In 2003, Yang, Chang, and Hwang proposed an enhanced scheme of Peyravivan-Zunic’s password authentication scheme by using the Diffie-Hellman scheme. Later, Yoon, Ryu, and Yoo demonstrated that Yang-Chang-Hwang’s scheme is vulnerable to a stolen-verifier attack and a denial-of-service attack, and then proposed an improved scheme. In this paper, we show that Yoon-Ryu-Yoo’s scheme is still vulnerable to a stolen-verifier attack and a server spoofing attack under some reasonable assumption. In addition, we propose an improved scheme to eliminate such security flaws.
목차
Abstract 1. Introduction 2. A Review and the Security Flaw of Yoon-Ryu-Yoo’s Scheme 2.1 A Review of Yoon-Ryu-Yoo’s Scheme 2.2 The Security Flaw of Yoon-Ryu-Yoo’s Scheme 3. The Proposed Scheme 3.1 The Proposed Password Change Protocol 4. Security Analysis 4.1 The Security Strength against the Replay Attack 4.2 The Security Strength against the Stolen-verifier Attack 4.3 The Security Strength against the Password Guessing Attack 4.4 The Security Strength against the Denied-of-Service Attack 4.5 The Security Strength against the Server Spoofing Attack 5. Conclusions 6. References
저자
Chin-Chen Chang [ Department of Computer Science and Information Engineering, Feng Chia University, Taichung, Taiwan, 40724, R.O.C. and Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan, 621, R.O.C. ]
Hao-Chuan Tsai [ Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan, 621, R.O.C. ]
Yi-Hui Chen [ Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan, 621, R.O.C. ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.1 No.2