Security improvements of dynamic ID-based remote user authentication scheme with session key agreement
YoungHwa An · International Conference on Advanced Communication Technology · 2013
Password-based authentication schemes have been widely adopted to protect resources from unauthorized access. In 2010, Khan et al. proposed an efficient and secure dynamic ID-based authentication scheme to overcome the weaknesses of Wang et al.'s scheme. In this paper, we show that Khan et al.'s scheme is vulnerable to password guessing attack, forgery attack, and does not provide user anonymity. Also, we propose the improved scheme to overcome the security drawbacks of Khan et al.'s scheme and to provide user anonymity and session key agreement, even if the secret values stored in the smart card is revealed. As a result, the improved scheme is relatively more secure than the related scheme in terms of security.