A New Dynamic ID-based User Authentication Scheme to Resist Smart-Card-Theft Attack

被引:0
|
作者
Lee, Yung-Cheng [1 ]
机构
[1] WuFeng Univ, Dept Secur Technol & Management, Chiayi 62153, Taiwan
来源
关键词
Password Authentication; Dynamic ID; Smart-Card-Theft Attack; PASSWORD AUTHENTICATION; REMOTE; EFFICIENT;
D O I
暂无
中图分类号
O29 [应用数学];
学科分类号
070104 ;
摘要
Password-based remote authentication schemes provide users with convenient and secure mechanisms to access resources through networks. Such schemes can be further divided into static ID and dynamic ID schemes. The main drawback of the static ID scheme is that an adversary can intercept the fixed login ID and masquerade as a legal user to log into the system. On the other hand, dynamic ID schemes can eliminate the risk of ID-theft and protect user's privacy. In 2004, Das et al. proposed a dynamic ID-based remote user authentication scheme. Their scheme allows users to select and update their passwords freely, and the server does not need to maintain a verifier table. In this paper, we first demonstrate that their scheme is not secure. We then propose an improved scheme for security enhancement. This improved scheme has a dynamic advantage such that an adversary cannot trace the users. Because the smart card generates a different random number for each authentication session, the forward messages are always different for each login. This causes the guessing attacks to fail, because the adversary has not enough information to verify his/her guess. Further, the adversary cannot successfully guess the correct password even if he/she obtains the smart card. Therefore, the proposed scheme can withstand smart-card-theft attack.
引用
收藏
页码:355S / 361S
页数:7
相关论文
共 50 条
  • [21] An enhanced smart card and dynamic ID based remote multi-server user authentication scheme
    Nitish Andola
    Sourabh Prakash
    Raghav Gahlot
    S. Venkatesan
    Shekhar Verma
    Cluster Computing, 2022, 25 : 3699 - 3717
  • [22] A more efficient and secure dynamic ID-based remote user authentication scheme
    Wang, Yan-yan
    Liu, Jia-yong
    Xiao, Feng-xia
    Dan, Jing
    COMPUTER COMMUNICATIONS, 2009, 32 (04) : 583 - 585
  • [23] Two-Factor Dynamic ID-Based Remote User Authentication Scheme
    Huang, Renjun
    Su, Fengfu
    Chen, Yangyi
    PROCEEDINGS OF 2010 CROSS-STRAIT CONFERENCE ON INFORMATION SCIENCE AND TECHNOLOGY, 2010, : 373 - 377
  • [24] Improved security enhancement for a dynamic ID-based remote user authentication scheme
    School of Electronics and Information Engineering, Beijing University of Aeronautics and Astronautics, Beijing 100083, China
    Beijing Hangkong Hangtian Daxue Xuebao, 2007, 5 (565-567+621):
  • [25] Cryptanalysis of a dynamic ID-based remote user authentication?with key agreement scheme
    Tang, Hong-bin
    Liu, Xin-song
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2012, 25 (12) : 1639 - 1644
  • [26] An enhanced smart card and dynamic ID based remote multi-server user authentication scheme
    Andola, Nitish
    Prakash, Sourabh
    Gahlot, Raghav
    Venkatesan, S.
    Verma, Shekhar
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2022, 25 (05): : 3699 - 3717
  • [27] An Improved Dynamic ID-Based Remote User Authentication with Key Agreement Scheme
    Qu, Juan
    Zou, Li-Min
    JOURNAL OF ELECTRICAL AND COMPUTER ENGINEERING, 2013, 2013
  • [28] On the Security of an Efficient and Secure Dynamic ID-Based Remote User Authentication Scheme
    Yoon, Eun-Jun
    Yoo, Kee-Young
    IEICE TRANSACTIONS ON INFORMATION AND SYSTEMS, 2012, E95D (06) : 1684 - 1686
  • [29] Weaknesses of an efficient and secure dynamic ID-based remote user authentication scheme
    Martinez-Pelaez, Rafael
    Rico-Novella, Francisco
    2012 IBEROAMERICAN CONFERENCE ON ELECTRONICS ENGINEERING AND COMPUTER SCIENCE, 2012, 3 : 351 - 353
  • [30] Efficient and secure dynamic ID-based remote user authentication scheme for distributed systems using smart cards
    Leu, Jenq-Shiou
    Hsieh, Wen-Bin
    IET INFORMATION SECURITY, 2014, 8 (02) : 104 - 113