Improvement of Das's Two-Factor Authentication Protocol in Wireless Sensor Networks

Improvement of Das's Two-Factor Authentication Protocol in Wireless Sensor Networks
复制标题

DOI:
--
复制
发表时间:
2009
期刊:
IACR Cryptol. ePrint Arch.
影响因子:
--
通讯作者:
Daehun Nyang;Mun-Kyu Lee
Daehun Nyang;Mun-Kyu Lee
中科院分区:
其他
文献类型:
--
作者:
Daehun Nyang;Mun-Kyu Lee

文献摘要

被引文献

相似文献

用户认证是无线传感器网络中实现个性化服务和特权访问控制的关键。2009年,Das提出了一种新的无线传感器网络双因素认证方案,其中用户必须证明拥有密码和智能卡。他的计划是精心设计的传感器节点,通常具有有限的资源,在这个意义上,其认证过程不需要公钥操作,但它只利用加密哈希函数。在这封信中,我们指出,Das的协议是容易受到离线密码猜测攻击,并提出了一个对策,以克服漏洞,而不牺牲任何效率和可用性。除了补丁,我们提出了一种方法来保护查询响应消息从无线传感器节点到用户,这是必要的,在一个机密和真实的方式服务于用户。
User authentication is essential for customized services and privileged access control in wireless sensor network. In 2009, Das proposed a novel two-factor authentication scheme for wireless sensor network, where a user must prove the possession of both a password and a smart card. His scheme is well-designed for sensor nodes which typically have limited resources in the sense that its authentication procedure requires no public key operations but it utilizes only cryptographic hash function. In this letter, we point out that Das’s protocol is vulnerable to an offline password guessing attack, and also show a countermeasure to overcome the vulnerability without sacrificing any efficiency and usability. Besides the patch, we suggest a method to protect query response messages from wireless a sensor node to a user, which is necessary in serving a user in a confidential and authentic way.