The Experts below are selected from a list of 1866 Experts worldwide ranked by ideXlab platform

Dongho Won - One of the best experts on this subject based on the ideXlab platform.

  • cryptanalysis of dynamic id based user authentication scheme using smartcards without verifier tables
    CSA CUTE, 2015
    Co-Authors: Jaewook Jung, Younsung Choi, Jiye Kim, Dong Hoon Lee, Jongho Mun, Dongho Won
    Abstract:

    Password-based remote user authentication technique is the most commonly used for secure communication over insecure network environments. Due to its simplicity and efficiency, it is widely used in many fields such as e-commerce, distributed system, remote host login system, etc. In recent years, several dynamic ID-based user authentication schemes using Password and smart card have been proposed to provide mutual authentication between the user and server. Recently, Lee proposed an efficient dynamic ID-based user authentication scheme without verifier tables. Lee claimed that his scheme can resist off-line Password Guessing attack, user impersonation attack and provide user anonymity. In this paper, we demonstrate that Lee’s enhanced scheme is not secure against off-line Password Guessing attack and user impersonation attack in violation of its security claim as well as it fails to preserve user anonymity.

  • cryptanalysis of a secure remote user authentication scheme
    The Journal of Korean Institute of Communications and Information Sciences, 2012
    Co-Authors: Jin Qiuyan, Kwangwoo Lee, Dongho Won
    Abstract:

    In 2011, C.-T. Li et al. proposed a secure user authentication scheme, which is an improvement over Kim et al.’s scheme to resolve several security flaws such as off-line Password Guessing attack and masquerading attack. C.-T. Li et al. claimed that their scheme prevents smart card security related attacks. Moreover, it provides mutual authentication and session key establishment. However, we found that their scheme is vulnerable to Password Guessing attack through Password change phase, smart card forgery attack and stolen verifier attack. Moreover, C.-T. Li et al.’s scheme is not secure against Password Guessing attack as they claimed. In this paper, we also point out that their scheme is not practical to use.

  • off line Password Guessing attack to yang s and huang s authentication schemes for session initiation protocol
    Networked Computing and Advanced Information Management, 2009
    Co-Authors: Yunho Lee, Mijin Kim, Seungjoo Kim, Dongho Won
    Abstract:

    The Session Initiation Protocol(SIP) is an application-layer control protocol for creating, modifying, and terminating sessions with one or more participants in the IP-based telephony environment.Yang et al. and Huang et al. proposed a secure authentication scheme for session initiation protocol.Yang's scheme is based on Deffi-Hellman key agreement scheme and a combination of hash functions. In 2006, Huang et al. pointed out that Yang's scheme is insecure, and proposed an improved authentication scheme for SIP. In this paper, the secure of Yang's and Huang's scheme is analyzed. It is demonstrated that both schemes still have some weaknesses: it cannot withstand against the off-line Password-Guessing attack. Based on our analysis, we found the security problem with these schemes and, in addition, shows how to fix it.

  • Password based authenticated key agreement protocol secure against advanced modification attack
    The Kips Transactions:partc, 2004
    Co-Authors: Jin Kwak, Hyung Kyu Yang, Dongho Won
    Abstract:

    Password-based mechanism is widely used methods for user authentication. Password-based mechanisms are using memorable Passwords(weak ferrets), therefore Password-based mechanism are vulnerable to the Password Guessing attack. To overcome this problem, man Password-based authenticated key exchange protocols have been proposed to resist Password Guessing attacks. Recently, Seo-Sweeny proposed Password-based Simple Authenticated Key Agreement(SAKA) protocol. In this paper, first, we will examine the SAKA and authenticated key agreement protocols, and then we will show that the proposed simple authenticated key agreement protocols are still insecure against Advanced Modification Attack. And we propose a Password-based Simple Authenticated Key Agreement Protocol secure against Advanced Modification Attack.

Hungmin Sun - One of the best experts on this subject based on the ideXlab platform.

Hertyan Yeh - One of the best experts on this subject based on the ideXlab platform.

Jingxuan Zhai - One of the best experts on this subject based on the ideXlab platform.

  • improved dynamic id based authentication scheme for telecare medical information systems
    Journal of Medical Systems, 2013
    Co-Authors: Tianjie Cao, Jingxuan Zhai
    Abstract:

    In order to protect users’ identity privacy, Chen et al. proposed an efficient dynamic ID-based authentication scheme for telecare medical information systems. However, Chen et al.’s scheme has some weaknesses. In Chen et al.’s scheme, an attacker can track a user by a linkability attack or an off-line identity Guessing attack. Chen et al.’s scheme is also vulnerable to an off-line Password Guessing attack and an undetectable on-line Password Guessing attack when user’s smart card is stolen. In server side, Chen et al.’s scheme needs large computational load to authentication a legal user or reject an illegal user. To remedy the weaknesses in Chen et al.’s scheme, we propose an improved smart card based Password authentication scheme. Our analysis shows that the improved scheme can overcome the weaknesses in Chen et al.’s scheme.

Mohammad Sabzinejad Farash - One of the best experts on this subject based on the ideXlab platform.

  • a provably secure and efficient two party Password based explicit authenticated key exchange protocol resistance to Password Guessing attacks
    Concurrency and Computation: Practice and Experience, 2015
    Co-Authors: Mohammad Sabzinejad Farash, S Hafizul K Islam, Mohammad S Obaidat
    Abstract:

    Password-based two-party authenticated key exchange 2PAKE protocol enables two or more entities, who only share a low-entropy Password between them, to authenticate each other and establish a high-entropy secret session key. Recently, Zheng et al. proposed a Password-based 2PAKE protocol based on bilinear pairings and claimed that their protocol is secure against the known security attacks. However, in this paper, we indicate that the protocol of Zheng et al. is insecure against the off-line Password Guessing attack, which is a serious threat to such protocols. Consequently, we show that an attacker who obtained the users' Password by applying the off-line Password Guessing attack can easily obtain the secret session key. In addition, the protocol of Zheng et al. does not provide the forward secrecy of the session key. As a remedy, we also improve the protocol of Zheng et al. and prove the security of our enhanced protocol in the random oracle model. The simulation result shows that the execution time of our 2PAKE protocol is less compared with other existing protocols. Copyright © 2015 John Wiley & Sons, Ltd.

  • an enhanced and secure three party Password based authenticated key exchange protocol without using server s public keys and symmetric cryptosystems
    International Test Conference, 2014
    Co-Authors: Mohammad Sabzinejad Farash, Mahmoud Ahmadian Attari
    Abstract:

    Password-based authenticated key exchange protocol is a type of authenticated key exchange protocols which enables two or more communication entities, who only share weak, low-entropy and easily memorable Passwords, to authenticate each other and establish a high-entropy secret session key. In 2012, Tallapally proposed an enhanced three-party Password-based authenticated key exchange protocol to overcome the weaknesses of Huang’s scheme. However, in this paper, we indicate that the Tallapally’s scheme not only is still vulnerable to undetectable online Password Guessing attack, but also is insecure against off-line Password Guessing attack. Therefore, we propose a more secure and efficient scheme to overcome the security flaws. DOI: http://dx.doi.org/10.5755/j01.itc.43.2.3790