2005Unpublished venueRequires access

Security enhancement for two remote user authentication schemes

Peng Shuanghe, Han Zhen, Liu Jiqiang

Open publisher page 0 citations

Abstract

In 2002, Lee, Li, and Hwang proposed a hash-based password authentication scheme that is efficient and can be easily implemented. Recently Ku, Chen, and Lee demonstrated that Lee-Li-Hwang's hash-based password authentication scheme is vulnerable to the off line guessing attack, the denial of service attack, and the stolen verifier attack. In 2003, Chih-Wei Lin et al. proposed a security enhancement for optimal strong password authentication protocol. This paper, however, will demonstrate that Chih-Wei Lin's scheme is vulnerable to the denial of service attack. In this article, we shall propose improved schemes to these two remote user authentication schemes, which make them able to withstand denial of service attack and have about the same computational cost as originals.

About this research paper

What this paper is about

In 2002, Lee, Li, and Hwang proposed a hash-based password authentication scheme that is efficient and can be easily implemented. Recently Ku, Chen, and Lee demonstrated that Lee-Li-Hwang's hash-based password authentication scheme is vulnerable to the off line guessing attack, the denial of service attack, and the stolen verifier attack. In 2003, Chih-Wei Lin et al. proposed a security enhancement for optimal strong password authentication protocol. This paper, however, will demonstrate that Chih-Wei Lin's scheme is vulnerable to the denial of service attack. In this article, we shall propose improved schemes to these two remote user authentication schemes, which make them able to withstand denial of service attack and have about the same computational cost as originals.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

In 2002, Lee, Li, and Hwang proposed a hash-based password authentication scheme that is efficient and can be easily implemented. Recently Ku, Chen, and Lee demonstrated that Lee-Li-Hwang's hash-based password authentication scheme is vulnerable to the off line guessing attack, the denial of service attack, and the stolen verifier attack. In 2003, Chih-Wei Lin et al. proposed a security enhancement for optimal strong password authentication protocol. This paper, however, will demonstrate that Chih-Wei Lin's scheme is vulnerable to the denial of service attack. In this article, we shall propose improved schemes to these two remote user authentication schemes, which make them able to withstand denial of service attack and have about the same computational cost as originals.

Key concepts: Challenge–response authentication, Computer science, Denial-of-service attack, Computer security, Hash function, Password, Authentication protocol, Authentication (law)

Related papers

Back to paper searchBrowse research topicsOriginal source
Security enhancement for two remote user authentication schemes — Research Paper | ScholarLens