Security of two remote user authentication schemes using smart cards

被引:14
作者
Hsu, CL [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Informat Management, Taipei 106, Taiwan
关键词
authentication; smart card; parallel session attack; password guessing attack;
D O I
10.1109/TCE.2003.1261216
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
In 2000, Sun proposed an efficient remote user authentication scheme using smart cards (published in IEEE Transactions on Consumer Electronics, Vol. 46, No. 4, 2000). Recently, Chien et al. pointed out that Sun's scheme only achieve the That is, only the authentication server can authenticate the legitimacy of the remote user while the user cannot authenticate that of the server. Chien et al. further proposed a new efficient and practical solution to achieve the mutual user authentication (published in Computers & Security, Vol. 21, No. 4, 2002). This paper, however, will demonstrate that Sun's scheme is vulnerable to the off-line and the on-line password guessing attacks and Chien et al.'s scheme is vulnerable to the parallel session attack.
引用
收藏
页码:1196 / 1198
页数:3
相关论文
共 12 条
[1]  
[Anonymous], ACM OPER SYST REV
[2]   An efficient and practical solution to remote authentication: Smart card [J].
Chien, HY ;
Jan, JK ;
Tseng, YM .
COMPUTERS & SECURITY, 2002, 21 (04) :372-375
[3]  
Diffie W., 1992, Designs, Codes and Cryptography, V2, P107, DOI 10.1007/BF00124891
[4]  
FELDMEIER DC, 1989, LECT NOTES COMPUTER, P44
[5]  
Gong L., 1990, Proceedings IEEE INFOCOM '90. The Conference on Computer Communications. Ninth Annual Joint Conference of the IEEE Computer and Communication Societies. The Multiple Facets of Integration (Cat. No.90CH2826-5), P686, DOI 10.1109/INFCOM.1990.91310
[6]   A new remote user authentication scheme using smart cards [J].
Hwang, MS ;
Li, LH .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2000, 46 (01) :28-30
[7]   Efficient and secure password-based authentication protocols against guessing attacks [J].
Kwon, T ;
Song, J .
COMPUTER COMMUNICATIONS, 1998, 21 (09) :853-861
[8]   PASSWORD AUTHENTICATION WITH INSECURE COMMUNICATION [J].
LAMPORT, L .
COMMUNICATIONS OF THE ACM, 1981, 24 (11) :770-772
[9]  
Lomas M., 1989, ACM OPERATING SYSTEM, V23, P14
[10]  
*NAT I STAND TECHN, 1993, NIST FIPS PUB, V180