An Improved User Authentication and Key Agreement Scheme Providing User Anonymity

被引:2
作者
Ya-Fen Chang and Pei-Yu Chang Department of Computer Science and Information Engineering
National Taichung Institute of Technology
机构
关键词
Authentication; key agreement; smart card; user anonymity;
D O I
暂无
中图分类号
TP393.08 [];
学科分类号
0839 ; 1402 ;
摘要
When accessing remote services over public networks, a user authentication mechanism is required because these activities are executed in an insecure communication environment. Recently, Wang et al. proposed an authentication and key agreement scheme preserving the privacy of secret keys and providing user anonymity. Later, Chang et al. indicated that their scheme suffers from two security flaws. First, it cannot resist DoS (denial-of-service) attack because the indicators for the next session are not consistent. Second, the user password may be modified by a malicious attacker because no authentication mechanism is applied before the user password is updated. To eliminate the security flaws and preserve the advantages of Wang et al.'s scheme, we propose an improvement in this paper.
引用
收藏
页码:352 / 358
页数:7
相关论文
共 2 条
[1]   PASSWORD AUTHENTICATION WITHOUT USING A PASSWORD TABLE [J].
HORNG, GB .
INFORMATION PROCESSING LETTERS, 1995, 55 (05) :247-250
[2]   PASSWORD AUTHENTICATION WITH INSECURE COMMUNICATION [J].
LAMPORT, L .
COMMUNICATIONS OF THE ACM, 1981, 24 (11) :770-772