Title :
A new password authentication and user anonymity scheme based on elliptic curve cryptography and smart card
Author_Institution :
Dept. of Inf. Manage., Tainan Univ. of Technol., Tainan, Taiwan
Abstract :
Password authentication has been widely used in computer networks to provide secure remote access control. In this study, the authors show that the improved password authentication and update scheme based on elliptic curve cryptography proposed by Islam and Biswas is vulnerable to offline password guessing, stolen-verifier and insider attacks. We propose an advanced smart card-based password authentication and update scheme and extend the scheme to provide the privacy of the client. By comparing the criteria with other related schemes, our scheme not only solves several hard security threats but also satisfies more functionality features.
Keywords :
authorisation; computer network security; data privacy; public key cryptography; Biswas; Islam; client privacy; computer networks; elliptic curve cryptography-based user anonymity scheme; hard security threats; insider attacks; secure remote access control; smart card-based password authentication; stolen-verifier; update scheme;
Journal_Title :
Information Security, IET
DOI :
10.1049/iet-ifs.2012.0058