Breaking a Robust Remote User Authentication Scheme Using Smart Cards

Abstract : Understanding security failures of cryptographic protocols is the key to both patching existing protocols and designing future schemes. Recently, Yeh et al. showed that Hsiang and Shih’s password-based remote user authentication scheme is vulnerable to various attacks if the smart card is non-tamper resistant, and proposed an improved version which was claimed to be efficient and secure. In this study, however, we find that, although Yeh et al.’s scheme possesses many attractive features, it still cannot achieve the claimed security goals, and we report its following flaws: (1) It cannot withstand offline password guessing attack and key-compromise impersonation attack under their non-tamper resistance assumption of the smart card; (2) It fails to provide user anonymity and forward secrecy; (3) It has some other minor defects. The proposed cryptanalysis discourages any use of the scheme under investigation in practice. Remarkably, rationales for the security analysis of password-based authentication schemes using smart cards are discussed in detail.
Type de document :
Communication dans un congrès
James J. Park; Albert Zomaya; Sang-Soo Yeo; Sartaj Sahni. 9th International Conference on Network and Parallel Computing (NPC), Sep 2012, Gwangju, South Korea. Springer, Lecture Notes in Computer Science, LNCS-7513, pp.110-118, 2012, Network and Parallel Computing. 〈10.1007/978-3-642-35606-3_13〉
Liste complète des métadonnées

Littérature citée [20 références]  Voir  Masquer  Télécharger

https://hal.inria.fr/hal-01551357
Contributeur : Hal Ifip <>
Soumis le : vendredi 30 juin 2017 - 10:36:07
Dernière modification le : vendredi 1 décembre 2017 - 01:09:57
Document(s) archivé(s) le : lundi 22 janvier 2018 - 21:03:28

Fichier

978-3-642-35606-3_13_Chapter.p...
Fichiers produits par l'(les) auteur(s)

Licence


Distributed under a Creative Commons Paternité 4.0 International License

Identifiants

Citation

Ding Wang, Chun-Guang Ma, Sen-Dong Zhao, Chang-Li Zhou. Breaking a Robust Remote User Authentication Scheme Using Smart Cards. James J. Park; Albert Zomaya; Sang-Soo Yeo; Sartaj Sahni. 9th International Conference on Network and Parallel Computing (NPC), Sep 2012, Gwangju, South Korea. Springer, Lecture Notes in Computer Science, LNCS-7513, pp.110-118, 2012, Network and Parallel Computing. 〈10.1007/978-3-642-35606-3_13〉. 〈hal-01551357〉

Partager

Métriques

Consultations de la notice

55

Téléchargements de fichiers

12