Cryptanalysis of a timestamp-based password authentication scheme 1

Lizhen Yang, Kefei Chen · 2004

Recently, J.-J. Shen, C.-W. Lin and M.-S. Hwang (Computers & Security, Vol 22, No 7, pp 591-595, 2003) proposed a modi ed Yang-Shieh scheme to enhance security. They claimed that their modi ed scheme can withstand the forged login attack and also provide a mutual authentication method to prevent the forged server attack. In this paper, we show that the Shen-Lin-Hwang scheme cannot resist the forged login attack either. The intruder is able to forge a valid forge request of a legitimate user U i and then successfully impersonate him by intercepting a login request sent by U i and registering a smart card.

Read the paper · More papers on PaperTik