| Previous | [ 1] | [ 2] | [ 3] | [ 4] | [ 5] | [ 6] | [ 7] | [ 8] | [ 9] | [ 10] | [ 11] | [ 12] | [ 13] | [ 14] | [ 15] |
¡@
Wei-Chi Ku and Hui-Lung Lee+
Department of Computer Science and Information Engineering
Fu Jen Catholic University
Taipei, 242 Taiwan
E-mail: wcku@csie.fju.edu.tw
+Department of Computer and Information Science
National Chiao Tung University
Hsinchu, 300 Taiwan
In 1999, Hoover and Kausik introduced a software token using the cryptographic
camouflage technique and claimed that it can resist various on-line and off-line guessing
attacks. Later, Kwon presented an authentication protocol based on the cryptographic
camouflage technique and DSA, and pointed out that this initial protocol is vulnerable to
an impersonation attack once a server¡¦s secret key or private key is compromised. Then,
Kwon proposed a modified version that can resist such an impersonation attack by cryptographically
embedding the recipient¡¦s identity in the user¡¦s signature to ensure that
only the intended recipient will accept this signature. However, we find that Kwon¡¦s
modified protocol still has some drawbacks. In this paper, we first demonstrate the
drawbacks of Kwon¡¦s modified protocol and then propose an improved authentication
protocol based on the cryptographic camouflage technique and RSA. Finally, we show
that our improved protocol can provide prefect forward secrecy and can resist the
off-line guessing attack, the impersonation attack, the replay attack, and the Denning-
Sacco attack. Furthermore, the resistance of our improved protocol to the modification
attack is also enhanced by additionally using credit-card sized CD-ROMs.
Received January 2, 2004; revised July 9, 2004; accepted August 26, 2004.
Communicated by Chi-Sung Laih.
* This work was supported in part by the National Science Council of Taiwan, R.O.C., under grant No. NSC
92-2213-E-030-013.