Weaknesses in a dynamic ID-based remote user authentication scheme for multi-server environment

  • Authors:
  • Debiao He;Yin Huang

  • Affiliations:
  • School of Mathematics and Statistics, Wuhan University, Wuhan 430072, China;Sumavision Technology Co. Ltd., Beijing 100085, China

  • Venue:
  • International Journal of Electronic Security and Digital Forensics
  • Year:
  • 2012

Quantified Score

Hi-index 0.00

Visualization

Abstract

Due to the widespread applications of internet services, the study of accessing the resources of multi-server environment has received considerable attention, and many schemes are proposed successively. Very recently, Hsiang et al. proposed a dynamic ID-based remote user authentication scheme for multi-server environment. They claimed their scheme can resist various attacks. However, in this paper, we will show that Hsiang et al.'s scheme is vulnerable to the impersonation attack, the password guessing attack, the masquerading user attack and the masquerading server attack. The analysis shows that Hsiang et al.'s scheme is insecure for practical application.