ChinaCom2008-Network and Information Security Symposium

Research Article

A Token Free Password Authentication Scheme with Multiple Key Agreements

  • @INPROCEEDINGS{10.1109/CHINACOM.2008.4685228,
        author={Chin-Chen Chang and Hao-Chuan Tsai and Shi-Yi Lin},
        title={A Token Free Password Authentication Scheme with Multiple Key Agreements},
        proceedings={ChinaCom2008-Network and Information Security Symposium},
        publisher={IEEE},
        proceedings_a={CHINACOM2008-NIS},
        year={2008},
        month={11},
        keywords={authentication password change Diffie-Hellman multiple key agreements},
        doi={10.1109/CHINACOM.2008.4685228}
    }
    
  • Chin-Chen Chang
    Hao-Chuan Tsai
    Shi-Yi Lin
    Year: 2008
    A Token Free Password Authentication Scheme with Multiple Key Agreements
    CHINACOM2008-NIS
    IEEE
    DOI: 10.1109/CHINACOM.2008.4685228
Chin-Chen Chang1,*, Hao-Chuan Tsai2,*, Shi-Yi Lin2,*
  • 1: Department of Computer Science and Information Engineering, Feng Chia University, Taichung, Taiwan, 40724, R.O.C.,Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan, 621, R.O.C.
  • 2: Department of Computer Science and Information Engineering, National Chung Cheng University, Chiayi, Taiwan, 621, R.O.C.
*Contact email: ccc@cs.ccu.edu.tw, tsaihc@cs.ccu.edu.tw, sylin@cs.ccu.edu.tw

Abstract

Recently, Peyravian and Jeffries proposed an efficient password authentication scheme with key agreement, which utilizes no extra tokens and freely updates account numbers and passwords for users. Unfortunately, due to the fact that the integrity is not well protected, it is still vulnerable to the fatal weaknesses. To overcome these security flaws, we propose an enhanced version with novel architecture. Our proposed scheme not only processes the merits that such token-free based schemes have, but also establishes multiple session keys in each session. Moreover, our proposed scheme does not lead heavy burden for users and is easier to implement than the previously similar ones.