Improvement of robust smart-card-based password authentication scheme

被引:97
|
作者
Jiang, Qi [1 ]
Ma, Jianfeng [1 ]
Li, Guangsong [2 ]
Li, Xinghua [1 ]
机构
[1] Xidian Univ, Sch Comp Sci & Technol, Xian 710071, Peoples R China
[2] Zhengzhou Informat Sci & Technol Inst, Dept Informat Res, Zhengzhou 450002, Peoples R China
基金
中国国家自然科学基金;
关键词
remote access; mutual authentication; secure channel; password; smart card; offline password guessing attack; REMOTE AUTHENTICATION;
D O I
10.1002/dac.2644
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Smart-card-based password authentication scheme is one of the commonly used mechanisms to prevent unauthorized service and resource access and to remove the potential security threats over the insecure networks and has been investigated extensively in the last decade. Recently, Chen et al. proposed a smart-card-based password authentication scheme and claimed that the scheme can withstand offline password guessing attacks even if the information stored in the smart card is extracted by the adversary. However, we observe that the scheme of Chen et al. is insecure against offline password guessing attacks in this case. To remedy this security problem, we propose an improved authentication protocol, which inherits the merits of the scheme of Chen et al. and is free from the security flaw of their scheme. Compared with the previous schemes, our improved scheme provides more security guarantees while keeping efficiency. Copyright (c) 2013 John Wiley & Sons, Ltd.
引用
收藏
页码:383 / 393
页数:11
相关论文
共 50 条
  • [31] A pairing-based password authentication scheme using smart card with user anonymity
    Jiang, Linmei
    Dai, Songsong
    Liu, Niansheng
    Guo, Donghui
    [J]. INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2015, 9 (01) : 12 - 22
  • [32] Improvements of a remote user password authentication scheme using smart card
    Division of Industrial Management Engineering, Sungkyul University, #147-2, Anyang 8 dong, Manan-gu, Anyang-si, Gyeonggi-do 430-742, Korea, Republic of
    [J]. Shin, K.C. (skcskc12@sungkyul.edu), 1600, Science and Engineering Research Support Society, 20 Virginia Court, Sandy Bay, Tasmania, Australia (07):
  • [33] Cryptanalysis of a User Anonymous Password Authentication Scheme Without Smart Card
    Lin, Hao
    Wen, Feng-Tong
    Du, Chun-Xia
    [J]. 2016 INTERNATIONAL CONFERENCE ON SERVICE SCIENCE, TECHNOLOGY AND ENGINEERING (SSTE 2016), 2016, : 293 - 298
  • [34] Improvements of a Remote User Password Authentication Scheme using Smart Card
    Shin, Kwang Cheul
    Huh, Won Whoi
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (04): : 119 - 126
  • [35] Design of a user anonymous password authentication scheme without smart card
    Kumari, Saru
    Khan, Muhammad Khurram
    Li, Xiong
    Wu, Fan
    [J]. INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2016, 29 (03) : 441 - 458
  • [36] A Security Improved Remote Password Authentication Scheme using Smart Card
    Jing, Chao
    [J]. EQUIPMENT MANUFACTURING TECHNOLOGY AND AUTOMATION, PTS 1-3, 2011, 317-319 : 1791 - 1796
  • [37] Robust one-time password authentication scheme using smart card for home network environment
    Vaidya, Binod
    Park, Jong Hyuk
    Yeo, Sang-Soo
    Rodrigues, Joel J. P. C.
    [J]. COMPUTER COMMUNICATIONS, 2011, 34 (03) : 326 - 336
  • [38] A Smart-Card-Based Remote User Authentication Protocol with Privacy Support
    Lu, Jian-Zhu
    Deng, Shengyuan
    Zhou, Jipeng
    Fan, Xiuwei
    Yang, Hao
    [J]. 2012 13TH INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING, APPLICATIONS, AND TECHNOLOGIES (PDCAT 2012), 2012, : 96 - 101
  • [39] Analysis and Improvement of a Robust Smart Card Based-Authentication Scheme for Multi-Server Architecture
    Dianli Guo
    Fengtong Wen
    [J]. Wireless Personal Communications, 2014, 78 : 475 - 490
  • [40] Analysis and Improvement of a Robust Smart Card Based-Authentication Scheme for Multi-Server Architecture
    Guo, Dianli
    Wen, Fengtong
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2014, 78 (01) : 475 - 490