A Simple Attack on a Recently Introduced Hash-Based Secure User Authentication Scheme

dc.authoridKoc, Cetin Kaya/0000-0002-2572-9565
dc.contributor.authorKim, Minho
dc.contributor.authorKoc, Cetin Kaya
dc.date.accessioned2024-10-12T19:43:06Z
dc.date.available2024-10-12T19:43:06Z
dc.date.issued2006
dc.departmentİstanbul Ticaret Üniversitesien_US
dc.description.abstractUser authentication is an important service in network security. Recently, several user authentication protocols have been proposed. However, a scheme which withstands all known attacks is not yet available. The Lee-Li-Hwang (LLH) authentication scheme [3] was proposed to circumvent the guessing attack in the Peyravian-Zunic (PZ) password scheme [6]. However, Yoon, Ryu, and Yoo (YRY) [9] discovered that the LLH scheme still suffers from the denial of service attack, and proposed an enhancement for the LLH scheme to solve its security problems. More recently, Ku, Chiang, and Chang (KCC) [2] demonstrated that the YRY scheme is vulnerable to the offline guessing and the stolen-verifier attacks. In this paper, we show that the YRY scheme is also vulnerable to the denial-ofservice attack. Furthermore, it was also claimed in [2] that the YRY scheme cannot achieve backward secrecy. We show in this paper that this claim is not entirely valid.en_US
dc.identifier.endpage160en_US
dc.identifier.issn1738-7906
dc.identifier.issue5Ben_US
dc.identifier.startpage157en_US
dc.identifier.urihttps://hdl.handle.net/11467/8760
dc.identifier.volume6en_US
dc.identifier.wosWOS:000216993200019en_US
dc.identifier.wosqualityN/Aen_US
dc.indekslendigikaynakWeb of Scienceen_US
dc.language.isoenen_US
dc.publisherInt Journal Computer Science & Network Security-Ijcsnsen_US
dc.relation.ispartofInternational Journal Of Computer Science And Network Securityen_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/closedAccessen_US
dc.snmzWoS_2024en_US
dc.subjectHash functionen_US
dc.subjectuser authenticationen_US
dc.subjectstolen-verifier attacken_US
dc.subjectdenial-of-service attacken_US
dc.titleA Simple Attack on a Recently Introduced Hash-Based Secure User Authentication Schemeen_US
dc.typeArticleen_US

Dosyalar