A key agreement based anonymity scheme

Chao-Wen Chan, Te-Chih Chiu · 2011 4th IEEE International Conference on Broadband Network and Multimedia Technology · 2011

In computer networks, how a server authenticates a client with a smart card to negotiate a session key for establishing a secure connection becomes an attractive research topic. For client authentication and key agreement, in 2011, Wang et al. proposed an authentication and key agreement scheme. They claimed that the proposed scheme possessed the following properties: no verification table, free password change, no time-synchronization problem, negotiating a common session key, efficiency, and preserving the privacy of secret key. We find that Wang et al.'s scheme has a security weakness in anonymity. When the server performs a compromise attack with an attacker, they shall break the anonymity. In this paper, we propose an improvement to remedy the weakness of Wang et al.'s scheme.

Read the paper · More papers on PaperTik