On the Security of a Dynamic Identity-Based Remote User Authentication Scheme with Verifiable Password Update.

Yongchun Liu,Peng Gong,Xiaopeng Yan,Ping Li
DOI: https://doi.org/10.1002/dac.2708
2013-01-01
International Journal of Communication Systems
Abstract:Recently, Chang et al. [Chang Y, Tai W, Chang H. Untraceable dynamic identity-based remote user authentication scheme with verifiable password update. International Journal of Communication Systems 2013; doi:10.1002/dac.2552] proposed a dynamic identity-based remote user authentication scheme with verifiable password update. They also proved that their scheme could withstand various attacks. Unfortunately, by proposing concrete attacks, we show that their scheme is vulnerable to three kinds of attacks. We also point out that their scheme cannot provide untraceability. The analysis shows that the scheme of Chang et al. is not suitable for practical applications. Copyright (c) 2013 John Wiley & Sons, Ltd.
What problem does this paper attempt to address?