Improvement Upon Mutual Password Authentication Scheme

被引:3
|
作者
Zhu, Lu [1 ]
Yu, Sheng [2 ]
Zhang, Xing [3 ]
机构
[1] Wuhan Univ, Sch Comp, Wuhan 430072, Peoples R China
[2] Informat Engn Univ, Inst Elect Technol, Zhengzhou, Peoples R China
[3] Beijing Univ Technol, Trusted Comp Lab, Beijing, Peoples R China
关键词
authentication; password; hash function; secure; attack; trusted computing; NETWORKS;
D O I
10.1109/ISBIM.2008.138
中图分类号
F [经济];
学科分类号
02 ;
摘要
Many password authentication schemes have been proposed for electronic commerce environment; however, none of them is secure enough. Hwang and Yeh proposed an improvement on the Peyravian-Zunic password authentication scheme including protected password transmission and password change. We demonstrate that the Hwang-Yeh scheme is also vulnerable to several kinds of attacks though the scheme has repaired some security problems of the Peyravianis-Zunic scheme. Furthermore, we propose an improved scheme to enhance security of their scheme in the paper. Based on collision-resistant hash function, the proposal employs techniques of salting, time stamp and trusted computing to be free from worries of possible common attacks, such as replay attack, guessing attack, stolen-verifier attack, denial of service attack, impersonation attack, and server spoofing attack. According to security analysis over insecure networks, the proposed scheme is the most secure scheme among the Peyravian-Zunic scheme, the Hwang-Yeh scheme, the Peyravian-Jeffries scheme, and the Wang-Zhang scheme.
引用
收藏
页码:400 / +
页数:2
相关论文
共 50 条
  • [1] Improvement on a Smart Card Based Password Authentication Scheme
    He, Debiao
    Chen, Jianhua
    Hu, Jin
    [J]. JOURNAL OF INTERNET TECHNOLOGY, 2012, 13 (03): : 405 - 409
  • [2] An improvement on a password authentication scheme over insecure networks
    Zeng, Yong
    Ma, Jianfeng
    [J]. Journal of Computational Information Systems, 2009, 5 (04): : 1331 - 1336
  • [3] A REMOTE PASSWORD AUTHENTICATION SCHEME BASED UPON ELGAMALS SIGNATURE SCHEME
    CHANG, CC
    LIAO, WY
    [J]. COMPUTERS & SECURITY, 1994, 13 (02) : 137 - 144
  • [4] Improved Password Mutual Authentication Scheme for Remote Login Network Systems
    An, Younghwa
    [J]. MULTIMEDIA, COMPUTER GRAPHICS AND BROADCASTING, PT II, 2011, 263 : 263 - 269
  • [5] Mutual authentication scheme with smart cards and password under trusted computing
    Yang, Li
    Ma, Jian-Feng
    Jiang, Qi
    [J]. International Journal of Network Security, 2012, 14 (03) : 156 - 163
  • [6] Security improvement on a timestamp-based password authentication scheme
    Wang, YJ
    Li, JH
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 580 - 582
  • [7] A password authentication scheme with secure password updating
    Lin, CL
    Hwang, T
    [J]. COMPUTERS & SECURITY, 2003, 22 (01) : 68 - 72
  • [8] A friendly password mutual authentication scheme for remote-login network systems
    Chang, Chin-Chen
    Lee, Chia-Yin
    [J]. International Journal of Multimedia and Ubiquitous Engineering, 2008, 3 (01): : 59 - 64
  • [9] Improvement of smart card based password authentication scheme for multiserver environments
    Tan, Zuowen
    [J]. TURKISH JOURNAL OF ELECTRICAL ENGINEERING AND COMPUTER SCIENCES, 2012, 20 (06) : 881 - 900
  • [10] Cryptanalysis and improvement of an efficient password authentication scheme based on smart card
    [J]. 1600, Computer Society of the Republic of China (25):