Security enhancement of a remote user authentication scheme using smart cards

  • Authors:
  • Youngsook Lee;Junghyun Nam;Dongho Won

  • Affiliations:
  • Information Security Group, Sungkyunkwan University, Korea;Information Security Group, Sungkyunkwan University, Korea;Information Security Group, Sungkyunkwan University, Korea

  • Venue:
  • OTM'06 Proceedings of the 2006 international conference on On the Move to Meaningful Internet Systems: AWeSOMe, CAMS, COMINF, IS, KSinBIT, MIOS-CIAO, MONET - Volume Part I
  • Year:
  • 2006

Quantified Score

Hi-index 0.00

Visualization

Abstract

Designing cryptographic protocols well suited for today's distributed large networks poses great challenges in terms of cost, performance, user convenience, functionality, and above all security As has been pointed out for many years, even designing a two-party authentication scheme is extremely error-prone This paper discusses the security of Lee et al.'s remote user authentication scheme making use of smart cards Lee et al.'s scheme was proposed to solve the security problem with Chien et al.'s authentication scheme and was claimed to provide mutual authentication between the server and the remote user However, we demonstrate that Lee et al.'s scheme only achieves unilateral authentication — only the server can authenticate the remote user, but not vice versa In addition, we recommend changes to the scheme that fix the security vulnerability.