pith. sign in

arxiv: 0802.2112 · v1 · submitted 2008-02-14 · 💻 cs.CR

On the Security of ``an efficient and complete remote user authentication scheme''

classification 💻 cs.CR
keywords schemeuserauthenticationliawremoteloginadversarycards
0
0 comments X
read the original abstract

Recently, Liaw et al. proposed a remote user authentication scheme using smart cards. Their scheme has claimed a number of features e.g. mutual authentication, no clock synchronization, no verifier table, flexible user password change, etc. We show that Liaw et al.'s scheme is completely insecure. By intercepting a valid login message in Liaw et al.'s scheme, any unregistered user or adversary can easily login to the remote system and establish a session key.

This paper has not been read by Pith yet.

discussion (0)

Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.