首页 | 本学科首页   官方微博 | 高级检索  
     


Cryptanalysis of Hsiang‐Shih's authentication scheme for multi‐server architecture
Authors:Kuo‐Hui Yeh  N. W. Lo  Yingjiu Li
Affiliation:1. Department of Information Management, National Taiwan University of Science and Technology, Taipei, 106 Taiwan, Republic of China;2. School of Information Systems, Singapore Management University, Singapore 178902, Singapore
Abstract:From user point of view, password‐based remote user authentication technique is one of the most convenient and easy‐to‐use mechanisms to provide necessary security on system access. As the number of computer crimes in modern cyberspace has increased dramatically, the robustness of password‐based authentication schemes has been investigated by industries and organizations in recent years. In this paper, a well‐designed password‐based authentication protocol for multi‐server communication environment, introduced by Hsiang and Shih, is evaluated. Our security analysis indicates that their scheme is insecure against session key disclosure, server spoofing attack, and replay attack and behavior denial. Copyright © 2010 John Wiley & Sons, Ltd.
Keywords:anonymity  authentication  dynamic ID  multi‐server  smart cards
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号