Short Communication: Cryptanalysis of a mutual authentication scheme based on nonce and smart cards

  • Authors:
  • Da-Zhi Sun;Jin-Peng Huai;Ji-Zhou Sun;Jian-Xin Li

  • Affiliations:
  • School of Computer Science and Technology, Tianjin University, No. 92 Weijin Road, Nankai District, Tianjin 300072, PR China and School of Computer, Beihang University, Beijing 100083, PR China;School of Computer, Beihang University, Beijing 100083, PR China;School of Computer Science and Technology, Tianjin University, No. 92 Weijin Road, Nankai District, Tianjin 300072, PR China;School of Computer, Beihang University, Beijing 100083, PR China

  • Venue:
  • Computer Communications
  • Year:
  • 2009

Quantified Score

Hi-index 0.24

Visualization

Abstract

To prevent the forged login attacks, Liu et al. recently proposed a new mutual authentication scheme using smart cards. However, we demonstrate that the attacker without any secret information can successfully not only impersonate any user to cheat the server but also impersonate the server to cheat any user. That is, Liu et al.'s scheme fails to defend the forged login attack as the previous version. Our cryptanalysis result is important for security engineers, who are responsible for the design and development of smart card-based user authentication systems.