透過您的圖書館登入
IP:3.145.17.46
  • 期刊
  • OpenAccess

Weakness and Improvement of the Smart Card Based Remote User Authentication Scheme with Anonymity

並列摘要


Today, people benefit various services through networks. However, due to the open environment of communications, networks are vulnerable to variety of security risks. Remote access capability is one of the critical functions for network systems. The remote user authentication scheme provides the server a convenient way to authenticate users before they are allowed to access database and obtain services. The smart card is one of the most reliable and efficient tools for remote user authentication. In some scenarios, remote user authentication schemes even require mechanisms to preserve user anonymity. In 2012, Shin et al. proposed a smart card based remote user authentication scheme. Their scheme has merits of providing user anonymity, key agreement, freely updating password and mutual authentication. They also claimed that their scheme can provide resilience to potential attacks of smart card based authentication schemes. In this article, we show that their scheme has several defects such as it cannot resist the impersonation attack, denial-of-service attack, off-line guessing attack and stolen-verifier attack. Furthermore, their scheme also suffers from high hash computation overhead and validations steps redundancy. We propose an improved scheme to overcome the drawbacks. The improved scheme has the merits of dynamic identity, user anonymity, forward and backward secrecy, mutual authentication, and low computation overhead. Moreover, the scheme can resist the replay attack, off-line guessing attack, smart card loss attack, impersonation attack and insider attack.

被引用紀錄


Wang, T. Y. (2013). 基於類別代數的點對點本體資料庫 [doctoral dissertation, National Chung Cheng University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613534160
Huang, Z. E. (2013). 為Cadabia資料庫提供一個以Android為基礎的更人性化操作介面 [master's thesis, National Chung Cheng University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613550435
Teng, H. Y. (2013). 異質網路下點對點視訊串流之研究 [doctoral dissertation, National Chung Cheng University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613562727
Hsieh, C. H. (2014). 人工智慧個人助理之設計與實作 [doctoral dissertation, National Chung Cheng University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613585917
Chen, C. F. (2014). 以Meteor為基礎之Cadabia資料庫系統安全框架 [master's thesis, National Chung Cheng University]. Airiti Library. https://www.airitilibrary.com/Article/Detail?DocID=U0033-2110201613585593

延伸閱讀