On the security of a smartcard-based authentication system for multiserver environments
Xianping Mao, Jing Zhao, Xuefeng Li, Huanyu Ma, Xiaochuan Wu, Qiushan Liu
Abstract
Xianping Mao, Jing Zhao, Xuefeng Li, Huanyu Ma, Xiaochuan Wu, Qiushan Liu
Abstract
Password-based authentication and key agreement protocols for multiserver environments have drawn much attention due to their simplicity and efficiency. Very recently, Amin et al. introduced a password-based authentication and key agreement protocol using smart cards. We review this protocol and point out that it has some security drawbacks. This protocol cannot resist replay attack, server masquerading attack, user impersonation attack and session key computation attack. Besides, this protocol does not provide user anonymity.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Password-based authentication and key agreement protocols for multiserver environments have drawn much attention due to their simplicity and efficiency. Very recently, Amin et al. introduced a password-based authentication and key agreement protocol using smart cards. We review this protocol and point out that it has some security drawbacks. This protocol cannot resist replay attack, server masquerading attack, user impersonation attack and session key computation attack. Besides, this protocol does not provide user anonymity.
Key concepts: Computer science, Authentication protocol, Computer security, Password, Replay attack, Challenge–response authentication, Reflection attack, Smart card