The Experts below are selected from a list of 1866 Experts worldwide ranked by ideXlab platform
Dongho Won - One of the best experts on this subject based on the ideXlab platform.
-
cryptanalysis of dynamic id based user authentication scheme using smartcards without verifier tables
CSA CUTE, 2015Co-Authors: Jaewook Jung, Younsung Choi, Jiye Kim, Dong Hoon Lee, Jongho Mun, Dongho WonAbstract:Password-based remote user authentication technique is the most commonly used for secure communication over insecure network environments. Due to its simplicity and efficiency, it is widely used in many fields such as e-commerce, distributed system, remote host login system, etc. In recent years, several dynamic ID-based user authentication schemes using Password and smart card have been proposed to provide mutual authentication between the user and server. Recently, Lee proposed an efficient dynamic ID-based user authentication scheme without verifier tables. Lee claimed that his scheme can resist off-line Password Guessing attack, user impersonation attack and provide user anonymity. In this paper, we demonstrate that Lee’s enhanced scheme is not secure against off-line Password Guessing attack and user impersonation attack in violation of its security claim as well as it fails to preserve user anonymity.
-
cryptanalysis of a secure remote user authentication scheme
The Journal of Korean Institute of Communications and Information Sciences, 2012Co-Authors: Jin Qiuyan, Kwangwoo Lee, Dongho WonAbstract:In 2011, C.-T. Li et al. proposed a secure user authentication scheme, which is an improvement over Kim et al.’s scheme to resolve several security flaws such as off-line Password Guessing attack and masquerading attack. C.-T. Li et al. claimed that their scheme prevents smart card security related attacks. Moreover, it provides mutual authentication and session key establishment. However, we found that their scheme is vulnerable to Password Guessing attack through Password change phase, smart card forgery attack and stolen verifier attack. Moreover, C.-T. Li et al.’s scheme is not secure against Password Guessing attack as they claimed. In this paper, we also point out that their scheme is not practical to use.
-
off line Password Guessing attack to yang s and huang s authentication schemes for session initiation protocol
Networked Computing and Advanced Information Management, 2009Co-Authors: Yunho Lee, Mijin Kim, Seungjoo Kim, Dongho WonAbstract:The Session Initiation Protocol(SIP) is an application-layer control protocol for creating, modifying, and terminating sessions with one or more participants in the IP-based telephony environment.Yang et al. and Huang et al. proposed a secure authentication scheme for session initiation protocol.Yang's scheme is based on Deffi-Hellman key agreement scheme and a combination of hash functions. In 2006, Huang et al. pointed out that Yang's scheme is insecure, and proposed an improved authentication scheme for SIP. In this paper, the secure of Yang's and Huang's scheme is analyzed. It is demonstrated that both schemes still have some weaknesses: it cannot withstand against the off-line Password-Guessing attack. Based on our analysis, we found the security problem with these schemes and, in addition, shows how to fix it.
-
Password based authenticated key agreement protocol secure against advanced modification attack
The Kips Transactions:partc, 2004Co-Authors: Jin Kwak, Hyung Kyu Yang, Dongho WonAbstract:Password-based mechanism is widely used methods for user authentication. Password-based mechanisms are using memorable Passwords(weak ferrets), therefore Password-based mechanism are vulnerable to the Password Guessing attack. To overcome this problem, man Password-based authenticated key exchange protocols have been proposed to resist Password Guessing attacks. Recently, Seo-Sweeny proposed Password-based Simple Authenticated Key Agreement(SAKA) protocol. In this paper, first, we will examine the SAKA and authenticated key agreement protocols, and then we will show that the proposed simple authenticated key agreement protocols are still insecure against Advanced Modification Attack. And we propose a Password-based Simple Authenticated Key Agreement Protocol secure against Advanced Modification Attack.
Hungmin Sun - One of the best experts on this subject based on the ideXlab platform.
-
Efficient three-party authentication and key agreement protocols resistant to Password Guessing attacks
2003Co-Authors: Hertyan Yeh, Hungmin Sun, Tzonelih HwangAbstract:Three-party EKE was proposed to establish a session key between two clients through a server. However, three-party EKE is insecure against undetectable on-line and off-line Password Guessing attacks. In this paper, we first propose an enhanced three-party EKE to withstand the security risk in three-party EKE. We also propose a verifier-based three-party EKE that is more secure than a plaintext-equivalent mechanism in which a compromise of the server’s database will not result in success in directly impersonating clients
-
simple authenticated key agreement protocol resistant to Password Guessing attacks
Operating Systems Review, 2002Co-Authors: Hertyan Yeh, Hungmin SunAbstract:Password-based mechanism is the widely used method for user authentication. Many Password-based authenticated key exchange protocols have been proposed to resist Password Guessing attacks. In this paper, we present a simple authenticated key agreement protocol called SAKA which is simple and cost-effective. To examine its security, we provide a formal proof of security to show its strength against both passive and active adversaries. Compared with the previously best protocols, SAKA has less number of steps and less computation cost.
