A password authentication scheme with secure password updating
โ Scribed by Chun-Li Lin; Tzonelih Hwang
- Publisher
- Elsevier Science
- Year
- 2003
- Tongue
- English
- Weight
- 109 KB
- Volume
- 22
- Category
- Article
- ISSN
- 0167-4048
No coin nor oath required. For personal study only.
โฆ Synopsis
Recently, Hwang and Yeh proposed an improvement on the Peyravian-Zunic password scheme. The Hwang-Yeh scheme comprises a password authentication protocol, a password change protocol, and can also provide key distribution. Though the Hwang-Yeh scheme repaired several security problems of the Peyravian-Zunic scheme, it has several security problems: the password change protocol in the
Hwang-Yeh scheme is vulnerable to a denial of service attack; and it does not provide the forward secrecy property in session key distribution. Furthermore, we shall fix the Hwang-Yeh scheme to avoid these problems.
๐ SIMILAR VOLUMES
Yang and Shieh proposed a timestamp-based password authentication scheme. Chan and Cheng proved that it is insecure. In this paper, we will give a further cryptanalysis of the scheme, and give an easier attack on it. Finally, we will propose an improved scheme that can withstand both of the attacks.
In 1999, Yang and Shieh proposed a timestamp-based password authentication scheme with smart cards. However, Chan and Cheng showed that it was insecure because the scheme was vulnerable to the forged login attack. In this paper, we propose a modified Yang-Shieh scheme to enhance security. Our modifi