Journal of University of Chinese Academy of Sciences >
Cryptanalysis of a Remote Password Authentication Scheme
Received date: 2002-06-03
Online published: 2002-05-18
This paper analyzes the security of Tan's scheme for remote password authentication based on cross-product. We point out that to impersonate one user's log-in reguest, the intruders need only to know the user's two log-in requests, or need only to know one log-in request after booking a smart card and getting some useful information from it, so the scheme is not secure. Some modifications to Tan's scheme for avoiding the above two kinds of possible attacks are given.
Key words: remote password authentication; smart card; time stamp; Hash function
FANG Gen-Xi , DAI Zong-Duo , YANG Jun-Hui . Cryptanalysis of a Remote Password Authentication Scheme[J]. Journal of University of Chinese Academy of Sciences, 2002 , 19(3) : 229 -232 . DOI: 10.7523/j.issn.2095-6134.2002.3.002
1. Evans A, Kantrowitz W. A User Authentication Scheme not Requiring Secrecy in the Computer. Comet ACM, 1974, 17(8):437^-442
2. Lennon K E, Matyas S M. Cryptographic Authentication of Time-invariant Quantities. IEEE Trans Comet, 1981,24(11):773一777
3. l,amport L. Password Authentication with Insecure Communication. Comet ACM, 1981,24(11):770-773
4. CHANG C C, WU T C. Remote Y}ssword Authentication with Smart Cards. iEE Proc E, 1991,138(3):165 } 168
5. CHANCE C C, Laih l' S. Correspondence for Remote Password Authentication with Smart Cards. IEE Proc E, 1992, 139(4):372一375
6. CHANC: C C, Hwang S J. Using Smart Cards to Authenticate Remote asswords. Comput Math Applic, 1993, 26(7):19一27
7. 潭凯军,何晨,诸鸿文.基于矢积的远程Cl令鉴别方案.电子学报,2000,28(2):28-30
/
| 〈 |
|
〉 |