Improved Against Off-Line Dictionary Attack Password Change Protocol

Tianjie Cao
2009-01-01
Computer Engineering and Applications Journal
Abstract:Password authentication is the simplest,most convenient and most widely used means of authentication.Recently,Tsaur and some others point out that the password change protocol which is presented by Chang presents the denial-of-service attacks and cannot provide backward secrecy.Then,they present an improved password change mechanism which is claimed to be secure.Their protocol is analysed to show that their improved password change mechanism fails to against the off-line dictionary attack and cannot provide backward secrecy and forward secrecy.Finally,an improved against off-line dictionary attack password change protocol is proposed,which can resist off-line dictionary attack and provide backward secrecy and forward secrecy.
What problem does this paper attempt to address?