Title :
Drawbacks of Liao et al.´s Password Authentication Scheme
Author :
Yoon, Eun-Jun ; Yoo, Kee-Young
Author_Institution :
Dept. of Comput. Eng., Kyungpook Nat. Univ., Daegu
Abstract :
In 2006, Liao et al. proposed a new password authentication scheme over insecure networks. The primary merit of their scheme is its simplicity and practicality for implementation under insecure communication links. The current paper, however, demonstrates that Liao et al.´s scheme is vulnerable to masquerading server attacks, password guessing attacks using lost smart cards, and insider attacks. In addition, we point out that Liao et al.´s password change scheme is insecure, because an unauthorized user can easily change a new password for a smart card
Keywords :
authorisation; message authentication; Diffie-Hellman key agreement; password authentication; password change scheme; password guessing attack; server attack; smart card; Authentication; Computational complexity; Cryptography; IP networks; Law; Legal factors; Network servers; Resists; Security; Smart cards; Authentication; Cryptanalysis; Diffie-Hellman key agreement; Password; Smart card;
Conference_Titel :
Next Generation Web Services Practices, 2006. NWeSP 2006. International Conference on
Conference_Location :
Seoul
Print_ISBN :
0-7695-2664-0
DOI :
10.1109/NWESP.2006.15