題名: Replay and Denial-of-Service Attacks on a New Strong-Password Authentication Scheme
作者: Ku, Wei-Chi
Tsai, Hao-Chuan
Chen, Shuai-Min
關鍵字: Strong password
password authentication
stolen-verifier attack
replay attack
denial-of-service attack
期刊名/會議名稱: 中華民國92年全國計算機會議
摘要: Existing one-time password authentication schemes can be categorized into two types, weak-password authentication schemes and strong-password authentication schemes. Generally, the strong-password authentication schemes have the advantages over the weak-password authentication schemes in that their computational overhead are lighter, designs are simpler, and implementations are easier, and therefore are especially suitable for some constrained environments. Recently, Lin, Sun, and Hwang proposed a strong-password authentication scheme, OSPA, which was later found to be vulnerable to a stolen-verifier attack and a man-in-the-middle attack. Later, Lin, Shen, and Hwang proposed an improved version of OSPA and showed that the improved scheme can resist the guessing attack, the replay attack, the impersonation attack, and the stolen-verifier attack. Herein, we show that their scheme is still vulnerable to a replay attack and a denial- of-service attack.
日期: 2006-06-08T08:32:11Z
分類:2003年 NCS 全國計算機會議

文件中的檔案:
檔案 描述 大小格式 
IS_0032003158.pdf105.63 kBAdobe PDF檢視/開啟


在 DSpace 系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。