Offline Password Guessing Attacks on Smart-Card-Based Remote User Authentication Schemes

Author(s):  
Xue-lei Li ◽  
Qiao-yan Wen ◽  
Hua Zhang ◽  
Zheng-ping Jin ◽  
Wen-min Li
2014 ◽  
Vol 543-547 ◽  
pp. 3343-3347
Author(s):  
Xue Lei Li ◽  
Qiao Yan Wen ◽  
Wen Min Li ◽  
Hua Zhang ◽  
Zheng Ping Jin

In this paper, we analyze and point out several weaknesses in the dynamic ID-based remote user authentication schemes using smart card for multi-server environments, and present the countermeasures to enhance the security of the schemes. Taking Li et al.'s scheme for instance, we demonstrate that their scheme does not provide forward secrecy and key privacy for the session keys, and cannot resist offline password guessing attack. Furthermore, the reasons of these security weaknesses are analyzed through extending the attacks to its predecessors. Finally, the improved ideas of local verification and authenticated Diffie-Hellman key agreement are presented to overcome the weaknesses mentioned above.


2012 ◽  
Vol 38 ◽  
pp. 1318-1326 ◽  
Author(s):  
G. Jaspher ◽  
W. Kathrine ◽  
E. Kirubakaran ◽  
Parul Prakash

Password and Smart card are the authentication factors to access significant information from remote servers. Authentication schemes based on RSA which are studied intensively that are utilized in most of the telecare medical systems. Latest RSA based remote beneficiary validation scheme which does not resist against certain attacks, not satisfy functional properties and consume more computations. The existing previous schemes still have less functional strengths. However, these schemes cannot be efficient by means of performance which is measured in terms of computation and communication. The improvised scheme using smart card and hash functions remove security short comings and reduce the communication, computational cost. We compare the proposed scheme with the other current schemes, our scheme has less computational, communication cost, security attacks than other schemes and prove that it efficient one.


Sign in / Sign up

Export Citation Format

Share Document