Cryptanalysis and improvement on remote user mutual authentication scheme with smart cards

  • Authors:
  • Razi Arshad;Nassar Ikram

  • Affiliations:
  • National University of Sciences and Technology, Pakistan;National University of Sciences and Technology, Pakistan

  • Venue:
  • ICACT'09 Proceedings of the 11th international conference on Advanced Communication Technology - Volume 2
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Password-based authentication schemes are the most widely used techniques for remote user authentication. Recently, Khan proposed an improvement to Wu-Chieu scheme to prevent the server spoofing attack and to allow the users to update their passwords freely and securely. In this paper, we do a cryptanalysis of khan's scheme and show that his scheme is vulnerable to the parallel session attack. Furthermore, his scheme is also susceptible to the impersonation attack and the guessing attack provided that the information stored in the smart card is disclosed by an adversary. We also propose a novel and secure remote user mutual authentication scheme which is immune to the presented attacks.