首页> 外文期刊>Wireless personal communications: An Internaional Journal >A New Password-Based Multi-server Authentication Scheme Robust to Password Guessing Attacks
【24h】

A New Password-Based Multi-server Authentication Scheme Robust to Password Guessing Attacks

机译:一种新的基于密码的多服务器身份验证方案,可有效应对密码猜测攻击

获取原文
获取原文并翻译 | 示例
           

摘要

A multi-server authentication scheme is a useful authentication mechanism in which a remote user can access the services of multiple servers after registering with the registration center (RC). This study shows that the password-based multi-server authentication scheme proposed by Yeh and Lo is vulnerable to undetectable password-guessing attack and offline password-guessing attack. This study proposes a new password-based multi-server authentication scheme to overcome these vulnerabilities. The proposed protocol introduces a new mechanism for protecting user password. The RC sends an alternative key to help the server verify the legitimacy of user instead of the user's password. The values of these keys are changed with a random large nonce in each session. Therefore, the password-guessing attack cannot work successfully on the proposed scheme.
机译:多服务器身份验证方案是一种有用的身份验证机制,在该机制中,远程用户在向注册中心(RC)注册后可以访问多个服务器的服务。这项研究表明,Yeh和Lo提出的基于密码的多服务器身份验证方案容易受到无法检测到的密码猜测攻击和离线密码猜测攻击的攻击。这项研究提出了一种新的基于密码的多服务器身份验证方案,以克服这些漏洞。所提出的协议引入了一种保护用户密码的新机制。 RC发送替代密钥来帮助服务器验证用户的合法性,而不是用户密码。这些密钥的值在每个会话中以随机的大随机数更改。因此,密码猜测攻击无法在所提出的方案上成功进行。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号