Abstract :
Password authentication is widely used in e-business because of its inexpensiveness, easy implementation, and user-friendliness. To resist stolen-verifier attacks, many verifier-free remote user password authentication schemes have been proposed. In 2004, Ku and Chen showed that an efficient verifier-free remote user password authentication proposed by Chien, Jan, and Tseng is flawed and then described an improved version. Recently, Yoon, Ryu, and Yoo pointed out that Ku-Chen ´s scheme is vulnerable to two attacks, and then proposed a slightly modified version. Unfortunately, Yoon- Ryu-Yoo s modified scheme is impractical. Herein, we propose a new verifier-free remote user password authentication scheme that is more secure and practical than existing similar schemes.