作者
Ding Wang, Ping Wang
发表日期
2015
研讨会论文
Information Security: 16th International Conference, ISC 2013, Dallas, Texas, November 13-15, 2013, Proceedings
页码范围
221-237
出版商
Springer International Publishing
简介
The design of secure and efficient smart-card-based password authentication schemes remains a challenging problem today despite two decades of intensive research in the security community, and the current crux lies in how to achieve truly two-factor security even if the smart cards can be tampered. In this paper, we analyze two recent proposals, namely, Hsieh-Leu’s scheme and Wang’s PSCAV scheme. We show that, under their non-tamper-resistance assumption of the smart cards, both schemes are still prone to offline dictionary attack, in which an attacker can obtain the victim’s password when getting temporary access to the victim’s smart card. This indicates that compromising a single factor (i.e., the smart card) of these two schemes leads to the downfall of both factors (i.e., both the smart card and the password), thereby invalidating their claim of preserving two-factor security. Remarkably, our …
引用总数
201420152016201720182019202020212022202320246109131518111014135
学术搜索中的文章
D Wang, P Wang - … Security: 16th International Conference, ISC 2013 …, 2015