원문정보
초록
영어
Liao et al.’s has recently announced the suitable authentication scheme for mobile device environment, which can authenticate remote users by using QR code. However, Liao et al.'s scheme cannot satisfy several important security requirements. The biggest drawback of Liao et al.'s scheme is that it is not able to satisfy the mutual authentication between remote users and SP since it is vulnerable to eavesdropping, man-in-the-middle, theft and loss of mobile devices and forgery attack. This paper aims to analyze the problems of Liao, et al., scheme and propose a safe authentication scheme using password based QR code that has fixed the aforementioned vulnerabilities.
목차
1. Introduction
2. Review of Liao, et al.,’s Authentication Scheme
3. Security Analysis of Liao et al.’s Scheme
3.1. Man-in-the-middle Attack
3.2. Stolen Attack
3.3. User Spoofing Attack
3.4. Server Spoofing Attack
4. Description of the Proposed Authentication Scheme
5. Security Analysis of the Proposed Scheme
5.1. Resist Stolen Mobile Device Attack
5.2. Resist Man-in-the Middle Attack
5.3. Resist Impersonation Attacks
5.4. Proper Mutual Authentication
5.5. Free Password Change
6. Performance Comparisons and Functionality Analysis
7. Conclusion
References
