Design and analysis of USB-Key based strong password authentication scheme
Zhang Yong-fu
Abstract
Zhang Yong-fu
Abstract
Concerning that the OSPA protocol is vulnerable to the replay attack and the denial-of-service attack,in this paper,a USB-Key based strong password authentication scheme was proposed,which used USB-Key to verify the user's password and store the security parameter.In this scheme,user's identity can be protected by using the temporary identity and the authentication parameters computation by Hash function.This scheme can achieve mutual authentication between user and server by transferring the authentication parameters.The security analysis of the scheme proves that the scheme is resistant to replay attack,impersonation attack and Denial of Service(DoS) attack,and it has high security,and it can be used by users with limited computation ability.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Concerning that the OSPA protocol is vulnerable to the replay attack and the denial-of-service attack,in this paper,a USB-Key based strong password authentication scheme was proposed,which used USB-Key to verify the user's password and store the security parameter.In this scheme,user's identity can be protected by using the temporary identity and the authentication parameters computation by Hash function.This scheme can achieve mutual authentication between user and server by transferring the authentication parameters.The security analysis of the scheme proves that the scheme is resistant to replay attack,impersonation attack and Denial of Service(DoS) attack,and it has high security,and it can be used by users with limited computation ability.
Key concepts: Computer science, Replay attack, Challenge–response authentication, S/KEY, Password, One-time password, Computer security, Authentication protocol