ACM Home Page
Please provide us with feedback. Feedback
A hash-based strong-password authentication scheme without using smart cards
Full text PdfPdf (358 KB)
Source ACM SIGOPS Operating Systems Review archive
Volume 38 ,  Issue 1  (January 2004) table of contents
Pages: 29 - 34  
Year of Publication: 2004
ISSN:0163-5980
Author
Wei-Chi Ku  Fu Jen Catholic University
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 13,   Downloads (12 Months): 88,   Citation Count: 1
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/974104.974107
What is a DOI?

ABSTRACT

So far, many strong-password authentication schemes have been proposed, however, none is secure enough. In 2003, Lin, Shen, and Hwang proposed a strong-password authentication scheme using smart cards, and claimed that their scheme can resist the guessing attack, the replay attack, the impersonation attack, and the stolen-verifier attack. Later, Ku, Tsai, and Chen showed that Lin-Shen-Hwang's scheme suffers from a replay attack and a denial-of-service attack. Herein, we propose a more secure hash-based strong-password authentication scheme without using smart cards.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
C. M. Chen and W. C. Ku, "Stolen-verifier attack on two new strong-password authentication protocols," IEICE Transactions on Communications, vol. E85-B, no. 11, pp. 2519--2521, Nov. 2002.
 
3
 
4
N. M. Hailer, "The S/KEY (TM) one-time password system," in Proceedings of the Internet Society Symposium on Network and Distributed System Security, pp. 151--158, 1994.
 
5
T. Hwang and W. C. Ku, "Reparable key distribution protocols for Internet environments," IEEE Transactions on Communications, vol. 43, no. 5, pp. 1947--1950, May 1995.
6
 
7
W. C. Ku, C. M. Chen, and H. L. Lee, "Cryptanalysis of a variant of Peyravian-Zunic's password authentication scheme," IEICE Transactions on Communications, 1682-1684, May 2003.
8
9
 
10
C. L. Lin, H. M. Sun, and T. Hwang, "Attacks and solutions on strong-password authentication," IEICE Transactions on Communications, vol. E84-B, no. 9, pp. 2622--2627, Sept. 2001.
11
12
 
13
M. Sandirigama, A. Shimizu, and M. T. Noda, "Simple and secure password authentication protocol (SAS)," IEICE Transactions on Communications, vol. E83-B, no. 6, pp. 1363--1365, June 2000.
 
14
A. Shimizu, "A dynamic password authentication method by one-way function," IEICE Transactions, vol. J73-D-I, no. 7, pp. 630--636, July 1990.
 
15
A. Shimizu, T. Horioka, and H. Inagaki, "A password authentication methods for contents communication on the Internet," IEICE Transactions on Communications, vol. E81-B, no. 8, pp. 1666--1673, Aug. 1998.
 
16
T. Tsuji and A. Shimizu, "An impersonation attack on one-time password authentication protocol OSPA," IEICE Transactions on Communications, vol. E86-B, no. 7, pp. 2182--2185, July 2003.
 
17
IEEE P 1363.2 / D 11 (Standard specifications for password-based public-key cryptographic techniques), IEEE P1363 working group, Aug. 2003.