首页> 外文会议>International Conference on Computer, Communications, and Control Technology >Cryptanalysis of remote user authentication scheme with key agreement
【24h】

Cryptanalysis of remote user authentication scheme with key agreement

机译:密钥协议远程用户身份验证方案的密码分析

获取原文

摘要

Password authentication with smart card is one of the most convenient and effective two-factor authentication mechanisms for remote systems to assure one communicating party of the legitimacy of the corresponding party by acquisition of corroborative evidence. This technique has been widely deployed for various kinds of authentication applications, such as remote host login, online banking, e-commerce and e-health. Recently, Kumari et al. presented a dynamic-identity-based user authentication scheme with session key agreement. In this research, we illustrate that Kumari et al.'s scheme violates the purpose of dynamic-identity contrary to author's claim. We show that once the smart card of an arbitrary user is lost, messages of all registered users are at risk. Using information from an arbitrary smart card, an adversary can impersonate any user of the system.
机译:使用智能卡的密码认证是远程系统最方便和有效的双因素认证机制之一,以通过获取核制性证据来确保相应方的合法性缔约方。这种技术已广泛用于各种认证应用程序,例如远程主机登录,网上银行,电子商务和电子健康。最近,Kumari等。呈现了一种基于动态标识的用户身份验证方案,具有会话密钥协议。在这项研究中,我们说明了Kumari等人。的计划违反了与作者索赔相反的动态身份的目的。我们表明,一旦任意用户的智能卡丢失,所有注册用户的消息都存在风险。使用来自任意智能卡的信息,对手可以模拟系统的任何用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号