On security of a more efficient and secure dynamic ID-based remote user authentication scheme
Cheng‐Chi Lee, Chin‐Ling Chen, Chun‐Ta Li, Rui‐Xiang Chang · 2010
Recently, Wang et al. showed that Das et al.'s dynamic ID-based remote user authentication scheme is vulnerable to an impersonation attack and can not achieve mutual authentication. Consequently, a more efficient and secure dynamic ID-based remote user authentication scheme was proposed and claimed that it was now secure and of practical value. However, in this paper, we will show that Wang et al.'s scheme is still vulnerable to off-line password guessing attacks, where the adversary can off-line guess a legal user's password from eavesdropping. Moreover, the dynamic ID feature of their scheme can not be achieved and the adversary is able to determine who was communicating with the remote server. Finally, the process of Wang et al.'s scheme is inconvenient for the user Uidue to any user who picks up Ui's smart card can easily change the original password and Uihas no choice for choosing his/her password in the registration phase.