...
首页> 外文期刊>Information security journal:A global perspective >Secure Dynamic Identity-Based Authentication Scheme Using Smart Cards
【24h】

Secure Dynamic Identity-Based Authentication Scheme Using Smart Cards

机译:使用智能卡的基于动态身份的安全认证方案

获取原文
获取原文并翻译 | 示例
           

摘要

In 2004, Das et al. proposed a dynamic identity-based remote user authentication scheme using smart cards. This scheme allows users to choose and change their passwords freely, and the server does not maintain any verification table. Das et al. claimed that their scheme is secure against stolen verifier attack, replay attack, forgery attack, dictionary attack, insider attack and identity theft. However, many researchers have demonstrated that Das et al.'s scheme is susceptible to various attacks. Furthermore, this scheme does not achieve mutual authentication and thus cannot resist malicious server attack. In 2009, Wang et al. argued that Das et al.'s scheme is susceptible to stolen smart card attack. If an attacker obtains the smart card of the user and chooses any random password, the attacker gets through the authentication process to get access of the remote server. Therefore, Wang et al. suggested an improved scheme to preclude the weaknesses of Das et al.'s scheme. However, we found that Wang et al.'s scheme is susceptible to impersonation attack, stolen smart card attack, offline password guessing attack, denial of service attack and fails to preserve the user anonymity. This paper improves Wang et al.'s scheme to resolve the aforementioned problems, while keep ing the merits of different dynamic identity based smart card authentication schemes.
机译:2004年,Das等人。提出了一种使用智能卡的基于动态身份的远程用户身份验证方案。该方案允许用户自由选择和更改密码,并且服务器不维护任何验证表。 Das等。声称他们的方案可以安全地防止被盗的验证者攻击,重播攻击,伪造攻击,字典攻击,内部人员攻击和身份盗用。但是,许多研究人员证明,Das等人的方案容易受到各种攻击。此外,该方案无法实现相互认证,因此无法抵抗恶意服务器攻击。 2009年,Wang等。辩称,Das等人的方案很容易受到盗窃的智能卡攻击。如果攻击者获得了用户的智能卡并选择了任何随机密码,则攻击者将通过身份验证过程来访问远程服务器。因此,王等。提出了一种改进的方案,以消除Das等人方案的缺点。但是,我们发现Wang等人的方案容易受到模拟攻击,被盗的智能卡攻击,离线密码猜测攻击,拒绝服务攻击,并且无法保留用户匿名性。本文改进了Wang等人的方案以解决上述问题,同时保留了基于动态身份的不同智能卡身份验证方案的优点。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号