The Experts below are selected from a list of 51 Experts worldwide ranked by ideXlab platform
De-song Wang - One of the best experts on this subject based on the ideXlab platform.
-
A Novel Mutual Authentication Scheme Based on Fingerprint Biometric and Nonce Using Smart Cards
2011Co-Authors: De-song WangAbstract:In 2007, Khan-Zhang made an enhancement based on Lin-Lai’s flexible biometrics remote user authentication scheme. The scheme has the merits of providing mutual authentication, no verification table, freely Changing Password and preventing the server spooling attack. However, this authentication scheme has been found to be vulnerable to the insider attack, the denial-of-service (DoS) attack and the clock synchronization problem. To overcome these weaknesses, a novel authentication scheme is proposed in this paper, which is based on nonce instead of timestamp and fresh tag to overcome the existing DoS attack and clock synchronization problem. The security analysis shows that the improved scheme not only inherits the merits of their scheme but also enhances the security of their scheme. Meantime the improved scheme does not add additional computation cost to the smart card. So the improved scheme is more secure, reliable and applicable with high potential to be used in the insecure network world than Khan-Zhang’s scheme.
-
Cryptanalysis of a remote user authentication scheme based on bilinear pairing
2009 International Conference on Apperceiving Computing and Intelligence Analysis, 2009Co-Authors: Yue-hao Yan, De-song WangAbstract:Remote user authentication scheme is a mechanism which allows a server to authenticate a remote user over insecure channel. Recently, Goriparthi et al. made an enhancement based on Das et al.'s remote user authentication scheme using bilinear pairings. The scheme has the merits of no verification table, freely Changing Password and preventing the forgery attack and the replay attack. This paper, however, demonstrates that Goriparthi et al.'s improved scheme is vulnerable to the insider attack, the denial-of-service attack, and the server spooling attack.
Song Cheng - One of the best experts on this subject based on the ideXlab platform.
-
A Dynamic-verifier Based Authenticated Key Exchange Protocol
Computer Engineering, 2006Co-Authors: Song ChengAbstract:Traditional design of authenticated key exchange protocol considers communication security, but seldom takes into account the security threat of server compromises. Whenever an authentication server is captured, the intruder can immediately masquerade as legitimate users to successfully log into the system. Although some zero-knowledge-proof methods were designed to relieve this threat, their computation is relatively high due to computationally heavy modular exponentiations employed. A dynamic-verifier based authenticated key exchange protocol is proposed, where the server stores a dynamically Changing Password-verifier and no Password leakage would occur even when the server’s verifier database is stolen. DV-AKE is especially useful for applications where lightweight client is required or lower server computational load is preferred.
Suhaidi Hassan - One of the best experts on this subject based on the ideXlab platform.
-
Anywhere On-Keyboard Password technique
2010 IEEE Student Conference on Research and Development (SCOReD), 2010Co-Authors: Dalia Abdul Hadi Abdul Ameer, Abu Obaydah Mohammed, Adib Monzer M. Habbal, Ahmed Abdulhakim Al-absi, Suhaidi HassanAbstract:Traditional authentication technique generally requires an id and Password to verify the identity of user. By nature, user is looking for a Password that is easy to remember and secured from any attack. However, remembering many complicated Passwords, especially when user has different accounts, is not an easy task. Moreover, Traditional technique is still vulnerable to attack such as hidden camera. To overcome these drawbacks, we propose a new Password authentication technique called “Anywhere On-Keyboard Password (AOKP)”. The experiment results show that 40% of the spies succeed to catch the Password shape but all of them fail to detect the number of the strokes. Therefore, the proposed technique provides more secure and memorable authentication method through Changing Password from text to mix shape and number of strokes. In addition, it has high level of scalability and simplicity though the freedom of writing the Password anywhere on keyboard, Password length and language independent.
Suhaidi Hassan Smieee - One of the best experts on this subject based on the ideXlab platform.
-
Anywhere On-Keyboard Password Technique Dalia Abdul Hadi Abdul Ameer, Ahmed Abdulhakim AL-Absi, Abu Obaydah Mohammed, Adib M. Monzer Habbal,
2010Co-Authors: Suhaidi Hassan SmieeeAbstract:my Abstract -Traditional authentication technique generally requires an id and Password to verify the identity of user. By nature, user is looking for a Password that is easy to remember and secured from any attack. However, remembering many complicated Passwords, especially when user has different accounts, is not an easy task. Moreover, Traditional technique is still vulnerable to attack such as hidden camera. To overcome these drawbacks, we propose a new Password authentication technique called "Anywhere On-Keyboard Password (AOKP)". The experiment results show that 40% of the spies succeed to catch the Password shape but all of them fail to detect the number of the strokes. Therefore, the proposed technique provides more secure and memorable authentication method through Changing Password from text to mix shape and number of strokes. In addition, it has high level of scalability and simplicity though the freedom of writing the Password anywhere on keyboard, Password length and language independent. overcome these drawbacks, we propose a novel alternative Password authentication technique called "Anywhere On Keyboard Password". In this technique, the Password is about any connected shape drawn using keyboard's keys mixed with the number of strokes on each key accordingly. To recall this Password, it is required to map the same Password anywhere on the keyboard using the same number of strokes on each key. This technique is proposed to improve the security of user authentication through Changing Password from text to mix shape and number of strokes. In addition, Anywhere On-Keyboard Password has high level of scalability and simplicity though the freedom of writing the Password at any location on keyboard, Password's length and its ASCII independent. To prove this technique'S features usability evaluation have been done through a laboratory experiment design. In addition, a system has been developed to help users to enter their Password and apply the technique concept through the keyboard device.
Dalia Abdul Hadi Abdul Ameer - One of the best experts on this subject based on the ideXlab platform.
-
Anywhere On-Keyboard Password technique
2010 IEEE Student Conference on Research and Development (SCOReD), 2010Co-Authors: Dalia Abdul Hadi Abdul Ameer, Abu Obaydah Mohammed, Adib Monzer M. Habbal, Ahmed Abdulhakim Al-absi, Suhaidi HassanAbstract:Traditional authentication technique generally requires an id and Password to verify the identity of user. By nature, user is looking for a Password that is easy to remember and secured from any attack. However, remembering many complicated Passwords, especially when user has different accounts, is not an easy task. Moreover, Traditional technique is still vulnerable to attack such as hidden camera. To overcome these drawbacks, we propose a new Password authentication technique called “Anywhere On-Keyboard Password (AOKP)”. The experiment results show that 40% of the spies succeed to catch the Password shape but all of them fail to detect the number of the strokes. Therefore, the proposed technique provides more secure and memorable authentication method through Changing Password from text to mix shape and number of strokes. In addition, it has high level of scalability and simplicity though the freedom of writing the Password anywhere on keyboard, Password length and language independent.