摘要
2009年,Liao-Wang提出了一种基于智能卡的典型远程用户身份鉴别方案,经分析证明该方案存在安全脆弱性,容易受到离线口令猜测攻击,攻击者伪装成服务器的攻击,域内合法用户伪装成域内其他用户的攻击。之后提出了一种安全改进方案,解决了上述脆弱性问题,具有可靠的安全性。
Analysis on the typical remote user authentication scheme based on smart card, proposed by Liao- Wang in 2009, shows that the scheme is vulnerahl to off-line password guessing attack, including the attacks of attacker' s masquerading as the server's attack, and the legitimate users within the domain as the other users. Meanwhile a safety improvement scheme is proposed to solve the above mentioned vulnerability problem, and the experiment indicates the reliable security of this scheme.
出处
《信息安全与通信保密》
2014年第2期95-97,共3页
Information Security and Communications Privacy
关键词
身份鉴别
智能卡
脆弱性
authentication
smartcard
vulnerability