Cryptanalysis and improvement of user authentication scheme using smart cards for multi-server environments

Zhen Fu Cao, Da Zhi Sun

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

For providing the login service in multi-server environments, Fan, Xu, and Li presented a remote user authentication scheme using smart cards. In this paper, we demonstrate that Fan-Xu-Li's scheme is vulnerable to the parallel session attack. That is, when a legal user logs in a server, an adversary without knowing any secret information can easily impersonate the user to log in other authorized servers. It means that a serious security flaw exists in Fan-Xu-Li's scheme. In addition to being practical, it is desirable to avoid relying on timestamps for security in their scheme. We therefore propose an improved scheme to overcome above disadvantages. As a unilateral authentication mechanism, our improved scheme is more suitable for real-life cryptographic applications than Fan-Xu-Li's scheme.

Original languageEnglish
Title of host publicationProceedings of the 2006 International Conference on Machine Learning and Cybernetics
Pages2818-2822
Number of pages5
DOIs
StatePublished - 2006
Externally publishedYes
Event2006 International Conference on Machine Learning and Cybernetics - Dalian, China
Duration: 13 Aug 200616 Aug 2006

Publication series

NameProceedings of the 2006 International Conference on Machine Learning and Cybernetics
Volume2006

Conference

Conference2006 International Conference on Machine Learning and Cybernetics
Country/TerritoryChina
CityDalian
Period13/08/0616/08/06

Keywords

  • Authentication
  • Multi-server
  • Parallel session attack
  • Smart card
  • Synchronization

Fingerprint

Dive into the research topics of 'Cryptanalysis and improvement of user authentication scheme using smart cards for multi-server environments'. Together they form a unique fingerprint.

Cite this