Improvement of the secure dynamic ID based remote user authentication scheme for multi-server environment

被引:227
作者
Hsiang, Han-Cheng [1 ,2 ]
Shih, Wei-Kuan [1 ]
机构
[1] Natl Tsing Hua Univ, Dept Comp Sci, Hsinchu 300, Taiwan
[2] Vanung Univ Sci & Technol, Dept Informat Management, Chungli 320, Taiwan
关键词
Authentication; Dynamic ID; Multi-server; Mutual authentication; Password; Smart card; IDENTIFICATION; ANONYMITY;
D O I
10.1016/j.csi.2008.11.002
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recently, Liao and Wang proposed a secure dynamic ID based remote user authentication scheme for multiserver environment, and claimed that their scheme was intended to provide mutual authentication, two-factor security, replay attack, server spoofing attack, insider and stolen verifier attack, forward secrecy and user anonymity. In this paper, we show that Liao and Wang's scheme is still vulnerable to insider's attack, masquerade attack, server spoofing attack, registration center spoofing attack and is not reparable. Furthermore, it fails to provide mutual authentication. To remedy these flaws, this paper proposes an efficient improvement over Liao-Wang's scheme with more security. The computation cost, security, and efficiency of the improved scheme are well suited to the practical applications environment. (C) 2008 Elsevier B.V. All rights reserved.
引用
收藏
页码:1118 / 1123
页数:6
相关论文
共 24 条
[1]   An enhanced remote user authentication scheme using smart cards [J].
Awasthi, AK ;
Lal, S .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) :583-586
[2]  
Chang C, 2004, IEEE P INT C CYB
[3]  
Chang CC, 2003, INFORMATICA-LITHUAN, V14, P289
[4]  
Cheng-Chi Lee, 2002, Operating Systems Review, V36, P46, DOI 10.1145/567331.567335
[5]   A dynamic ID-based remote user authentication scheme [J].
Das, ML ;
Saxena, A ;
Gulati, VP .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) :629-631
[6]   A simple remote user authentication scheme [J].
Hwang, MS ;
Lee, CC ;
Tang, YL .
MATHEMATICAL AND COMPUTER MODELLING, 2002, 36 (1-2) :103-107
[7]  
Hwang Tzonelih, 1990, IEEE TENCON'90: 1990 IEEE Region 10 Conference on Computer and Communication Systems (Cat. No.90CH2866-2), P429, DOI 10.1109/TENCON.1990.152647
[8]  
HWANG T, 1995, IEEE T COMMUN, V43, P1947
[9]   Efficient multi-server password authenticated key agreement using smart cards [J].
Juang, WS .
IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (01) :251-255
[10]   Impersonation attack on a dynamic ID-based remote user authentication scheme using smart cards [J].
Ku, WC ;
Chang, ST .
IEICE TRANSACTIONS ON COMMUNICATIONS, 2005, E88B (05) :2165-2167