【24h】

An Improved Two-factor Authentication Protocol

机译:改进的两因素身份验证协议

获取原文
获取原文并翻译 | 示例

摘要

Most recently, Yang et al proposed a new set of security requirements for two-factor smart-card-based password mutual authentication and then suggested a new scheme satisfying all their security requirements. In this paper, however, we first show one critical security weakness being overlooked, i.e., allowing key-compromise impersonation. We provide an attack to illustrate the adversary is able to masquerade any user to access the server's service in their protocol once if the long-term key of the server is compromised. Thereafter, we suggests key-compromise impersonation resilience should be added as one more important security requirement for two-factor smart-card based password mutual authentication and then propose an improved protocol to eliminate the security weakness existing in Yang et al's protocol.
机译:最近,Yang等人针对基于两因素智能卡的密码相互身份验证提出了一套新的安全性要求,然后提出了一种满足其所有安全性要求的新方案。但是,在本文中,我们首先显示了一个被忽略的关键安全弱点,即允许密钥泄露模拟。我们提供了一种攻击手段,以说明对手一旦服务器的长期密钥受到破坏,便能够伪装任何用户以其协议访问服务器的服务。此后,我们建议应添加密钥折衷模拟弹性,作为基于两因素智能卡的密码相互身份验证的一项更重要的安全要求,然后提出一种改进的协议,以消除Yang等人协议中存在的安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号