Cryptanalysis and Improvement of An 'Efficient Remote Mutual Authentication and Key Agreement'

被引:0
作者
Wang, Jian [1 ]
Wang, Haihang [1 ]
Tan, Chengxiang [1 ]
机构
[1] Tongji Univ, Coll Elect & Informat Engn, Shanghai 201804, Peoples R China
来源
2008 IEEE ASIA-PACIFIC SERVICES COMPUTING CONFERENCE, VOLS 1-3, PROCEEDINGS | 2008年
关键词
Mutual authentication; Key agreement; Smart card; Password;
D O I
10.1109/APSCC.2008.173
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
A smart card based scheme is practical and widely used in remote mutual authentication. In 2006, Shieh-Wang pointed out the weakness of Juang's remote mutual authentication scheme using smart card and further proposed a novel one to improve Juang's. The advantages in Shieh-Wang:v scheme include effective mutual authentication freely chosen password no verification tables low compulational cost session key agreement and no synchronized clocks. However in 2007 Yoon-Yoo showed Mat Shieh-Wang's scheme does not provide perfect forward secrecy, and is vulnerable to a privileged insider's attack Furthermore, the current paper demonstrates that Shieh-Wang's scheme is also vulnerable to the parallel session attack and lack of wrong password detection and Men presents a more efficient and secure scheme to resolve all the above problems including those that, Yoon-Yoo has pointed out with less computational cost increase.
引用
收藏
页码:835 / 840
页数:6
相关论文
共 12 条
[1]  
[Anonymous], ACM OPER SYST REV
[2]   An efficient and practical solution to remote authentication: Smart card [J].
Chien, HY ;
Jan, JK ;
Tseng, YM .
COMPUTERS & SECURITY, 2002, 21 (04) :372-375
[3]  
Hsu CL, 2004, COMP STAND INTER, V26, P167, DOI [10.1016/S0920-5489(03)00094-1, 10.1016/s0920-5489(03)00094-1]
[4]   A new remote user authentication scheme using smart cards [J].
Hwang, MS ;
Li, LH .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2000, 46 (01) :28-30
[5]   Efficient password authenticated key agreement using smart cards [J].
Juang, WS .
COMPUTERS & SECURITY, 2004, 23 (02) :167-173
[6]   Chaotic hash-based fingerprint biometric remote user authentication scheme on mobile devices [J].
Khan, Muhammad Khurram ;
Zhang, Jiashu ;
Wang, Xiaomin .
CHAOS SOLITONS & FRACTALS, 2008, 35 (03) :519-524
[7]   PASSWORD AUTHENTICATION WITH INSECURE COMMUNICATION [J].
LAMPORT, L .
COMMUNICATIONS OF THE ACM, 1981, 24 (11) :770-772
[8]   SMART CARDS PROVIDE VERY HIGH SECURITY AND FLEXIBILITY IN SUBSCRIBERS MANAGEMENT [J].
PEYRET, P ;
LISIMAQUE, G ;
CHUA, TY .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 1990, 36 (03) :744-752
[9]   Efficient remote mutual authentication and key agreement [J].
Shieh, WG ;
Wang, FM .
COMPUTERS & SECURITY, 2006, 25 (01) :72-77
[10]  
WANG XM, 2000, IEEE P ICEIS 06 ISL, P140