首页> 外文会议>International Conference on Information and Network Security >Cryptanalysis and improvement of a smart card-based identity authentication scheme
【24h】

Cryptanalysis and improvement of a smart card-based identity authentication scheme

机译:密码分析和基于智能卡的身份认证方案的改进

获取原文

摘要

Remote user authentication scheme has been widely adopted in the cyberworld to provide security and privacy because of various online threats and insecure communications. In the past few decades, many smart card-based authentication schemes are put forward. In such schemes, a user only need to maintain an identity and a password and employ a smart card to fulfill the authentication with a remote server. In 2014, Lee et al. put forward an authentication scheme using smart based on the hash function. However, we find that novel as it is, the scheme still has some severe security and performance weaknesses such as a verification table should stored in their scheme, it is easy to suffer the stolen verifier attack. Besides, it has the problem of synchronization between the server and users, failure of protecting users' anonymity and it is unfriendly to users since the inability of supporting changing the password freely. In this paper, we propose an improved authentication scheme supporting the Diffie-Hellman key exchange protocol using hash functions and the ElGamal cryptosystem. Besides the drawbacks in Lee et al.'s scheme, our proposed scheme overcomes the offline password guessing attack, man-in-the-middle attack and so on. At last, we show that our scheme is more suitable and secure for practical use.
机译:由于各种在线威胁和不安全的通信,远程用户身份验证方案已在网络世界中广泛采用,以提供安全性和隐私性。在过去的几十年中,提出了许多基于智能卡的身份验证方案。在这样的方案中,用户只需要维护身份和密码,并使用智能卡来实现与远程服务器的身份验证。在2014年,Lee等人。提出了基于智能的基于哈希函数的认证方案。但是,我们发现该方案虽然很新颖,但仍然存在一些严重的安全性和性能弱点,例如应在其方案中存储一个验证表,很容易遭受被盗的验证者攻击。此外,它还具有服务器与用户之间的同步问题,无法保护用户的匿名性,并且由于无法支持自由更改密码而对用户不友好。在本文中,我们提出了一种改进的认证方案,该方案支持使用哈希函数和ElGamal密码系统的Diffie-Hellman密钥交换协议。除了Lee等人的方案的缺点外,我们提出的方案还克服了离线密码猜测攻击,中间人攻击等问题。最后,我们证明了该方案对于实际使用更加合适和安全。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号