Journal of Applied Computer Science & Mathematics (Jan 2011)

An Improved Smart Card Based Remote user Authentication Scheme with Session Key Agreement During the Verification Phase

  • Saru KUMARI,
  • M. K. GUPTA,
  • Manoj KUMAR

Journal volume & issue
Vol. 5, no. 11
pp. 38 – 46

Abstract

Read online

In 2009, Hsiang-Shih’s proposed an improvement to Yoon-Ryu-Yoo’s scheme to prevent offline password guess attack and parallel session attack; and Kim-Chung proposed amore secure improvement to Yoon-Yoo’s scheme to with stand offline password leak, masquerading attacks and stolen verifier attack. This article shows that the two improved schemes are still vulnerable to offline password guess attack, insider attack or extended insider attack, denial of service attack and other security flaws. We also propose an improved scheme that not only retains the advantages of the aforementioned schemes but also enhances its security by withstanding the flaws discussed.

Keywords