2018 2nd annual International Conference on Cloud Technology and Communication Engineering | |
An Improved Mutual Authentication Scheme with Smart Cards and Password under Trusted Computing | |
计算机科学;无线电电子学 | |
Cahyadi, Eko Fajar^1,2 ; Chou, Yung-Chen^1 ; Yang, Cheng-Ying^3 ; Hwang, Min-Shiang^1,4 | |
Department of Computer Science and Information Engineering, Asia University, Taichung | |
41354, Taiwan^1 | |
Department of Telecommunication Engineering, Institut Teknologi Telkom Purwokerto, Purwokerto, Indonesia^2 | |
Department of Computer Science, University of Taipei, Taipei, Taiwan^3 | |
Department of Medical Research, China Medical University Hospital, China Medical University, Taichung | |
40402, Taiwan^4 | |
关键词: Man in the middle attacks; Mutual authentication; Password attacks; Password authentication; Secure session; User identity; | |
Others : https://iopscience.iop.org/article/10.1088/1757-899X/466/1/012008/pdf DOI : 10.1088/1757-899X/466/1/012008 |
|
学科分类:计算机科学(综合) | |
来源: IOP | |
【 摘 要 】
In the traditional smart card-based password authentication schemes, the authentication is only applied to verify both of server and user, but not applied to verify the platform. Recently, Yang, Ma, and Jiang proposed a mutual authentication scheme with smart cards and password under trusted computing. Their scheme was designed to authenticate the platform. They claimed that their scheme could withstand most of the possible attacks, such as secure session key agreement, user identity anonymity, password free changing, and platform certification updating. However, we will show that their scheme is vulnerable to on-line guessing password attack with smart card, and man-in-the-middle attack. In this article, we also propose an improved Yang-Ma-Jiang's mutual authentication scheme to withstand the vulnerability in their scheme.
【 预 览 】
Files | Size | Format | View |
---|---|---|---|
An Improved Mutual Authentication Scheme with Smart Cards and Password under Trusted Computing | 94KB | download |