首页> 外文会议>International Conference on Applications and Innovations in Mobile Computing >A robust remote user authentication scheme resistant to known session specific temporary information attack
【24h】

A robust remote user authentication scheme resistant to known session specific temporary information attack

机译:强大的远程用户身份验证方案,可抵抗已知的特定于会话的临时信息攻击

获取原文

摘要

Rapid growth of mobile and networking technologies, resulted in new paradigms of networking like Internet of Things (IoT) etc, which allows user to connect to insecure public communication channel through various devices and can access the services and data provided by remote server. Thus, remote user authentication and key agreement for wireless, wired, IoT communications becoming more challenging task. In this context many researchers have proposed authentication schemes. In 2013, An et al. proposed a dynamic ID-based remote user authentication scheme which is secure, even if the secret values stored in the smart card is revealed. In 2014, Troung et al claimed that An et al scheme is vulnerable to server forgery attack and proposed an improved scheme. In this manuscript, we validate that Troung et al's scheme is vulnerable to known session specific temporary information attack, replay and impersonation attack. Furthermore, we also propose the improved scheme to overcome these limitations without increase in the cost front.
机译:移动和网络技术的快速发展催生了新的联网模式,如物联网(IoT)等,它使用户可以通过各种设备连接到不安全的公共通信渠道,并可以访问远程服务器提供的服务和数据。因此,用于无线,有线,IoT通讯的远程用户身份验证和密钥协议成为更具挑战性的任务。在这种情况下,许多研究人员提出了认证方案。 2013年,An等人。提出了一种动态的基于ID的远程用户身份验证方案,即使泄露了存储在智能卡中的秘密值,该方案也是安全的。 Troung等人在2014年声称An等人的方案容易受到服务器伪造攻击,并提出了一种改进的方案。在此手稿中,我们验证了Troung等人的方案容易受到已知会话特定的临时信息攻击,重播和模仿攻击的攻击。此外,我们还提出了一种改进的方案来克服这些限制,而又不会增加成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号