Title :
Cryptanalysis of "A Robust Smart-Card-Based Remote User Password Authentication Scheme"
Author :
Kumari, Smriti ; Bin Muhaya, Fahad ; Khan, Muhammad Khurram ; Kumar, Ravindra
Author_Institution :
Dept. of Math., Dr. B.R.A. Univ., Agra, India
Abstract :
Smart card is a widely accepted user authentication tool to ensure only authorized access to resources available via open networks. In 2010, Sood et al. and Song independently examined a smart card based authentication scheme proposed by Xu et al. They showed that in Xu et al.´s scheme an internal user of the system could turn hostile to impersonate other users of the system. Sood et al. and Song also proposed schemes in order to improve scheme proposed by Xu et al.´s. Recently, Chen et al. identified some security problems in the improvements proposed by Sood et al. and Song. To fix these problems Chen et al. presented another scheme, which they claimed to provide mutual authentication and withstand, lost smart card attack. Undoubtedly, in their scheme user can also verify the legitimacy of server but we find that the scheme fails to resist impersonation attacks and privileged insider attack. We also show that the scheme does not provide user anonymity and confidentiality to air messages. In addition, an attacker can guess a user´s password from his lost/stolen smart card.
Keywords :
authorisation; cryptography; data privacy; smart cards; cryptanalysis; impersonation attack resistance; lost smart card attack; mutual authentication; open network; privileged insider attack; resource authorized access; robust smart-card-based remote user password authentication scheme; server legitimacy verification; user anonymity; user confidentiality; user impersonation; user password guessing; Authentication; Computers; Cryptography; Educational institutions; Servers; Smart cards; Password guessing attack; Session-key disclosure; Smart card; User anonymity; User impersonation attack;
Conference_Titel :
Biometrics and Security Technologies (ISBAST), 2013 International Symposium on
Conference_Location :
Chengdu
Print_ISBN :
978-0-7695-5010-7
DOI :
10.1109/ISBAST.2013.43