Cryptanalysis and improvement of a DoS-resistant ID-based password authentication scheme without using smart card

  • Authors:
  • Wenbo Shi;Debiao He;Shuhua Wu

  • Affiliations:
  • Department of Electronic Engineering, Northeastern University at Qinhuangdao, Qinhuangdao, 066004, China;School of Mathematics and Statistics, Wuhan University, Wuhan, 430072, China;Department of Networks Engineering, Information Science and Technology Institute, Zhengzhou, 450002, China

  • Venue:
  • International Journal of Information and Communication Technology
  • Year:
  • 2014

Quantified Score

Hi-index 0.00

Visualization

Abstract

An authentication scheme allows the user and the server to authenticate each other and establish a session key for future communication in an open network. Very recently, Wen et al. proposed a DoS-resistant ID-based password authentication scheme without using smart card. They claimed that their scheme could overcome various attacks. However, in this paper, we will point out that Wen et al.'s scheme is vulnerable to an impersonation attack and a privileged insider attack. To overcome weaknesses, we also propose an improved scheme. The analysis shows our scheme not only overcomes weaknesses in Wen et al.'s scheme but also has better performance. Then our scheme is more suitable for practical applications.