Improvement of Wang-Li's Forward-Secure User Authentication Scheme with Smart Cards

  • Authors:
  • Wen-Bing Horng;Cheng-Ping Lee

  • Affiliations:
  • -;-

  • Venue:
  • ISDA '08 Proceedings of the 2008 Eighth International Conference on Intelligent Systems Design and Applications - Volume 01
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

Smart card-based applications have been widely used in e-commerce for years. Therefore, many authentication schemes have been proposed to improve security over insecure networks. In 2006, Wang and Li pointed out that Yoon et al.'s remote user authentication scheme with smart cards does not provide the property of perfect forward secrecy; i.e., all previous session keys will be broken if the secret key of the remote server is compro卢mised. They then proposed a new remote user authentica卢tion scheme based on the Diffie-Hellman algorithm to provide session key exchange capability with the perfect forward secrecy property. However, in this paper, we will first show that their new scheme is vulnerable to the offline password guessing attack, the parallel session attack, the reflection attack, and the insider attack. Then, we will present an improvement to overcome these weaknesses, while preserving all their merits.