Cryptanalysis of a flexible remote user authentication scheme using smart cards

  • Authors:
  • Wei-Chi Ku;Shuai-Min Chen

  • Affiliations:
  • Fu Jen Catholic University, Hsinchuang, Taipei County, Taiwan, R.O.C.;Fu Jen Catholic University, Hsinchuang, Taipei County, Taiwan, R.O.C.

  • Venue:
  • ACM SIGOPS Operating Systems Review
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

In 2002, Lee, Hwang, and Yang proposed a verifier-free remote user authentication scheme using smart cards. Their scheme is efficient because of mainly using cryptographic hash functions. However, we find that Lee-Hwang-Yang's scheme is not reparable once the user's permanent secret is compromised and is vulnerable to a privileged insider's attack. Furthermore, it lacks the user eviction mechanism. In this paper, we first show the weaknesses of Lee-Hwang-Yang's scheme, and then compare Lee-Hwang-Yang's scheme with three similar schemes.