Cryptanalysis of ‘A novel user-participating authentication scheme’
Amlan Jyoti Choudhury, Mangal Sain · 2017 International Conference on Inventive Computing and Informatics (ICICI) · 2017
User authentication is a vital security issue in client-server inter-networking systems due to the presence of critical threats or network adversaries in the communication channel. Verifying legitimacy of such users in real-time environments is a prime security challenge. Of late, T. H. Chen and J. C. Huang proposed a two-factor authentication framework claiming that the scheme is secure against most of the existing attacks. However we show that Chen and Huang scheme have many critical weakness in real-time environments. The scheme is prone to man in the middle attack and information leakage attack. Furthermore, the scheme does not provide two essential security services such user anonymity and session key establishment.