Publication Type
Journal Article
Version
publishedVersion
Publication Date
11-2008
Abstract
One of the most commonly used two-factor user authentication mechanisms nowadays is based on smart-card and password. A scheme of this type is called a smart-card-based password authentication scheme. The core feature of such a scheme is to enforce two-factor authentication in the sense that the client must have the smart-card and know the password in order to gain access to the server. In this paper, we scrutinize the security requirements of this kind of schemes, and propose a new scheme and a generic construction framework for smart-card-based password authentication. We show that a secure password based key exchange protocol can be efficiently transformed to a smart-card-based password authentication scheme provided that there exist pseudorandom functions and target collision resistant hash functions. Our construction appears to be the first one with provable security. In addition, we show that two recently proposed schemes of this kind are insecure.
Keywords
Two-factor authentication, Password, Smart-card, Guessing attack, Dictionary attack
Discipline
Information Security
Research Areas
Information Systems and Management
Publication
Journal of Computer and System Sciences
Volume
74
Issue
7
First Page
1160
Last Page
1172
ISSN
0022-0000
Identifier
10.1016/j.jcss.2008.04.002
Publisher
Elsevier
Citation
YANG, Guomin; WONG, Duncan S.; WANG, Huaxiong; and DENG, Xiaotie.
Two-factor mutual authentication based on smart cards and passwords. (2008). Journal of Computer and System Sciences. 74, (7), 1160-1172.
Available at: https://ink.library.smu.edu.sg/sis_research/7401
Creative Commons License
This work is licensed under a Creative Commons Attribution-NonCommercial-No Derivative Works 4.0 International License.
Additional URL
http://doi.org/10.1016/j.jcss.2008.04.002