期刊名称:International Journal of Security and Its Applications
印刷版ISSN:1738-9976
出版年度:2013
卷号:7
期号:6
页码:155-164
DOI:10.14257/ijsia.2013.7.6.16
出版社:SERSC
摘要:Generally, if a user wants to use numerous different network services, he/she must register himself/herself to every service providing server. It is not easy task for users to remember these different identities and passwords for each server. To solve the problem, various multi- server authentication schemes have been proposed. Recently, Wang et al. proposed a smartcard based multi-server authentication scheme. They claimed that their scheme is secure against impersonation attack, server spoofing attack and offline dictionary attack, and provides forward secrecy. However, through careful analysis, we find that Wang et al.'s scheme is still vulnerable to password guessing attack with stolen smartcard. Furthermore, we propose an enhanced smartcard based multi-server authentication scheme to cope with the security problem in Wang et al.'s scheme. The proposed scheme is suitable for use in distributed multi-server architecture since it provides mutual authentication, efficiency and security.
关键词:We would like to encourage you to list your keywords in this section