Cryptanalysis and Improvement of Park Et Al.'s Remote User Authentication Protocol

XIE Qi,CHEN De-ren,YU Xiu-yuan
IF: 2.034
2010-01-01
Systems Engineering
Abstract:In 2009, Park, et al. proposed an efficient remote user authentication protocol. They claimed that their protocol was the first password and smart card based remote user authentication scheme which can resist the off-line password guessing attack, and had many advantages over existing solutions such as no password tables and timestamp, low communication and computational costs. However, this paper shows that their protocol cannot resist the forgery attack and off-line password guessing attack. To overcome the security weaknesses, two improved schemes based on either nonce or timestamp without affecting the merits of the Park, et al. scheme are proposed. Technical discussions are provided to show that the improved protocol is secure, efficient and practical.
What problem does this paper attempt to address?