Security Improvements on Smart-Card Based Mutual Authentication Scheme
Young-Do Joo
Abstract
Young-Do Joo
Abstract
Abstract Password-based authentication schemes have been widely adopted in order to protect resources from unauthorized access. In 2008, Liu et al. proposed a new mutual authentication scheme using smart cards which can withstand the forged attack. In this paper, author has proven that Liu et al.'s scheme is still vulnerable to the various attacks by analyzing the security of their scheme. This paper introduces an enhanced scheme to overcome these security weakness and to provide mutual authentication between the user and the server, even if the secrete information stored in the smart card is revealed by an attacker. The comparative result from the security analysis demonstrates that the proposed scheme is more secure against the possible attacks than Liu et al.'s scheme. Key Words : Mutual Authentication, Smart Card, User Impersonation Attack, Password Guessing Attack * 정회원, 강남대학교 컴퓨터미디어정보공학부접수일자 2012년 9월 18일, 수정일자 2012년 11월 8일게재확정일자 : 2012년 12월 14일Received: 27 September 2012 / Revised: 24 November 2012 /Accepted: 14 December 2012
OpenAlex reports 3 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Abstract Password-based authentication schemes have been widely adopted in order to protect resources from unauthorized access. In 2008, Liu et al. proposed a new mutual authentication scheme using smart cards which can withstand the forged attack. In this paper, author has proven that Liu et al.'s scheme is still vulnerable to the various attacks by analyzing the security of their scheme. This paper introduces an enhanced scheme to overcome these security weakness and to provide mutual authentication between the user and the server, even if the secrete information stored in the smart card is revealed by an attacker. The comparative result from the security analysis demonstrates that the proposed scheme is more secure against the possible attacks than Liu et al.'s scheme. Key Words : Mutual Authentication, Smart Card, User Impersonation Attack, Password Guessing Attack * 정회원, 강남대학교 컴퓨터미디어정보공학부접수일자 2012년 9월 18일, 수정일자 2012년 11월 8일게재확정일자 : 2012년 12월 14일Received: 27 September 2012 / Revised: 24 November 2012 /Accepted: 14 December 2012
Key concepts: Mutual authentication, Smart card, Scheme (mathematics), Computer science, Computer security, Authentication (law), Computer network, Mathematics