A security enhanced mutual authentication scheme based on nonce and smart cards

作者:Shi Wenbo*; He Debiao
来源:Journal of the Chinese Institute of Engineers, 2014, 37(8): 1090-1095.
DOI:10.1080/02533839.2014.912785

摘要

There are many mutual authentication schemes proposed in the literature for preventing unauthorized parties from accessing resources in an insecure environment. However, most of them based on smart cards have assumed a tamper resistant condition for the smart card. To solve the problem, Huang, Liu, and Chen (2013) proposed a mutual authentication scheme based on nonce and smart cards and claimed that the adversary was not able to attack and access the system even if he could extract the data stored in the smart card. Unfortunately, in this paper, we will demonstrate that Huang et al.'s scheme is vulnerable to the offline password guessing attack and the privileged insider attack. We also propose an improved scheme to overcome the weaknesses.