Attacking and improving on lee and chiu’s authentication scheme using smart cards

  • Authors:
  • Youngsook Lee;Hyungkyu Yang;Dongho Won

  • Affiliations:
  • Department of Cyber Investigation Police, Howon University, Korea;Department of Computer and Media Information, Kangnam University, Korea;Department of Computer Engineering, Sungkyunkwan University, Korea

  • Venue:
  • ISPEC'10 Proceedings of the 6th international conference on Information Security Practice and Experience
  • Year:
  • 2010

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper discusses the security of Lee and Chiu’s remote user authentication scheme making use of smart cards. We first figure out that Lee and Chiu’s scheme does not achieve two-factor security. If an attacker steals some user’s smart card and extracts the information stored in the smart card, he/she can easily find out the user’s password. We show this by mounting an off-line dictionary attack on the scheme. In addition, we showed what really is causing the problem and how to fix it and proposed the scheme which improves on Lee and Chiu’s scheme.