Cryptanalysis of Khan et al.'s dynamic ID-based remote user authentication scheme
Chun‐Ta Li, Chen-Ju Liu, Cheng‐Chi Lee, Chin-Wen Lee · 2010
Recently, Khan et al. showed that Wang et al.'s dynamic ID-based remote user authentication scheme is not feasible for real-life implementations such as without preserving anonymity of a user during authentication, user cannot choose the password he/she wants, no provision for revocation of lost or stolen smart card, and can not provide session key agreement. Consequently, an improved version of dynamic ID-based remote user authentication scheme was proposed and claimed that it was now secure and of practical value. However, in this paper, we will show that user anonymity of Khan et al.'s scheme is not preserved and a registered user Ujcan identify the login person Uitrying to login into the server. Furthermore, Khan et al.'s scheme suffers from insider attacks and the malicious insider can impersonate legal users to login into remote server.