Non-interactive password authentications without password tables
Tzonelih Hwang, Yihwa Chen, Chi Jung Laih · 2002
The authors propose a noninteractive password authentication scheme. The scheme simply discards the use of verification tables. The legitimacy of the login user can be validated easily by anyone inside the system. However, no one can masquerade as a legitimate user even though he intercepts the previous login password. The security of the scheme is equivalent to that of Shamir's signature scheme. It can withstand the attack of replaying a previously intercepted login request.>