• DocumentCode
    5289
  • Title

    Efficient and secure dynamic ID-based remote user authentication scheme for distributed systems using smart cards

  • Author

    Jenq-Shiou Leu ; Wen-Bin Hsieh

  • Author_Institution
    Dept. of Electron. & Comput. Eng., Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
  • Volume
    8
  • Issue
    2
  • fYear
    2014
  • fDate
    Mar-14
  • Firstpage
    104
  • Lastpage
    113
  • Abstract
    In a distributed environment, a fundamental concern is authentication of local and remote users in insecure communication networks. Absolutely, legitimate users are more powerful attackers, since they possess internal system information not available to an intruder. Therefore many remote user authentication schemes for distributed systems have been proposed. These schemes claimed that they could resist various attacks. However, they were found to have some weaknesses later. Lee et al. proposed a secure dynamic ID-based remote user authentication scheme for the multi-server environment using smart cards and claimed that their scheme could protect against masquerade attacks, server spoofing attack, registration server spoofing attack and insider attack. In this study, the authors show that Lee et al.´s scheme is still vulnerable to password guessing attack, server spoofing attack and masquerade attack. To propose a viable authentication scheme for distributed systems, we remedy the flaws of Lee et al.´s scheme and propose an efficient improvement over Lee et al.´s scheme. Furthermore, we compare the proposed scheme with related ones to prove that the computation cost, security and efficiency of the proposed scheme are well suitable for practical applications in a distributed system.
  • Keywords
    authorisation; computer network security; smart cards; attack resistance; authentication scheme; computation cost; distributed resources; distributed systems; insecure communication networks; insider attack attack protection; internal system information; legitimate users; local user authentication; masquerade attack protection; multiserver environment; network services; open network; password guessing attack; registration server spoofing attack protection; remote user authentication; secure dynamic ID-based remote user authentication scheme; server spooflng attack protection; service access; smart cards;
  • fLanguage
    English
  • Journal_Title
    Information Security, IET
  • Publisher
    iet
  • ISSN
    1751-8709
  • Type

    jour

  • DOI
    10.1049/iet-ifs.2012.0206
  • Filename
    6748544