Cryptanalysis and improvement of a smart card-based identity authentication scheme

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

1 Scopus citations

Abstract

Remote user authentication scheme has been widely adopted in the cyberworld to provide security and privacy because of various online threats and insecure communications. In the past few decades, many smart card-based authentication schemes are put forward. In such schemes, a user only need to maintain an identity and a password and employ a smart card to fulfill the authentication with a remote server. In 2014, Lee et al. put forward an authentication scheme using smart based on the hash function. However, we find that novel as it is, the scheme still has some severe security and performance weaknesses such as a verification table should stored in their scheme, it is easy to suffer the stolen verifier attack. Besides, it has the problem of synchronization between the server and users, failure of protecting users' anonymity and it is unfriendly to users since the inability of supporting changing the password freely. In this paper, we propose an improved authentication scheme supporting the Diffie-Hellman key exchange protocol using hash functions and the ElGamal cryptosystem. Besides the drawbacks in Lee et al.'s scheme, our proposed scheme overcomes the offline password guessing attack, man-in-the-middle attack and so on. At last, we show that our scheme is more suitable and secure for practical use.

Original languageEnglish
Title of host publicationIET Conference Publications
PublisherInstitution of Engineering and Technology
EditionCP657
ISBN (Print)9781849199094
DOIs
StatePublished - 2014
Event2014 International Conference on Information and Network Security, ICINS 2014 - Beijing, China
Duration: 14 Nov 201416 Nov 2014

Publication series

NameIET Conference Publications
NumberCP657
Volume2014

Conference

Conference2014 International Conference on Information and Network Security, ICINS 2014
Country/TerritoryChina
CityBeijing
Period14/11/1416/11/14

Keywords

  • Anonymity
  • Authentication
  • Privacy
  • Security
  • Smart card

Fingerprint

Dive into the research topics of 'Cryptanalysis and improvement of a smart card-based identity authentication scheme'. Together they form a unique fingerprint.

Cite this