Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards

Saved in:
Bibliographic Details
Title: Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards
Authors: Hsiang, Han-Cheng1,2, Shih, Wei-Kuan1 shc@rtlab.cs.nthu.edu.tw
Source: Computer Communications. Mar2009, Vol. 32 Issue 4, p649-652. 4p.
Subjects: RADIUS (Computer network protocol), Smart cards, Software verification, Computer passwords, Hashing, Cryptography, Computer network security, Internet protocols, Keystroke timing authentication
Abstract: Abstract: Remote user authentication scheme is a procedure which allows a server to authenticate a remote user through insecure channel. Recently, Yoon, Ryu and Yoo made an enhancement based on Ku–Chen’s remote user authentication scheme by using smart cards. The scheme has the merits of providing mutual authentication, no verification table, freely choosing password, involving only few hashing operations and parallel session attack resistance. In this paper, we point out security flaws of Yoon–Ryu–Yoo’s protocols against masquerading attack, off-line password guessing attacks and parallel session attack. An improvement to enhance Yoon–Ryu–Yoo’s security scheme is proposed. [Copyright &y& Elsevier]
Copyright of Computer Communications is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 36477765
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Hsiang%2C+Han-Cheng%22">Hsiang, Han-Cheng</searchLink><relatesTo>1,2</relatesTo><br /><searchLink fieldCode="AR" term="%22Shih%2C+Wei-Kuan%22">Shih, Wei-Kuan</searchLink><relatesTo>1</relatesTo><i> shc@rtlab.cs.nthu.edu.tw</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Computer+Communications%22">Computer Communications</searchLink>. Mar2009, Vol. 32 Issue 4, p649-652. 4p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22RADIUS+%28Computer+network+protocol%29%22">RADIUS (Computer network protocol)</searchLink><br /><searchLink fieldCode="DE" term="%22Smart+cards%22">Smart cards</searchLink><br /><searchLink fieldCode="DE" term="%22Software+verification%22">Software verification</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+passwords%22">Computer passwords</searchLink><br /><searchLink fieldCode="DE" term="%22Hashing%22">Hashing</searchLink><br /><searchLink fieldCode="DE" term="%22Cryptography%22">Cryptography</searchLink><br /><searchLink fieldCode="DE" term="%22Computer+network+security%22">Computer network security</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+protocols%22">Internet protocols</searchLink><br /><searchLink fieldCode="DE" term="%22Keystroke+timing+authentication%22">Keystroke timing authentication</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Abstract: Remote user authentication scheme is a procedure which allows a server to authenticate a remote user through insecure channel. Recently, Yoon, Ryu and Yoo made an enhancement based on Ku–Chen’s remote user authentication scheme by using smart cards. The scheme has the merits of providing mutual authentication, no verification table, freely choosing password, involving only few hashing operations and parallel session attack resistance. In this paper, we point out security flaws of Yoon–Ryu–Yoo’s protocols against masquerading attack, off-line password guessing attacks and parallel session attack. An improvement to enhance Yoon–Ryu–Yoo’s security scheme is proposed. [Copyright &y& Elsevier]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Computer Communications is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=36477765
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1016/j.comcom.2008.11.019
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 4
        StartPage: 649
    Subjects:
      – SubjectFull: RADIUS (Computer network protocol)
        Type: general
      – SubjectFull: Smart cards
        Type: general
      – SubjectFull: Software verification
        Type: general
      – SubjectFull: Computer passwords
        Type: general
      – SubjectFull: Hashing
        Type: general
      – SubjectFull: Cryptography
        Type: general
      – SubjectFull: Computer network security
        Type: general
      – SubjectFull: Internet protocols
        Type: general
      – SubjectFull: Keystroke timing authentication
        Type: general
    Titles:
      – TitleFull: Weaknesses and improvements of the Yoon–Ryu–Yoo remote user authentication scheme using smart cards
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Hsiang, Han-Cheng
      – PersonEntity:
          Name:
            NameFull: Shih, Wei-Kuan
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 04
              M: 03
              Text: Mar2009
              Type: published
              Y: 2009
          Identifiers:
            – Type: issn-print
              Value: 01403664
          Numbering:
            – Type: volume
              Value: 32
            – Type: issue
              Value: 4
          Titles:
            – TitleFull: Computer Communications
              Type: main
ResultId 1