首页    期刊浏览 2024年07月06日 星期六
登录注册

文章基本信息

  • 标题:Weaknesses and Improvements of a One-time Password Authentication Scheme
  • 本地全文:下载
  • 作者:Mijin Kim ; Byunghee Lee ; Seungjoo Kim
  • 期刊名称:International Journal of Future Generation Communication and Networking
  • 印刷版ISSN:2233-7857
  • 出版年度:2009
  • 卷号:2
  • 期号:4
  • 出版社:SERSC
  • 摘要:Authentication of communicating entities and confidentiality of transmitted data are fundamental procedures to establish secure communications over public insecure networks. Recently, many researchers proposed a variety of authentication schemes to confirm legitimate users. Among the authentication schemes, a one-time password authentication scheme requires less computation and considers the limitations of mobile devices. The purpose of a one-time password authentication is to make it more difficult to gain unauthorized access to restricted resources. This paper discusses the security of Kuo-Lee's one-time password authentication scheme. Kuo-Lee proposed to solve the security problem based on Tsuji-Shimizu's one-time password authentication scheme. It was claimed that their proposed scheme could withstand a replay attack, a theft attack and a modification attack. Therefore, the attacker cannot successfully impersonate the user to log into the system. However, contrary to the claim, Kuo-Lee's scheme does not achieve its main security goal to authenticate communicating entities. We show that Kuo-Lee's scheme is still insecure under a modification attack, a replay attack and an impersonation attack, in which any attacker can violate the authentication goal of the scheme without intercepting any transmitted message. We also propose a scheme that resolves the security flaws found in Kuo-Lee's scheme.
  • 关键词:One-time password; authentication scheme; impersonation attack.
国家哲学社会科学文献中心版权所有