International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

Comments on two password based protocols

Authors:
Yalin Chen
Hung-Min Sun
Chun-Hui Huang
Jue-Sam Chou
Download:
URL: http://eprint.iacr.org/2008/400
Search ePrint
Search Google
Abstract: Recently, M. Hölbl et al. and I. E. Liao et al. each proposed an user authentication protocol. Both claimed that their schemes can withstand password guessing attack. However, T. Xiang et al. pointed out I. E. Liao et al.'s protocol suffers three kinds of attacks, including password guessing attacks. We present an improvement protocol to get rid of password guessing attacks. In this paper, we first point out the security loopholes of M. Hölbl et al.'s protocol and review T. Xiang et al.'s cryptanalysis on I. E. Liao et al.'s protocol. Then, we present the improvements on M. Hölbl et al.'s protocol and I. E. Liao et al.'s protocol, respectively.
BibTeX
@misc{eprint-2008-18167,
  title={Comments on two password based protocols},
  booktitle={IACR Eprint archive},
  keywords={cryptographic protocols / hash functions, identification protocols, smart cards},
  url={http://eprint.iacr.org/2008/400},
  note={ d949702@oz.nthu.edu.tw 14146 received 20 Sep 2008, last revised 24 Sep 2008},
  author={Yalin Chen and Hung-Min Sun and Chun-Hui Huang and Jue-Sam Chou},
  year=2008
}