2009Jisuanji gongcheng yu shejiRequires access

Mutual password authentication scheme with key distribution

Sheng Yu

Open publisher page 0 citations

Abstract

The protocols for strong authentication and key exchange are studied in asymmetric scenarios where the authentication server possesses a pair of private and public keys while the client has a weak human-memorizable password.Wang's password authentication scheme is analyzed in this scenario, and the results show that it is vulnerable to many attacks.A new scheme is proposed for remote user authentication, password change and session key establishment over insecure networks.According to security analysis, the proposal is resistant to known attacks and the most secure scheme among Hwang-Yeh's, Peyravian-Zunic's, Peyravian-Jeffries's, Wang's and mine authentication key.Several simple password protocols are analyzed in this scenario, and the results show that under the choice of suitable public key encryption functions the security of these protocols can be formally proven based on stanlord cryptographic assumptions.In particular, our analysis shows optimal resistance to off line password guessing attacks.

About this research paper

What this paper is about

The protocols for strong authentication and key exchange are studied in asymmetric scenarios where the authentication server possesses a pair of private and public keys while the client has a weak human-memorizable password.Wang's password authentication scheme is analyzed in this scenario, and the results show that it is vulnerable to many attacks.A new scheme is proposed for remote user authentication, password change and session key establishment over insecure networks.According to security analysis, the proposal is resistant to known attacks and the most secure scheme among Hwang-Yeh's, Peyravian-Zunic's, Peyravian-Jeffries's, Wang's and mine authentication key.Several simple password protocols are analyzed in this scenario, and the results show that under the choice of suitable public key encryption functions the security of these protocols can be formally proven based on stanlord cryptographic assumptions.In particular, our analysis shows optimal resistance to off line password guessing attacks.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

The protocols for strong authentication and key exchange are studied in asymmetric scenarios where the authentication server possesses a pair of private and public keys while the client has a weak human-memorizable password.Wang's password authentication scheme is analyzed in this scenario, and the results show that it is vulnerable to many attacks.A new scheme is proposed for remote user authentication, password change and session key establishment over insecure networks.According to security analysis, the proposal is resistant to known attacks and the most secure scheme among Hwang-Yeh's, Peyravian-Zunic's, Peyravian-Jeffries's, Wang's and mine authentication key.Several simple password protocols are analyzed in this scenario, and the results show that under the choice of suitable public key encryption functions the security of these protocols can be formally proven based on stanlord cryptographic assumptions.In particular, our analysis shows optimal resistance to off line password guessing attacks.

Key concepts: S/KEY, Computer science, Challenge–response authentication, Password, One-time password, Zero-knowledge password proof, Computer security, Password policy

Related papers

Back to paper searchBrowse research topicsOriginal source
Mutual password authentication scheme with key distribution — Research Paper | ScholarLens