標題: Authentication protocols using Hoover-Kausik's software token
作者: Ku, Wei-Chi
Lee, Hui-Lung
資訊工程學系
Department of Computer Science
關鍵字: password;authentication;software token;cryptographic camouflage;guessing attack
公開日期: 1-May-2006
摘要: In 1999, Hoover and Kausik introduced a software token using the cryptographic camouflage technique and claimed that it can resist various on-line and off-line guessing attacks. Later, Kwon presented an authentication protocol based on the cryptographic camouflage technique and DSA, and pointed out that this initial protocol is vulnerable to an impersonation attack once a server's secret key or private key is compromised. Then, Kwon proposed a modified version that can resist such an impersonation attack by cryptographically embedding the recipient's identity in the user's signature to ensure that only the intended recipient will accept this signature. However, we find that Kwon's modified protocol still has some drawbacks. In this paper, we first demonstrate the drawbacks of Kwon's modified protocol and then propose an improved authentication protocol based on the cryptographic camouflage technique and RSA. Finally, we show that our improved protocol can provide prefect forward secrecy and can resist the off-line guessing attack, the impersonation attack, the replay attack, and the Denning-Sacco attack. Furthermore, the resistance of our improved protocol to the modification attack is also enhanced by additionally using credit-card sized CD-ROMs.
URI: http://hdl.handle.net/11536/12314
ISSN: 1016-2364
期刊: JOURNAL OF INFORMATION SCIENCE AND ENGINEERING
Volume: 22
Issue: 3
起始頁: 691
結束頁: 699
Appears in Collections:Articles


Files in This Item:

  1. 000237907900015.pdf

If it is a zip file, please download the file and unzip it, then open index.html in a browser to view the full text content.