Cryptanalysis and Improvement of an 'Efficient Remote Mutual Authentication and Key Agreement'

Jian Wang,Haihang Wang,Chengxiang Tan
DOI: https://doi.org/10.1109/APSCC.2008.173
2008-01-01
Abstract:A smart card based scheme is practical and widely used in remote mutual authentication. In 2006, Shieh-Wang pointed out the weakness of Juang’s remote mutual authentication scheme using smart card and further proposed a novel one to improve Juang’s. The advantages in Shieh-Wang’s scheme include effective mutual authentication, freely chosen password, no verification tables, low computational cost, session key agreement and no synchronized clocks. However, in 2007, Yoon-Yoo showed that Shieh-Wang’s scheme does not provide perfect forward secrecy, and is vulnerable to a privileged insider’s attack. Furthermore, the current paper demonstrates that Shieh-Wang’s scheme is also vulnerable to the parallel session attack and lack of wrong password detection and then presents a more efficient and secure scheme to resolve all the above problems including those that Yoon-Yoo has pointed out with less computational cost increase.
What problem does this paper attempt to address?