Cryptanalysis of multi factor authentication scheme using smart card
Yasir Glani, LI Jian-hua, Chen Gongliang, Zahid Mehmood · 2016
In the recent decades, in order to achieve high-degree security many researchers are introducing multifactor authentication schemes replacing by conventional password-based remote authentication schemes. In 2010, Li and Hwang proposed biometric-based authentication scheme using the smart card. Later on, Das pointed out that the scheme is susceptible to denial of services attack and also having low efficiency. Then proposed a new scheme to overcome the weaknesses of prior scheme. In 2012, Younghwa An. substantiate that Das's scheme doesn't provide mutual authentication. In 2014, Cao and Ge pointed that Younghwa's scheme is still vulnerable to replay attack and unable to provide user anonymity, while an adversary can perform the re-registration by intercepting user identity IDx in the login phase. In this paper, we first analyze Cao and Ge's scheme and show that their scheme is still vulnerable to password guessing and traceability attacks.