The following information was submitted:
Transactions: WSEAS TRANSACTIONS ON COMPUTERS
Transactions ID Number: 32-819
Full Name: Wen-Bing Horng
Position: Associate Professor
Age: ON
Sex: Male
Address: 151 Ying-Chuna Road, Tamsui, Taipei 25137
Country: TAIWAN
Tel: +886-2-2621-5656 #2616
Tel prefix:
Fax: +886-2-2620-9749
E-mail address: horng@mail.tku.edu.tw
Other E-mails: wbhorng@cs.tku.edu.tw
Title of the Paper: Improvement of Hu-Yang-Niu's Remote Authentication Scheme Preserving User Anonymity
Authors as they appear in the Paper: Wen-Bing Horng, Cheng-Ping Lee, Jian-Wen Peng
Email addresses of all the authors: horng@mail.tku.edu.tw, 89419038@s94.tku.edu.tw, pchw8598@mail.chihlee.edu.tw
Number of paper pages: 10
Abstract: Anonymity is one of the important properties of remote authentication schemes to preserve user privacy. Besides, it can avoid unauthorized entities from using the user ID and other intercepted information to forge legal login messages. In 2004, Das et al. first proposed a remote user authentication scheme with smart cards using dynamic ID to protect user anonymity. Later, in 2005, Chien and Chen demonstrated that Das et al.'s scheme fails to preserve user anonymity and then presented a new scheme to remedy this problem. In 2007, Hu et al. pointed out that Chien-Chen's scheme cannot preserve user anonymity if the smart card is non-tamper resistant; i.e., the secret information stored in the smart card can be revealed. They then proposed an improved scheme to cope with this problem. In this paper, however, we will show that Hu et al.'s scheme still cannot preserve user anonymity under their assumption. In addition, their scheme is also vulnerable to the offline passw!
ord guessing attack. We then present an improvement to overcome these weaknesses, while preserving all the merits of their scheme.
Keywords: Anonymity, Cryptanalysis, Password guessing, Remote authentication, Smart card
EXTENSION of the file: .pdf
Special (Invited) Session:
Organizer of the Session:
How Did you learn about congress:
IP ADDRESS: 163.13.19.66