Abstract

Generally, if a user wants to use numerous different network services, he/she must register himself/herself to every service providing server. It is not easy task for users to remember these different identities and passwords for each server. To solve the problem, various multiserver authentication schemes have been proposed. Recently, Wang et al. proposed a smartcard based multi-server authentication scheme. They claimed that their scheme is secure against impersonation attack, server spoofing attack and offline dictionary attack, and provides forward secrecy. However, through careful analysis, we find that Wang et al.’s scheme is still vulnerable to password guessing attack with stolen smartcard. Furthermore, we propose an enhanced smartcard based multi-server authentication scheme to cope with the security problem in Wang et al.’s scheme. The proposed scheme is suitable for use in distributed multi-server architecture since it provides mutual authentication, efficiency and security.

Full Text
Published version (Free)

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call