Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards
Saved in:
| Title: | Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards |
|---|---|
| Authors: | Hsiang, Han-Cheng1,2, Shih, Wei-Kuan1 shc@rtlab.cs.nthu.edu.tw |
| Source: | Computer Communications. Mar2009, Vol. 32 Issue 4, p649-652. 4p. |
| Subjects: | RADIUS (Computer network protocol), Smart cards, Software verification, Computer passwords, Hashing, Cryptography, Computer network security, Internet protocols, Keystroke timing authentication |
| Abstract: | Abstract: Remote user authentication scheme is a procedure which allows a server to authenticate a remote user through insecure channel. Recently, Yoon, Ryu and Yoo made an enhancement based on Ku–Chen’s remote user authentication scheme by using smart cards. The scheme has the merits of providing mutual authentication, no verification table, freely choosing password, involving only few hashing operations and parallel session attack resistance. In this paper, we point out security flaws of Yoon–Ryu–Yoo’s protocols against masquerading attack, off-line password guessing attacks and parallel session attack. An improvement to enhance Yoon–Ryu–Yoo’s security scheme is proposed. [Copyright &y& Elsevier] |
| Copyright of Computer Communications is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 36477765 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Hsiang%2C+Han-Cheng%22">Hsiang, Han-Cheng</searchLink><relatesTo>1,2</relatesTo><br /><searchLink fieldCode="AR" term="%22Shih%2C+Wei-Kuan%22">Shih, Wei-Kuan</searchLink><relatesTo>1</relatesTo><i> shc@rtlab.cs.nthu.edu.tw</i> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Computer+Communications%22">Computer Communications</searchLink>. Mar2009, Vol. 32 Issue 4, p649-652. 4p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22RADIUS+%28Computer+network+protocol%29%22">RADIUS (Computer network protocol)</searchLink><br /><searchLink fieldCode="DE" term="%22Smart+cards%22">Smart cards</searchLink><br /><searchLink fieldCode="DE" term="%22Software+verification%22">Software verification</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+passwords%22">Computer passwords</searchLink><br /><searchLink fieldCode="DE" term="%22Hashing%22">Hashing</searchLink><br /><searchLink fieldCode="DE" term="%22Cryptography%22">Cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+security%22">Computer network security</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+protocols%22">Internet protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Keystroke+timing+authentication%22">Keystroke timing authentication</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Abstract: Remote user authentication scheme is a procedure which allows a server to authenticate a remote user through insecure channel. Recently, Yoon, Ryu and Yoo made an enhancement based on Ku–Chen’s remote user authentication scheme by using smart cards. The scheme has the merits of providing mutual authentication, no verification table, freely choosing password, involving only few hashing operations and parallel session attack resistance. In this paper, we point out security flaws of Yoon–Ryu–Yoo’s protocols against masquerading attack, off-line password guessing attacks and parallel session attack. An improvement to enhance Yoon–Ryu–Yoo’s security scheme is proposed. [Copyright &y& Elsevier] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Computer Communications is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=36477765 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1016/j.comcom.2008.11.019 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 4 StartPage: 649 Subjects: – SubjectFull: RADIUS (Computer network protocol) Type: general – SubjectFull: Smart cards Type: general – SubjectFull: Software verification Type: general – SubjectFull: Computer passwords Type: general – SubjectFull: Hashing Type: general – SubjectFull: Cryptography Type: general – SubjectFull: Computer network security Type: general – SubjectFull: Internet protocols Type: general – SubjectFull: Keystroke timing authentication Type: general Titles: – TitleFull: Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Hsiang, Han-Cheng – PersonEntity: Name: NameFull: Shih, Wei-Kuan IsPartOfRelationships: – BibEntity: Dates: – D: 04 M: 03 Text: Mar2009 Type: published Y: 2009 Identifiers: – Type: issn-print Value: 01403664 Numbering: – Type: volume Value: 32 – Type: issue Value: 4 Titles: – TitleFull: Computer Communications Type: main |
| ResultId | 1 |