Recently, Juang proposed an efficient password authenticated key agreement scheme using smart cards for the multi-server architecture. Juang's scheme was intended to provide mutual authentication and session key agreement. Herein, we show that Juang's scheme is vulnerable to a privileged insider's attack and is not easily reparable. Furthermore, it does not provide forward secrecy and the user eviction mechanism.
The copyright of the original papers published on this site belongs to IEICE. Unauthorized use of the original or translated papers is prohibited. See IEICE Provisions on Copyright for details.
Copy
Wei-Chi KU, Hsiu-Mei CHUANG, Min-Hung CHIANG, "Cryptanalysis of a Multi-Server Password Authenticated Key Agreement Scheme Using Smart Cards" in IEICE TRANSACTIONS on Fundamentals,
vol. E88-A, no. 11, pp. 3235-3238, November 2005, doi: 10.1093/ietfec/e88-a.11.3235.
Abstract: Recently, Juang proposed an efficient password authenticated key agreement scheme using smart cards for the multi-server architecture. Juang's scheme was intended to provide mutual authentication and session key agreement. Herein, we show that Juang's scheme is vulnerable to a privileged insider's attack and is not easily reparable. Furthermore, it does not provide forward secrecy and the user eviction mechanism.
URL: https://globals.ieice.org/en_transactions/fundamentals/10.1093/ietfec/e88-a.11.3235/_p
Copy
@ARTICLE{e88-a_11_3235,
author={Wei-Chi KU, Hsiu-Mei CHUANG, Min-Hung CHIANG, },
journal={IEICE TRANSACTIONS on Fundamentals},
title={Cryptanalysis of a Multi-Server Password Authenticated Key Agreement Scheme Using Smart Cards},
year={2005},
volume={E88-A},
number={11},
pages={3235-3238},
abstract={Recently, Juang proposed an efficient password authenticated key agreement scheme using smart cards for the multi-server architecture. Juang's scheme was intended to provide mutual authentication and session key agreement. Herein, we show that Juang's scheme is vulnerable to a privileged insider's attack and is not easily reparable. Furthermore, it does not provide forward secrecy and the user eviction mechanism.},
keywords={},
doi={10.1093/ietfec/e88-a.11.3235},
ISSN={},
month={November},}
Copy
TY - JOUR
TI - Cryptanalysis of a Multi-Server Password Authenticated Key Agreement Scheme Using Smart Cards
T2 - IEICE TRANSACTIONS on Fundamentals
SP - 3235
EP - 3238
AU - Wei-Chi KU
AU - Hsiu-Mei CHUANG
AU - Min-Hung CHIANG
PY - 2005
DO - 10.1093/ietfec/e88-a.11.3235
JO - IEICE TRANSACTIONS on Fundamentals
SN -
VL - E88-A
IS - 11
JA - IEICE TRANSACTIONS on Fundamentals
Y1 - November 2005
AB - Recently, Juang proposed an efficient password authenticated key agreement scheme using smart cards for the multi-server architecture. Juang's scheme was intended to provide mutual authentication and session key agreement. Herein, we show that Juang's scheme is vulnerable to a privileged insider's attack and is not easily reparable. Furthermore, it does not provide forward secrecy and the user eviction mechanism.
ER -