2011Information Security and CryptologyRequires access

Design of Improved Strong Password Authentication Scheme to Secure on Replay Attack

Jun-Sub Kim, Jin Kwak

Open publisher page 1 citations

Abstract

ABSTRACT Password-based authentication is the protocol that two entities share a password in advance and use the password as the basic of authentication. Password authentication schemes are di vided into weak-password and strong-password authentication scheme. SPAS protocol, one of the strong-password authenticatio n scheme, was proposed for secure against DoS attack. However it has vulnerability of the replay attack. In this paper, we analyze the vulnerability to the replay attack in SPAS protocol. Then we also propose an Improved-Strong Password Auth entication Scheme (I-SPAS) with secure against the replay attack.Keywords: Password Authentication, Replay Attack, Hash Function, Securi ty I.서 론 사용자 인증은 네트워크를 통하여 컴퓨터에 접속하는 사용자의 정당성 여부를 검증하는 과정이다. 사용자를 인증하기 위한 방법으로는 패스워드를 기반으로 접수일(2011년 5월 25일), 수정일(2011년 8월 25일),게재확정일(2011년 11월 6일)†주저자, jskim0911@sch.ac.kr‡교신저자, jkwak@sch.ac.kr 하는 인증 기술이 널리 사용되고 있으나, 많은 사용자들은 상대적으로 낮은 엔트로피의 패스워드를 선택하여 사용하기 때문에 공격자에 의해 쉽게 추측될 수 있다. 이러한 프로토콜의 안전성을 강화하기 위해서 약한 패스워드 인증 프로토콜은 약한 패스워드를 암호화하기 위해 공개키 기술을 사용하여 여러 가지 공격에 저항할 수 있다. 반면 강한 패스워드 인증 프로토콜은 암호용 해시 함수와 XOR 연산 이후 높은 엔트로피를 가지는 강한 패스워드를 얻게 되기 때문에 패스워드를

About this research paper

What this paper is about

ABSTRACT Password-based authentication is the protocol that two entities share a password in advance and use the password as the basic of authentication. Password authentication schemes are di vided into weak-password and strong-password authentication scheme. SPAS protocol, one of the strong-password authenticatio n scheme, was proposed for secure against DoS attack. However it has vulnerability of the replay attack. In this paper, we analyze the vulnerability to the replay attack in SPAS protocol. Then we also propose an Improved-Strong Password Auth entication Scheme (I-SPAS) with secure against the replay attack.Keywords: Password Authentication, Replay Attack, Hash Function, Securi ty I.서 론 사용자 인증은 네트워크를 통하여 컴퓨터에 접속하는 사용자의 정당성 여부를 검증하는 과정이다. 사용자를 인증하기 위한 방법으로는 패스워드를 기반으로 접수일(2011년 5월 25일), 수정일(2011년 8월 25일),게재확정일(2011년 11월 6일)†주저자, jskim0911@sch.ac.kr‡교신저자, jkwak@sch.ac.kr 하는 인증 기술이 널리 사용되고 있으나, 많은 사용자들은 상대적으로 낮은 엔트로피의 패스워드를 선택하여 사용하기 때문에 공격자에 의해 쉽게 추측될 수 있다. 이러한 프로토콜의 안전성을 강화하기 위해서 약한 패스워드 인증 프로토콜은 약한 패스워드를 암호화하기 위해 공개키 기술을 사용하여 여러 가지 공격에 저항할 수 있다. 반면 강한 패스워드 인증 프로토콜은 암호용 해시 함수와 XOR 연산 이후 높은 엔트로피를 가지는 강한 패스워드를 얻게 되기 때문에 패스워드를

Why it matters

OpenAlex reports 1 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

ABSTRACT Password-based authentication is the protocol that two entities share a password in advance and use the password as the basic of authentication. Password authentication schemes are di vided into weak-password and strong-password authentication scheme. SPAS protocol, one of the strong-password authenticatio n scheme, was proposed for secure against DoS attack. However it has vulnerability of the replay attack. In this paper, we analyze the vulnerability to the replay attack in SPAS protocol. Then we also propose an Improved-Strong Password Auth entication Scheme (I-SPAS) with secure against the replay attack.Keywords: Password Authentication, Replay Attack, Hash Function, Securi ty I.서 론 사용자 인증은 네트워크를 통하여 컴퓨터에 접속하는 사용자의 정당성 여부를 검증하는 과정이다. 사용자를 인증하기 위한 방법으로는 패스워드를 기반으로 접수일(2011년 5월 25일), 수정일(2011년 8월 25일),게재확정일(2011년 11월 6일)†주저자, jskim0911@sch.ac.kr‡교신저자, jkwak@sch.ac.kr 하는 인증 기술이 널리 사용되고 있으나, 많은 사용자들은 상대적으로 낮은 엔트로피의 패스워드를 선택하여 사용하기 때문에 공격자에 의해 쉽게 추측될 수 있다. 이러한 프로토콜의 안전성을 강화하기 위해서 약한 패스워드 인증 프로토콜은 약한 패스워드를 암호화하기 위해 공개키 기술을 사용하여 여러 가지 공격에 저항할 수 있다. 반면 강한 패스워드 인증 프로토콜은 암호용 해시 함수와 XOR 연산 이후 높은 엔트로피를 가지는 강한 패스워드를 얻게 되기 때문에 패스워드를

Key concepts: Password, S/KEY, Challenge–response authentication, Computer science, One-time password, Zero-knowledge password proof, Replay attack, Password strength

Related papers

Back to paper searchBrowse research topicsOriginal source
Design of Improved Strong Password Authentication Scheme to Secure on Replay Attack — Research Paper | ScholarLens