首页> 外文会议>International Conference on Ubiquitous Information Management and Communication >Cryptanalysis and Improvement of User Authentication Scheme Based on Rabin Cryptosystem
【24h】

Cryptanalysis and Improvement of User Authentication Scheme Based on Rabin Cryptosystem

机译:基于Rabin密码系统的密码分析和用户认证方案的改进

获取原文

摘要

With the emergence of various methods for user authentication, smartcards have appeared as a convenient method of authentication based on possession factor. Besides, Rabin Cryptosystem has the same security strength is seen in using factoring problems such as RSA. In 2016, Ranjan et al. introduced Rabin Cryptosystem based user authentication scheme. Rabin Cryptosystem calculates only square modulo in encryption, it is more efficient than the RSA. Furthermore, they insisted their scheme provides resistance of replay attack and denial of service attack, and mutual authentication. However, unfortunately, we discover that there are some vulnerabilities in Ranjan et al.’s scheme that might cause serious problems. In this paer, we briefly review a Ranjan et al.’s scheme and reveal the possibility of attacks to consider in the user authentication scheme like offline password guessing, user/server impersonation attacks. Also, their scheme does not support a user anonymity and a session key agreement process. Next, we describe our Rabin Cryptosystem based user authentication improvement; then, we demonstrate our proposed scheme shows more secure compared to Ranjan et al.’s scheme and more suitable to the real environment.
机译:随着各种用户身份验证方法的出现,智能卡已成为一种基于占有因子的便捷身份验证方法。此外,在使用诸如RSA之类的分解问题时,可以看到Rabin Cryptosystem具有相同的安全强度。在2016年,Ranjan等人。引入了基于Rabin Cryptosystem的用户身份验证方案。 Rabin Cryptosystem在加密中仅计算平方模,比RSA效率更高。此外,他们坚持认为自己的方案可以抵抗重放攻击和拒绝服务攻击,以及相互认证。但是,不幸的是,我们发现Ranjan等人的方案中存在一些漏洞,可能会引起严重的问题。在本文中,我们简要回顾了Ranjan等人的方案,并揭示了在用户身份验证方案中考虑攻击的可能性,例如离线密码猜测,用户/服务器模拟攻击。而且,他们的方案不支持用户匿名和会话密钥协商过程。接下来,我们描述基于Rabin密码系统的用户身份验证改进;然后,我们证明了我们提出的方案比Ranjan等人的方案更安全,并且更适合实际环境。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号