@article{ART001417392},
author={Youngsook Lee and WON, DONGHO},
title={Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2010},
volume={15},
number={1},
pages={139-147}
TY - JOUR
AU - Youngsook Lee
AU - WON, DONGHO
TI - Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards
JO - Journal of The Korea Society of Computer and Information
PY - 2010
VL - 15
IS - 1
PB - The Korean Society Of Computer And Information
SP - 139
EP - 147
SN - 1598-849X
AB - A remote user authentication scheme is a two-party protocol whereby an authentication server in a distributed system confirms the identity of a remote individual logging on to the server over an untrusted, open network. In 2005, Liao et al. proposed a remote user authentication scheme using a smart card, in which users can be authenticated anonymously. Recently, Yoon et al. have discovered some security flaws in Liao et al.’s authentication scheme and proposed an improved version of this scheme to fix the security flaws. In this article, we review the improved authentication scheme by Yoon et al. and provide a security analysis on the scheme. Our analysis shows that Yoon et al.’s scheme does not guarantee not only any kind of authentication, either server-to-user authentication or user-to-server authentication but also password security. The contribution of the current work is to demonstrate these by mounting two attacks, a server impersonation attack and a user impersonation attack, and an off-line dictionary attack on Yoon et al.’s scheme. In addition, we propose the enhanced authentication scheme that eliminates the security vulnerabilities of Yoon et al.’s scheme.
KW - Authentication scheme; User anonymity; Impersonation attack; Off-line dictionary attack
DO -
UR -
ER -
Youngsook Lee and WON, DONGHO. (2010). Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards. Journal of The Korea Society of Computer and Information, 15(1), 139-147.
Youngsook Lee and WON, DONGHO. 2010, "Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards", Journal of The Korea Society of Computer and Information, vol.15, no.1 pp.139-147.
Youngsook Lee, WON, DONGHO "Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards" Journal of The Korea Society of Computer and Information 15.1 pp.139-147 (2010) : 139.
Youngsook Lee, WON, DONGHO. Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards. 2010; 15(1), 139-147.
Youngsook Lee and WON, DONGHO. "Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards" Journal of The Korea Society of Computer and Information 15, no.1 (2010) : 139-147.
Youngsook Lee; WON, DONGHO. Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards. Journal of The Korea Society of Computer and Information, 15(1), 139-147.
Youngsook Lee; WON, DONGHO. Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards. Journal of The Korea Society of Computer and Information. 2010; 15(1) 139-147.
Youngsook Lee, WON, DONGHO. Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards. 2010; 15(1), 139-147.
Youngsook Lee and WON, DONGHO. "Cryptanalysis and Enhancement of a Remote User Authentication Scheme Using Smart Cards" Journal of The Korea Society of Computer and Information 15, no.1 (2010) : 139-147.