160 likes | 277 Views
Efficient Password authenticated key agreement using smart cards Author : Wen-Shenq Juang* Date : 2003.11.26 in Computers & Security. 90321011 孫國偉. Introduction:. What is the smart card What does it must to have merits Review Chien et al.s(2002) Our protocol Security analysis.
E N D
Efficient Password authenticatedkey agreement using smart cards Author : Wen-Shenq Juang* Date : 2003.11.26 in Computers & Security 90321011 孫國偉
Introduction: • What is the smart card • What does it must to have merits • Review Chien et al.s(2002) • Our protocol • Security analysis
Main merits: No verification table: ID1 PW1 ID2 PW2 ID3 PW3 . . . User Server
Main merits: Freely chosen password: Users can feely choose Their own passwords
Main merits: Lower communication and computation cost: They may not provide a powerful computation capability and high bandwidth
Main merits: Mutual authentication: Users and servers can authenticate each other
Review Chien et al.s(2002) • The registration phase • The login phase • The verification phase
The registration phase ID = identity PW= password x = server’s secret key Smart Card Server User
The login phase T = current timestamp Card Reader Smart Card Server
The verification phase Reject Server User
The drawbacks • Time-synchronization problem user’s time and server’s time must differ only in small range • No provide key agreement
Our protocol • Registration phase • Login and session key agreement phase
The registration phase ID = identity PW= password x = server’s secret key Smart Card Server User