...
首页> 外文期刊>International journal of communication systems >A lightweight password-based authentication protocol using smart card
【24h】

A lightweight password-based authentication protocol using smart card

机译:使用智能卡的轻量级基于密码的身份验证协议

获取原文
获取原文并翻译 | 示例

摘要

With its simplicity and feasibility, password-based remote user authentication becomes a popular way to control remote access to network. These years, numerous password-based authentication schemes have been proposed. Recently, Maitra et al proposed a smart card-based scheme which claims to be resistant to various attacks. Unfortunately, we found some important flaws in this scheme. Therefore, in this paper, we will demonstrate that the scheme of Maitra et al is not secure enough as claimed: neither resisting against off-line password guessing attack and insider attack nor preserve forward secrecy. To overcome those flaws, we put forward an improved new scheme which not only is resistant to all known attacks but also provides many attractive attributes, such as user revocation and re-register. Also, we compared the scheme with other related schemes, the result proved the superiority of our scheme. Particularly, we show a new way (beyond the conventional Deffie-Hellman approach) to achieve forward secrecy. Furthermore, we put some efforts into exploring the design principle of authentication schemes.
机译:由于其简单性和可行性,基于密码的远程用户身份验证已成为控制远程访问网络的一种流行方法。这些年来,已经提出了许多基于密码的认证方案。最近,Maitra等人提出了一种基于智能卡的方案,该方案声称能够抵抗各种攻击。不幸的是,我们发现了该方案中的一些重要缺陷。因此,在本文中,我们将证明Maitra等人的方案不够安全:既不能抵抗离线密码猜测攻击和内部人员攻击,又不能保持前向保密性。为了克服这些缺陷,我们提出了一种改进的新方案,该方案不仅可以抵抗所有已知的攻击,而且还提供了许多吸引人的属性,例如用户吊销和重新注册。此外,我们将该方案与其他相关方案进行了比较,结果证明了该方案的优越性。特别是,我们展示了一种新方法(超越了传统的Deffie-Hellman方法)来实现前向保密。此外,我们付出了一些努力来探索认证方案的设计原理。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号