Cryptanalysis of a dynamic identity‐based remote user authentication scheme with verifiable password update
Xiong Li, Jianwei Niu, Junguo Liao, Wei Yan Liang · International Journal of Communication Systems · 2013
SUMMARY In the authentication scheme, it is important to ensure that the user's identity changed dynamically with the different sessions, which can protect the user's privacy information from being tracked. Recently, Changet al. proposed an untraceable dynamic identity‐based remote user authentication scheme with verifiable password update. However, our analysis show that the property of untraceability can easily be broken by the legal user of the system. Besides, we find the scheme of Changet al. vulnerable to offline password guessing attack, impersonation attack, stolen smart card attack, and insider attack. Copyright © 2013 John Wiley & Sons, Ltd.