On the Security of an Authentication Scheme for Multi-Server Architecture

Debiao He,Jianhua Chen,Wenbo Shi,Muhammad Khurram Khan
DOI: https://doi.org/10.1504/ijesdf.2013.058669
2013-01-01
International Journal of Electronic Security and Digital Forensics
Abstract:Recently, Pippal et al. proposed an authentication scheme for multi-server architecture and claimed that their scheme could withstand various attacks. In this paper, we will analyse the security of Pippal et al.'s scheme. After reviewing their scheme, we find that their scheme cannot withstand the server spoofing attack, the user impersonation attack, the offline password guessing attack and the privileged insider attack. The analysis shows their scheme is not secure for practical applications.
What problem does this paper attempt to address?