{"title":"Strengthening the Security and Preserving User Anonymity of Remote User Authentication Scheme Using Smart Card","authors":"Abdullah Hanifan, Ari Moesriami Barmawi","doi":"10.1145/3478301.3478302","DOIUrl":null,"url":null,"abstract":"Smart card based user authentication offers security and convenience in the remote user authentication system. On the other hand, a strong and secure scheme is needed to provide user authentication based on a smart card. Several schemes have been proposed, one of them is Lee's scheme proposed in 2015 [1]. However, based on Jung et al. analysis 2015[2], Lee's scheme has several weaknesses against impersonation and off-line password guessing attack. Moreover, the scheme is also failed to preserve user anonymity. This research proposed an improvement scheme to strengthen Lee's scheme [1]. For strengthening Lee's scheme, the proposed scheme uses Zero Knowledge and keyed hash function. The proposed scheme introduces an additional phase for generating a session key for securing the communication between two parties each other. Based on the experiment, it can be concluded that the proposed scheme is stronger than the previous scheme because the probability for breaking the proposed scheme using the off-line password guessing and impersonation attack is less than probability for breaking Lee's scheme.","PeriodicalId":338866,"journal":{"name":"The 2nd European Symposium on Computer and Communications","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-04-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"The 2nd European Symposium on Computer and Communications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3478301.3478302","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Smart card based user authentication offers security and convenience in the remote user authentication system. On the other hand, a strong and secure scheme is needed to provide user authentication based on a smart card. Several schemes have been proposed, one of them is Lee's scheme proposed in 2015 [1]. However, based on Jung et al. analysis 2015[2], Lee's scheme has several weaknesses against impersonation and off-line password guessing attack. Moreover, the scheme is also failed to preserve user anonymity. This research proposed an improvement scheme to strengthen Lee's scheme [1]. For strengthening Lee's scheme, the proposed scheme uses Zero Knowledge and keyed hash function. The proposed scheme introduces an additional phase for generating a session key for securing the communication between two parties each other. Based on the experiment, it can be concluded that the proposed scheme is stronger than the previous scheme because the probability for breaking the proposed scheme using the off-line password guessing and impersonation attack is less than probability for breaking Lee's scheme.