Formal analysis and systematic construction of two-factor authentication scheme

Guomin Yang, Duncan S. Wong, Huaxiong Wang, Xiaotie Deng

Research output: Chapters, Conference Papers, Creative and Literary WorksRGC 32 - Refereed conference paper (with host publication)peer-review

Abstract

One of the most commonly used two-factor authentication mechanisms is based on smart card and user’s password. Throughout the years, there have been many schemes proposed, but most of them have already been found flawed due to the lack of formal security analysis. On the cryptanalysis of this type of schemes, in this paper, we further review two recently proposed schemes and show that their security claims are invalid. To address the current issue, we propose a new and simplified property set and a formal adversarial model for analyzing the security of this type of schemes. We believe that the property set and the adversarial model themselves are of independent interest. We then propose a new scheme and a generic construction framework. In particular, we show that a secure password based key exchange protocol can be transformed efficiently to a smartcard and password based two-factor authentication scheme provided that there exist pseudorandom functions and collision-resistant hash functions. © Springer-Verlag Berlin Heidelberg 2006.
Original languageEnglish
Title of host publicationInformation and Communications Security - 8th International Conference, ICICS 2006, Proceedings
PublisherSpringer Verlag
Pages82-91
Volume4307 LNCS
ISBN (Print)9783540494966
DOIs
Publication statusPublished - 2006
Event8th International Conference on Information and Communications Security, ICICS 2006 - Raleigh, United States
Duration: 4 Dec 20067 Dec 2006

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume4307 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference8th International Conference on Information and Communications Security, ICICS 2006
PlaceUnited States
CityRaleigh
Period4/12/067/12/06

Bibliographical note

Publication details (e.g. title, author(s), publication statuses and dates) are captured on an “AS IS” and “AS AVAILABLE” basis at the time of record harvesting from the data source. Suggestions for further amendments or supplementary information can be sent to <a href="mailto:[email protected]">[email protected]</a>.

Funding

The author was supported by a grant from CityU (Project No. 7001959).

Fingerprint

Dive into the research topics of 'Formal analysis and systematic construction of two-factor authentication scheme'. Together they form a unique fingerprint.

Cite this