首页> 外文会议>International conference on information computing and applications >On the Security of an Improved Password Authentication Scheme Based on ECC
【24h】

On the Security of an Improved Password Authentication Scheme Based on ECC

机译:一种改进的基于ECC的密码认证方案的安全性

获取原文
获取外文期刊封面目录资料

摘要

The design of secure remote user authentication schemes for mobile applications is still an open and quite challenging problem, though many schemes have been published lately. Recently, Islam and Biswas pointed out that Lin and Hwang et al.'s password-based authentication scheme is vulnerable to various attacks, and then presented an improved scheme based on elliptic curve cryptography (ECC) to overcome the drawbacks. Based on heuristic security analysis, Islam and Biswas claimed that their scheme is secure and can withstand all related attacks. In this paper, however, we show that Islam and Biswas's scheme cannot achieve the claimed security goals and report its flaws: (1) It is vulnerable to offline password guessing attack, stolen verifier attack and denial of service (DoS) attack; (2) It fails to preserve user anonymity. The cryptanalysis demonstrates that the scheme under study is unfit for practical use.
机译:尽管最近已经发布了许多方案,但用于移动应用程序的安全远程用户身份验证方案的设计仍然是一个开放且颇具挑战性的问题。最近,Islam和Biswas指出Lin和Hwang等人的基于密码的身份验证方案容易受到各种攻击,然后提出了一种基于椭圆曲线密码学(ECC)的改进方案来克服该缺点。根据启发式安全分析,Islam和Biswas声称他们的方案是安全的,并且可以抵御所有相关攻击。但是,在本文中,我们表明Islam and Biswas的方案无法实现所声称的安全目标并报告其缺陷:(1)容易受到脱机密码猜测攻击,验证者被盗和拒绝服务(DoS)攻击的攻击; (2)无法保留用户匿名。密码分析表明,所研究的方案不适合实际使用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号