
    Shunmuganathan, Saraswathi
    Saravanan, Renuka Devi
    Palanichamy, Yogesh
    [J]. CANADIAN JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING-REVUE CANADIENNE DE GENIE ELECTRIQUE ET INFORMATIQUE, 2015, 38 (01): : 20 - 30
  • [8] Improvements of a Remote User Password Authentication Scheme using Smart Card
    Shin, Kwang Cheul
    Huh, Won Whoi
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (04): : 119 - 126
  • [9] A Robust and Effective Smart-Card-Based Remote User Authentication Mechanism Using Hash Function
    Das, Ashok Kumar
    Odelu, Vanga
    Goswami, Adrijit
    [J]. SCIENTIFIC WORLD JOURNAL, 2014,
  • [10] Robust password and smart card based authentication scheme with smart card revocation
    Xie Q.
    Liu W.-H.
    Wang S.-B.
    Hu B.
    Dong N.
    Yu X.-Y.
    [J]. Journal of Shanghai Jiaotong University (Science), 2014, 19 (4) : 418 - 424