Affiliation:
1. National Chung Cheng University, Chaiyi, Taiwan, R.O.C.
2. National Kaohsiung University of Applied Sciences, Kaohsiung, Taiwan, R.O.C.
Abstract
In 2002, Lee, Ryu, and Yoo proposed a fingerprint-based remote user authentication scheme using smart cards. The scheme makes it possible for authenticating the legitimacy of each login user without any password table. In addition, the authors claimed that the scheme can withstand message replay attack and impersonation. In this paper, we shall point out a security flaw in this scheme, that is, <i>n</i> legitimate users can conspire to forge 2<sup><i>n</i></sup>-<i>n</i>-1 valid IDs and PWs for successfully passing the system authentication. Furthermore, we also show that the authentication equation is incorrect. Thus, the scheme is unworkable.
Publisher
Association for Computing Machinery (ACM)
Cited by
34 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献