计算机应用

• 信息安全(Information security) • 上一篇    下一篇

一种基于Smart Card的远程用户身份验证方案的安全性讨论

张忠 向涛   

  1. 重庆大学教务处 重庆大学计算机学院
  • 收稿日期:2008-05-27 修回日期:2008-07-28 发布日期:2008-11-01 出版日期:2008-11-01
  • 通讯作者: 张忠

On security of efficient nonce-based remote user authentication scheme using Smart Card

Zhong ZHANG Tao XIANG   

  • Received:2008-05-27 Revised:2008-07-28 Online:2008-11-01 Published:2008-11-01
  • Contact: Zhong ZHANG

摘要: 身份验证是计算机通信的一个重要方面。由于密码验证协议的简单性,它已经被广泛地用于身份验证。最近,Lee氏等利用Smart Card,提出了一个基于随机数的远程用户验证方案。指出了这个方案并不像其提出者所声称的那样安全,同时提出了两种攻击方法以破解其验证方案。

关键词: 密码验证, 猜测攻击, Smart Card

Abstract: Authentication is an issue of importance in computer communications, and password authentication protocols have been widely utilized due to their great convenience. Recently, Lee et al. proposed a nonce-based remote user authentication scheme using smart cards. In this paper, however, it is found that their scheme is not secure as claimed, and two attacks can be launched to break the scheme.

Key words: password authentication, guessing attack, Smart Card