Password Protected Smart Card and Memory Stick Authentication Against Off-line Dictionary Attacks
Yongge Wang

TL;DR
This paper analyzes security protocols for password-based authentication with smart cards and memory sticks, focusing on preventing impersonation even if devices are stolen or passwords are weak, ensuring robust offline attack resistance.
Contribution
It introduces a new authentication framework that secures smart cards and portable devices against offline dictionary attacks and impersonation, even when devices are stolen or untrusted readers are used.
Findings
Proposes a protocol resistant to offline dictionary attacks.
Ensures smart card and device theft do not compromise security.
Extends security measures to portable storage devices.
Abstract
In this paper, we study the security requirements for remote authentication with password protected smart card. In recent years, several protocols for password-based authenticated key exchange have been proposed. These protocols are used for the protection of password based authentication between a client and a remote server. In this paper, we will focus on the password based authentication between a smart card owner and smart card via an untrusted card reader. In a typical scenario, a smart card owner inserts the smart card into an untrusted card reader and input the password via the card reader in order for the smart card to carry out the process of authentication with a remote server. In this case, we want to guarantee that the card reader will not be able to impersonate the card owner in future without the smart card itself. Furthermore, the smart card could be stolen. If this…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Authentication Protocols Security · Biometric Identification and Security
