Off-line pas sword-guessing attack to Peyravian-Jeffries's remote user authentication protocol

被引:11
|
作者
Munilla, J. [1 ]
Peinado, A. [1 ]
机构
[1] Univ Malaga, ETSI Telecomun, Dept Ingn Comun, Malaga 29071, Spain
关键词
authentication; hash; cryptanalysis; password;
D O I
10.1016/j.comcom.2006.07.012
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, Peyravian and Jeffries [M. Peyravian, C. Jeffries, Secure remote user access over insecure networks, Computer Communications 29 (2006) 660-667] have proposed two set of protocols to perform remote user authentication and password change in a secure manner. The first set of protocols is based on hash functions, where no symmetric or asymmetric encryption scheme is applied. As Peyravian and Jeffries claim, these protocols suffer from an off-line password-guessing attack. They propose a second set of protocols based on Diffie-Hellman key agreement scheme to overcome the mentioned weakness. However, we show in this paper that this second set of protocols suffers also from the off-line password-guessing attack when a server impersonation attack is performed. (c) 2006 Elsevier B.V. All rights reserved.
引用
收藏
页码:52 / 54
页数:3
相关论文
共 5 条
  • [1] SECURITY ANALYSIS OF PEYRAVIAN-JEFFRIES'S REMOTE USER AUTHENTICATION PROTOCOL
    Guo, Yongning
    Liu, Chenglian
    2011 3RD INTERNATIONAL CONFERENCE ON COMPUTER TECHNOLOGY AND DEVELOPMENT (ICCTD 2011), VOL 1, 2012, : 767 - 771
  • [2] Improvement of the Peyravian-Jeffries's user authentication protocol and password change protocol
    Hoelbl, Marko
    Welzer, Tatjana
    Brumen, Bostjan
    COMPUTER COMMUNICATIONS, 2008, 31 (10) : 1945 - 1951
  • [3] An efficient remote user authentication scheme secure against the off-line password guessing attack by power analysis
    Park, Ji-Hye
    Lee, Ji-Seon
    Chang, Jik Hyun
    11TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS I-III, PROCEEDINGS,: UBIQUITOUS ICT CONVERGENCE MAKES LIFE BETTER!, 2009, : 1289 - 1292
  • [4] Off-line password guessing attack on an efficient key agreement protocol for secure authentication
    Department of Computer Science and Engineering, Shanghai Jiao Tong University, No. 1954, Huashan Road, Shanghai 200030, China
    Int. J. Netw. Secur., 2006, 1 (35-38):
  • [5] Off-line password-guessing attacks on the generalized key agreement and password authentication protocol
    Shim, K
    APPLIED MATHEMATICS AND COMPUTATION, 2005, 169 (01) : 511 - 515