首页> 外文会议>International Conference on Computer, Communications, and Control Technology >Cryptanalysis of remote user authentication scheme with key agreement
【24h】

Cryptanalysis of remote user authentication scheme with key agreement

机译:具有密钥协商的远程用户认证方案的密码分析

获取原文

摘要

Password authentication with smart card is one of the most convenient and effective two-factor authentication mechanisms for remote systems to assure one communicating party of the legitimacy of the corresponding party by acquisition of corroborative evidence. This technique has been widely deployed for various kinds of authentication applications, such as remote host login, online banking, e-commerce and e-health. Recently, Kumari et al. presented a dynamic-identity-based user authentication scheme with session key agreement. In this research, we illustrate that Kumari et al.'s scheme violates the purpose of dynamic-identity contrary to author's claim. We show that once the smart card of an arbitrary user is lost, messages of all registered users are at risk. Using information from an arbitrary smart card, an adversary can impersonate any user of the system.
机译:使用智能卡进行密码身份验证是远程系统最便捷,最有效的两因素身份验证机制之一,以通过获取确证证据来确保一个通信方相应方的合法性。该技术已广泛用于各种身份验证应用程序,例如远程主机登录,在线银行,电子商务和电子医疗。最近,Kumari等。提出了一种具有会话密钥协商的基于动态身份的用户身份验证方案。在这项研究中,我们说明了Kumari等人的方案违反了动态同一性的目的,与作者的主张相反。我们表明,一旦任意用户的智能卡丢失,所有注册用户的消息都将受到威胁。攻击者可以使用来自任意智能卡的信息来冒充系统的任何用户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号