More secure remote user authentication scheme

Saved in:
Bibliographic Details
Title: More secure remote user authentication scheme
Authors: Kim, Sang-Kyun1 goldmunt@mju.ac.kr, Chung, Min Gyo2 mchung@swu.ac.kr
Source: Computer Communications. Apr2009, Vol. 32 Issue 6, p1018-1021. 4p.
Subjects: Keystroke timing authentication, RADIUS (Computer network protocol), Computer network security, Computer passwords, Masqueraders (Computer users), Databases
Abstract: Abstract: Recently, Yoon and Yoo proposed a remote user authentication scheme which is an improvement on Lee–Kim–Yoo’s method. However, we find out that Yoon–Yoo’s scheme easily reveals a user’s password and is vulnerable to both masquerading user attack and masquerading server attack. Yoon–Yoo’s scheme is also exposed to stolen verifier attack, because it has to maintain a user database in a remote server. This paper proposes a new remote user authentication scheme that resolves all aforementioned problems, while keeping the merits of Yoon–Yoo’s scheme. [Copyright &y& Elsevier]
Copyright of Computer Communications is the property of Elsevier B.V. and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Description
Abstract:Abstract: Recently, Yoon and Yoo proposed a remote user authentication scheme which is an improvement on Lee–Kim–Yoo’s method. However, we find out that Yoon–Yoo’s scheme easily reveals a user’s password and is vulnerable to both masquerading user attack and masquerading server attack. Yoon–Yoo’s scheme is also exposed to stolen verifier attack, because it has to maintain a user database in a remote server. This paper proposes a new remote user authentication scheme that resolves all aforementioned problems, while keeping the merits of Yoon–Yoo’s scheme. [Copyright &y& Elsevier]
ISSN:01403664
DOI:10.1016/j.comcom.2008.11.026