2017•Proceedings of the 3rd International Conference on Communication and Information ProcessingRequires access

On the security of a smartcard-based authentication system for multiserver environments

Xianping Mao, Jing Zhao, Xuefeng Li, Huanyu Ma, Xiaochuan Wu, Qiushan Liu

Open publisher page 0 citations

Abstract

Password-based authentication and key agreement protocols for multiserver environments have drawn much attention due to their simplicity and efficiency. Very recently, Amin et al. introduced a password-based authentication and key agreement protocol using smart cards. We review this protocol and point out that it has some security drawbacks. This protocol cannot resist replay attack, server masquerading attack, user impersonation attack and session key computation attack. Besides, this protocol does not provide user anonymity.

About this research paper

What this paper is about

Password-based authentication and key agreement protocols for multiserver environments have drawn much attention due to their simplicity and efficiency. Very recently, Amin et al. introduced a password-based authentication and key agreement protocol using smart cards. We review this protocol and point out that it has some security drawbacks. This protocol cannot resist replay attack, server masquerading attack, user impersonation attack and session key computation attack. Besides, this protocol does not provide user anonymity.

Why it matters

A significance statement is not available in the OpenAlex record.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Password-based authentication and key agreement protocols for multiserver environments have drawn much attention due to their simplicity and efficiency. Very recently, Amin et al. introduced a password-based authentication and key agreement protocol using smart cards. We review this protocol and point out that it has some security drawbacks. This protocol cannot resist replay attack, server masquerading attack, user impersonation attack and session key computation attack. Besides, this protocol does not provide user anonymity.

Key concepts: Computer science, Authentication protocol, Computer security, Password, Replay attack, Challenge–response authentication, Reflection attack, Smart card

Related papers

Back to paper searchBrowse research topicsOriginal source
On the security of a smartcard-based authentication system for multiserver environments — Research Paper | ScholarLens