학술논문

Robust and Efficient Password-Authenticated Key Agreement Using Smart Cards
Document Type
Periodical
Source
IEEE Transactions on Industrial Electronics IEEE Trans. Ind. Electron. Industrial Electronics, IEEE Transactions on. 55(6):2551-2556 Jun, 2008
Subject
Power, Energy and Industry Applications
Signal Processing and Analysis
Communication, Networking and Broadcast Technologies
Robustness
Smart cards
Authentication
Dictionaries
Elliptic curve cryptography
Computational efficiency
Privacy
Protection
Public key cryptography
Information management
elliptic curve cryptosystem
key exchange
offline dictionary attack
smart card
Language
ISSN
0278-0046
1557-9948
Abstract
User authentication and key agreement is an important security primitive for creating a securely distributed information system. Additionally, user authentication and key agreement is very useful for providing identity privacy to users. In this paper, we propose a robust and efficient user authentication and key agreement scheme using smart cards. The main merits include the following: 1) the computation and communication cost is very low; 2) there is no need for any password or verification table in the server; 3) a user can freely choose and change his own password; 4) it is a nonce-based scheme that does not have a serious time-synchronization problem; 5) servers and users can authenticate each other; 6) the server can revoke a lost card and issue a new card for a user without changing his identity; 7) the privacy of users can be protected; 8) it generates a session key agreed upon by the user and the server; and 9) it can prevent the offline dictionary attack even if the secret information stored in a smart card is compromised.