skip to main content
10.1145/1754288.1754303acmotherconferencesArticle/Chapter ViewAbstractPublication PagescomputeConference Proceedingsconference-collections
research-article

An improvement of Xu et al.'s authentication scheme using smart cards

Published:22 January 2010Publication History

ABSTRACT

In 2009, Xu et al. found that Lee et al.'s [3] scheme is vulnerable to offline password guessing attack. Xu et al. also demonstrated that Lee and Chiu's [4] scheme is vulnerable to forgery attack. Furthermore, Lee and Chiu's scheme does not achieve mutual authentication and thus can not resist malicious server attack. Therefore, Xu et al. proposed an improved scheme that inherits the merits of Lee et al.'s and Lee and Chiu's schemes and resists different possible attacks. However, we found that Xu et al.'s scheme is vulnerable to forgery attack. This paper presents an improved scheme to resolve the aforementioned problem, while keeping the merits of Xu et al.'s scheme.

References

  1. C. L. Hsu, "Security of Chien et al.'s Remote User Authentication Scheme using Smart Cards," Computer Standards & Interfacéés, vol. 26, no. 3, pp. 167--169, July 2004.Google ScholarGoogle ScholarCross RefCross Ref
  2. H. Y. Chien, J. K. Jan and Y. M. Tseng, "An Efficient and Practical Solution to Remote Authentication: Smart Card," Computers & Security, vol. 21, no. 4, pp. 372--375, August 2002.Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. S. W. Lee, H. S. Kim and K. Y. Yoo, "Improvement of Chien et al.'s Remote User Authentication Scheme using Smart Cards," Computer Standards & Interfaces, vol. 27, no. 2, pp. 181--183, January 2005.Google ScholarGoogle ScholarCross RefCross Ref
  4. N. Y. Lee and Y. C. Chiu, "Improved Remote Authentication Scheme with Smart Card," Computer Standards & Interfaces, vol. 27, no. 2, pp. 177--180, January 2005.Google ScholarGoogle ScholarCross RefCross Ref
  5. S. T. Wu and B. C. Chieu, "A User Friendly Remote Authentication Scheme with Smart Cards," Computer & Security, vol. 22, no. 6, pp. 547--550, September 2003.Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. I. E. Liao, C. C. Lee and M. S. Hwang, "A Password Authentication Scheme over Insecure Networks," Journal of Computer and System Sciences, vol. 72, no. 4, pp. 727--740, June 2006. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. G. Yang, D. S. Wong, H. Wang and X. Deng, "Two-factor Mutual Authentication based on Smart Cards and Passwords," Journal of Computer and System Sciences, vol. 74, no. 7, pp. 1160--1172, November 2008. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. J. Xu, W. T. Zhu and D. G. Feng, "An Improved Smart Card based Password Authentication Scheme with Provable Security," Computer Standards & Interfaces, vol. 31, no. 4, pp. 723--728, June 2009. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. P. Kocher, J. Jaffe and B. Jun, "Differential Power Analysis," Proc. CRYPTO 99, Springer-Verlag, pp. 388--397, August 1999. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. T. S. Messerges, E. A. Dabbish and R. H. Sloan, "Examining Smart-Card Security under the Threat of Power Analysis Attacks," IEEE Transactions on Computers, vol. 51, no. 5, pp. 541--552, May 2002. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. An improvement of Xu et al.'s authentication scheme using smart cards

          Recommendations

          Reviews

          Zheng Gong

          Password authentication based on smart cards is widely accepted in electronic transactions. Xu et al.'s cryptanalysis scheme [1] improves upon the schemes of Lee et al. [2] and Lee and Chiu [3], which are actually insecure for offline guessing attacks. Sood, Sarje, and Singh propose in this paper an improved scheme to resolve the problem of guessing attacks, while keeping the merits of Xu et al.'s scheme. The proposed scheme is based on the Diffie-Hellman computation. The security analysis shows the proposed scheme is secure against various types of attacks, such as malicious user attacks, offline dictionary attacks, and denial-of-services (DOS) attacks. The computational costs of the proposed scheme are also competitive. The paper is a good reference for researchers and engineers who work in the field. Online Computing Reviews Service

          Access critical reviews of Computing literature here

          Become a reviewer for Computing Reviews.

          Comments

          Login options

          Check if you have access through your login credentials or your institution to get full access on this article.

          Sign in
          • Published in

            cover image ACM Other conferences
            COMPUTE '10: Proceedings of the Third Annual ACM Bangalore Conference
            January 2010
            171 pages
            ISBN:9781450300018
            DOI:10.1145/1754288

            Copyright © 2010 ACM

            Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

            Publisher

            Association for Computing Machinery

            New York, NY, United States

            Publication History

            • Published: 22 January 2010

            Permissions

            Request permissions about this article.

            Request Permissions

            Check for updates

            Qualifiers

            • research-article

            Acceptance Rates

            Overall Acceptance Rate114of622submissions,18%

          PDF Format

          View or Download as a PDF file.

          PDF

          eReader

          View online with eReader.

          eReader