Secure Password-Based Remote User Authentication Scheme with Non-tamper Resistant Smart Cards - Data and Applications Security and Privacy XXVI Access content directly
Conference Papers Year : 2012

Secure Password-Based Remote User Authentication Scheme with Non-tamper Resistant Smart Cards

Ding Wang
  • Function : Author
  • PersonId : 1010029
Chun-Guang Ma
  • Function : Author
  • PersonId : 1010030

Abstract

In DBSec’11, Li et al. showed that Kim and Chung’s password-based remote user authentication scheme is vulnerable to various attacks if the smart card is non-tamper resistant. Consequently, an improved version was proposed and claimed that it is secure against smart card security breach attacks. In this paper, however, we will show that Li et al.’s scheme still cannot withstand offline password guessing attack under the non-tamper resistance assumption of the smart card. In addition, their scheme is also prone to denial of service attack and fails to provide user anonymity and forward secrecy. Therefore, a robust scheme with a brief analysis is presented to overcome the identified drawbacks.
Fichier principal
Vignette du fichier
978-3-642-31540-4_9_Chapter.pdf (87.7 Ko) Télécharger le fichier
Origin : Files produced by the author(s)

Dates and versions

hal-01534767 , version 1 (08-06-2017)

Licence

Attribution

Identifiers

Cite

Ding Wang, Chun-Guang Ma, Peng Wu. Secure Password-Based Remote User Authentication Scheme with Non-tamper Resistant Smart Cards. 26th Conference on Data and Applications Security and Privacy (DBSec), Jul 2012, Paris, France. pp.114-121, ⟨10.1007/978-3-642-31540-4_9⟩. ⟨hal-01534767⟩
139 View
139 Download

Altmetric

Share

Gmail Facebook X LinkedIn More