首页> 外文会议>International Conference on Web Information Systems and Mining >Comments on an Advanced Dynamic ID-Based Authentication Scheme for Cloud Computing
【24h】

Comments on an Advanced Dynamic ID-Based Authentication Scheme for Cloud Computing

机译:关于云计算的高级动态ID身份验证方案的评论

获取原文

摘要

The design of secure remote user authentication schemes for mobile devices in Cloud Computing is still an open and quite challenging problem, though many such schemes have been published lately. Recently, Chen et al. pointed out that Yang and Chang's ID-based authentication scheme based on elliptic curve cryptography (ECC) is vulnerable to various attacks, and then presented an improved password based authentication scheme using ECC to overcome the drawbacks. Based on heuristic security analysis, Chen et al. claimed that their scheme is more secure and can withstand all related attacks. In this paper, however, we show that Chen et al.'s scheme cannot achieve the claimed security goals and report its flaws: (1) It is vulnerable to offline password guessing attack; (2) It fails to preserve user anonymity; (3) It is prone to key compromise impersonation attack; (4) It suffers from the clock synchronization problem. The cryptanalysis demonstrates that the scheme under study is unfit for practical use in Cloud Computing environment.
机译:云计算中的移动设备的安全远程用户身份验证方案的设计仍然是一个开放性的问题,尽管最近发布了许多这样的方案。最近,陈等人。指出,基于椭圆曲线加密(ECC)的阳和Chai的基于ID的身份验证方案容易受到各种攻击,然后使用ECC呈现改进的基于密码的认证方案来克服缺点。基于启发式安全分析,陈等人。声称他们的计划更加安全,可以承受所有相关的攻击。然而,在本文中,我们展示了Chen等人。的计划无法实现所要求的安全目标,并报告其缺陷:(1)它很容易偏离密码猜测攻击; (2)它未能保留用户匿名; (3)易于关键损害冒充攻击; (4)它遭受了时钟同步问题。密码分析表明,在云计算环境中的实际应用方面的研究方案是不合适的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号