Cryptanalysis of ID-Based Remote Authentication with Smart Cards on Open Distributed System from Elliptic Curve Cryptography
Duc-Liem Vo, Kwangjo Kim · 2007
Remote authentication is an important mechanism to control user access to remote systems in a way such that only authorized users can be authenticated before being granted services. There are several methods to implement authentication but for human, password authentication is preferred. With advances in elliptic curve cryptography, Wu et al. (10) proposed ID-based remote authentication schemes with smart cards. Their schemes do not require the server to store a verification table for authenticating users and let users choose and change password freely. In addition, the remote hosts can be in open distributed networks and require nothing about the secret of the key information center to authenticate users. However, we show that these schemes are insecure by impersonation attacks. With these attacks, any adversary can be successfully authenticated and then use services at no cost. We also suggest a repaired scheme which is more secure than the original scheme.