題名: | Replay and Denial-of-Service Attacks on a New Strong-Password Authentication Scheme |
作者: | Ku, Wei-Chi Tsai, Hao-Chuan Chen, Shuai-Min |
關鍵字: | Strong password password authentication stolen-verifier attack replay attack denial-of-service attack |
期刊名/會議名稱: | 中華民國92年全國計算機會議 |
摘要: | Existing one-time password authentication schemes can be categorized into two types, weak-password authentication schemes and strong-password authentication schemes. Generally, the strong-password authentication schemes have the advantages over the weak-password authentication schemes in that their computational overhead are lighter, designs are simpler, and implementations are easier, and therefore are especially suitable for some constrained environments. Recently, Lin, Sun, and Hwang proposed a strong-password authentication scheme, OSPA, which was later found to be vulnerable to a stolen-verifier attack and a man-in-the-middle attack. Later, Lin, Shen, and Hwang proposed an improved version of OSPA and showed that the improved scheme can resist the guessing attack, the replay attack, the impersonation attack, and the stolen-verifier attack. Herein, we show that their scheme is still vulnerable to a replay attack and a denial- of-service attack. |
日期: | 2006-06-08T08:32:11Z |
分類: | 2003年 NCS 全國計算機會議 |
文件中的檔案:
檔案 | 描述 | 大小 | 格式 | |
---|---|---|---|---|
IS_0032003158.pdf | 105.63 kB | Adobe PDF | 檢視/開啟 |
在 DSpace 系統中的文件,除了特別指名其著作權條款之外,均受到著作權保護,並且保留所有的權利。