篇名 | An Improved Protocol for Password Authentication Using Smart Cards |
---|---|
卷期 | 22:4 |
作者 | Zi-Yao Cheng 、 Yun Liu 、 Chin-Chen Chang 、 Shih-Chang |
頁次 | 028-037 |
關鍵字 | Mutual authentication 、 Password 、 smart card 、 security 、 keyautho 、 EI 、 MEDLINE 、 Scopus |
出刊日期 | 201201 |
Abstract. In recent years, several password authentication schemes for remote login and verification havebeen widely implemented for systems that control and access to Internet applications. Therefore, how to assurethe security protection of these related operations in computer networks has been extensively investigatedby many engineers in these two decades. Recently, an advanced smart card based password authenticationscheme is proposed by Song. He claimed that the proposed scheme performs secure operations and activitiesover the insecure network communications. However, Song’s scheme is still vulnerable to the off-linepassword guessing attack, and it is lack of perfect forward secrecy and system reparability. In this paper, westate the security weaknesses of Song’s scheme, and then propose an improvement of the password based authenticationscheme which not only inherits the criteria of authentication scheme such as mutual authenticationand session key agreement but also protects against the risk of various attacks over the insecure Internetenvironment. Furthermore, we analyze the security and performance aspects to prove that our proposedscheme is more secure, efficient and practical for applications of networks communications.