Mutual password authentication scheme with key distribution
Sheng Yu
Abstract
Sheng Yu
Abstract
The protocols for strong authentication and key exchange are studied in asymmetric scenarios where the authentication server possesses a pair of private and public keys while the client has a weak human-memorizable password.Wang's password authentication scheme is analyzed in this scenario, and the results show that it is vulnerable to many attacks.A new scheme is proposed for remote user authentication, password change and session key establishment over insecure networks.According to security analysis, the proposal is resistant to known attacks and the most secure scheme among Hwang-Yeh's, Peyravian-Zunic's, Peyravian-Jeffries's, Wang's and mine authentication key.Several simple password protocols are analyzed in this scenario, and the results show that under the choice of suitable public key encryption functions the security of these protocols can be formally proven based on stanlord cryptographic assumptions.In particular, our analysis shows optimal resistance to off line password guessing attacks.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The protocols for strong authentication and key exchange are studied in asymmetric scenarios where the authentication server possesses a pair of private and public keys while the client has a weak human-memorizable password.Wang's password authentication scheme is analyzed in this scenario, and the results show that it is vulnerable to many attacks.A new scheme is proposed for remote user authentication, password change and session key establishment over insecure networks.According to security analysis, the proposal is resistant to known attacks and the most secure scheme among Hwang-Yeh's, Peyravian-Zunic's, Peyravian-Jeffries's, Wang's and mine authentication key.Several simple password protocols are analyzed in this scenario, and the results show that under the choice of suitable public key encryption functions the security of these protocols can be formally proven based on stanlord cryptographic assumptions.In particular, our analysis shows optimal resistance to off line password guessing attacks.
Key concepts: S/KEY, Computer science, Challenge–response authentication, Password, One-time password, Zero-knowledge password proof, Computer security, Password policy