-
security analysis of the generalized key agreement and Password authentication protocol
IEEE Communications Letters, 2001Co-Authors: Hertyan Yeh, Hungmin Sun, Tzonelih HwangAbstract:We show that the enhanced version of the generalized key agreement and Password authentication protocol, proposed by Kwon and Song (see IEICE Trans. Commun., vol.E83-B, no.9, p.2044-50, Sept. 2000), is insecure against off-line Password Guessing attacks.
Hertyan Yeh - One of the best experts on this subject based on the ideXlab platform.
-
Efficient three-party authentication and key agreement protocols resistant to Password Guessing attacks
2003Co-Authors: Hertyan Yeh, Hungmin Sun, Tzonelih HwangAbstract:Three-party EKE was proposed to establish a session key between two clients through a server. However, three-party EKE is insecure against undetectable on-line and off-line Password Guessing attacks. In this paper, we first propose an enhanced three-party EKE to withstand the security risk in three-party EKE. We also propose a verifier-based three-party EKE that is more secure than a plaintext-equivalent mechanism in which a compromise of the server’s database will not result in success in directly impersonating clients
-
simple authenticated key agreement protocol resistant to Password Guessing attacks
Operating Systems Review, 2002Co-Authors: Hertyan Yeh, Hungmin SunAbstract:Password-based mechanism is the widely used method for user authentication. Many Password-based authenticated key exchange protocols have been proposed to resist Password Guessing attacks. In this paper, we present a simple authenticated key agreement protocol called SAKA which is simple and cost-effective. To examine its security, we provide a formal proof of security to show its strength against both passive and active adversaries. Compared with the previously best protocols, SAKA has less number of steps and less computation cost.
-
security analysis of the generalized key agreement and Password authentication protocol
IEEE Communications Letters, 2001Co-Authors: Hertyan Yeh, Hungmin Sun, Tzonelih HwangAbstract:We show that the enhanced version of the generalized key agreement and Password authentication protocol, proposed by Kwon and Song (see IEICE Trans. Commun., vol.E83-B, no.9, p.2044-50, Sept. 2000), is insecure against off-line Password Guessing attacks.
Jingxuan Zhai - One of the best experts on this subject based on the ideXlab platform.
-
improved dynamic id based authentication scheme for telecare medical information systems
Journal of Medical Systems, 2013Co-Authors: Tianjie Cao, Jingxuan ZhaiAbstract:In order to protect users’ identity privacy, Chen et al. proposed an efficient dynamic ID-based authentication scheme for telecare medical information systems. However, Chen et al.’s scheme has some weaknesses. In Chen et al.’s scheme, an attacker can track a user by a linkability attack or an off-line identity Guessing attack. Chen et al.’s scheme is also vulnerable to an off-line Password Guessing attack and an undetectable on-line Password Guessing attack when user’s smart card is stolen. In server side, Chen et al.’s scheme needs large computational load to authentication a legal user or reject an illegal user. To remedy the weaknesses in Chen et al.’s scheme, we propose an improved smart card based Password authentication scheme. Our analysis shows that the improved scheme can overcome the weaknesses in Chen et al.’s scheme.
Mohammad Sabzinejad Farash - One of the best experts on this subject based on the ideXlab platform.
-
a provably secure and efficient two party Password based explicit authenticated key exchange protocol resistance to Password Guessing attacks
Concurrency and Computation: Practice and Experience, 2015Co-Authors: Mohammad Sabzinejad Farash, S Hafizul K Islam, Mohammad S ObaidatAbstract:Password-based two-party authenticated key exchange 2PAKE protocol enables two or more entities, who only share a low-entropy Password between them, to authenticate each other and establish a high-entropy secret session key. Recently, Zheng et al. proposed a Password-based 2PAKE protocol based on bilinear pairings and claimed that their protocol is secure against the known security attacks. However, in this paper, we indicate that the protocol of Zheng et al. is insecure against the off-line Password Guessing attack, which is a serious threat to such protocols. Consequently, we show that an attacker who obtained the users' Password by applying the off-line Password Guessing attack can easily obtain the secret session key. In addition, the protocol of Zheng et al. does not provide the forward secrecy of the session key. As a remedy, we also improve the protocol of Zheng et al. and prove the security of our enhanced protocol in the random oracle model. The simulation result shows that the execution time of our 2PAKE protocol is less compared with other existing protocols. Copyright © 2015 John Wiley & Sons, Ltd.
-
an enhanced and secure three party Password based authenticated key exchange protocol without using server s public keys and symmetric cryptosystems
International Test Conference, 2014Co-Authors: Mohammad Sabzinejad Farash, Mahmoud Ahmadian AttariAbstract:Password-based authenticated key exchange protocol is a type of authenticated key exchange protocols which enables two or more communication entities, who only share weak, low-entropy and easily memorable Passwords, to authenticate each other and establish a high-entropy secret session key. In 2012, Tallapally proposed an enhanced three-party Password-based authenticated key exchange protocol to overcome the weaknesses of Huang’s scheme. However, in this paper, we indicate that the Tallapally’s scheme not only is still vulnerable to undetectable online Password Guessing attack, but also is insecure against off-line Password Guessing attack. Therefore, we propose a more secure and efficient scheme to overcome the security flaws. DOI: http://dx.doi.org/10.5755/j01.itc.43.2.3790