Chenyu Wang 0002

dblp:98/10212-2 · DBLP profile ↗
← Back
23ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0002-6527-2897ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 1 first-author · 8 since 2021Security and privacy · 7 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 AttnSafe: Detecting Potential Backdoors for LLM via Attention Anomaly Analysis
Leyao Bao, Xinran Mao, Shao-Yong Guo 0001, Chenyu Wang 0002, Xuesong Qiu 0001
ICIC (24)5
2026 Federated Graph Neural Network for Real-Time Distributed Monitoring System Against Illicit Blockchain Transaction Accounts
abstract
The anonymity and decentralization of blockchain facilitate illicit blockchain transactions, while the dispersed computing resources in IoT(Internet of Things) scenarios pose challenges like insufficient high-dimensional feature processing capability, poor unknown anomaly detection, and high model update costs for identifying illicit accounts. To address these issues, we propose FLTG-Double GAT, a dedicated monitoring method for decentralized resource scenarios. It aggregating multi-party knowledge to enable cross-organizational detection of illicit transaction, while protecting data privacy by only uploading detection model parameter. It adopt a customized feature extraction paradigm combining double GAT and PCA balances deep feature mining and efficiency, enabling high-precision modeling on edge devices. At the same time, a GRU-driven real-time update mechanism is used. This realizes lightweight adaptation of the detection model to dynamic transactions and enhances early warning capability. Experiments on the Elliptic++ dataset show it achieves 99.80% detection recall and 99.28% prediction recall with low computational complexity, verifying its scalability and practical value in large-scale distributed blockchain monitoring systems.
Shao-Yong Guo 0001, Chenyu Wang 0002, Feng Qi 0004
IEEE Internet Things J.4
2025 A Provably Secure Authentication Protocol Based on PUF and ECC for IoT Cloud-Edge Environments
abstract
The Internet of Things (IoT) cloud model provides an efficient scheme for rapid collection, storage, processing, and analysis of massive node data, and its application has gradually expanded to key areas such as healthcare and transportation. However, the security issues of open channel transmission in IoT still persist. Researchers have proposed a lot of solutions, but the forward secrecy, session key security, and other aspects have not been effectively solved. This paper proposes a provably secure authenticated key agreement scheme, which constructs a secure channel between endpoint, gateway, and cloud server (CS). Compared with other schemes, this scheme has three characteristics: (1) According to the different computing resources of devices, gateways and CSs, a segmented differential authentication and secret key negotiation protocol is designed by using cryptographic primitives with different computing overheads; (2) after verification with the ProVerif tool, rigorous proof with the real‐or‐random (ROR) model, and informal analysis, the protocol has been proven to be secure, effectively guarding against typical threats; and (3) compared with the five most recent schemes, it can be seen that the protocol is at least 35% superior to other schemes in endpoint computational overhead, and it meets 10 security objectives, making it very suitable for application scenarios where endpoint resources are limited.
Guosheng Xu 0001, Chenyu Wang 0002, Jinwen Xi, Guoai Xu
IET Inf. Secur.3
2025 Blockchain Heterogeneous Network Authentication Scheme Based on Batch Verification Group Signature
abstract
The application of blockchain technology in the field of wireless communication authentication is becoming more and more widespread. The adoption of blockchain access schemes with composite security features is an important research direction in the current wireless access field. Meanwhile, the authentication scheme needs to reduce the process steps and improve the efficiency on the basis of protecting the identity privacy of the access device. In this article, with identity-based cryptography (IBC) as the core, a group signature algorithm supporting batch verification is constructed. Meanwhile, the proposed algorithm is the main component to design a blockchain-based heterogeneous network authentication scheme. Through security analysis, it is proved that the group signature algorithm can carry out multiuser batch authentication under the conditions of unforgeability, anonymity, and unlinkability. And through efficiency analysis, it can be seen that the authentication scheme can significantly reduce the number of pairwise operations in multiuser authentication, thus improving the efficiency of the authentication scheme by nearly 30.7%.
Juliang Cai, Xiaofeng Tao 0001, Chenyu Wang 0002
IEEE Internet Things J.3
2025 Statistical Fault Attacks on ASCON Using Improved Square Euclidean Imbalance
abstract
In current environment of frequent information exchange between Internet of Things (IoT) devices, traditional cryptographic algorithms often fail to effectively play a role in resource-limited electronic devices, which highlights the importance of lightweight cryptographic algorithms. NIST has completed the standardization process of lightweight cryptographic algorithms, and ASCON has become the ultimate winner. It is foreseeable that its application demand will continue to grow in the future, so the security analysis for ASCON is of significant value. Among various cryptographic algorithm analysis methods, fault attack is an efficient choice. Currently, there are also some fault attack methods for ASCON, but they share a common issue: their time complexity is too high for practical application. In view of this, this article proposes a more efficient fault attack method for ASCON, including several key points: First, several new statistical scoring function are constructed based on square euclidean imbalance (SEI). Second, a single S-box fault model is proposed to reduce the complexity of injection. Lastly, the complete key is recovered by combining statistical ineffective fault attack (SIFA), statistical effective fault attack (SEFA), and statistical hybrid fault attack (SHFA). The time complexity is$2^{16.57}$,$2^{14.91}$, and$2^{14.52}$, respectively. Experimental results on a Python implementation of ASCON, the results show that our scheme significantly reduces the time complexity of attacks, which can provide warnings for cryptography design and applications, and pay more attention to avoiding such risks.
Guosheng Xu 0001, Yuque Zhang, Chenyu Wang 0002, Guoai Xu
IEEE Internet Things J.4
2025 PUF-Based Lightweight Group Authentication for Massive IoT Access With Insecure Channel
abstract
The massive access in Internet of Things (IoT) introduces significant communication and computation overheads. Besides, the widespread IoT terminals placed in unattended area and with limited capabilities are vulnerable to various attacks such as physical attack. To alleviate the huge communication and computation overheads and to resist physical attacks, we propose a physically unclonable function (PUF)-based group authentication protocol in this paper, where a pre-stored PUF challenge scheme with PUF acting as the root key is proposed to limit the size of signalings in a group. Different from existing work with assumptions on secure communication channels and trusted group leader (GL), we consider untrusted GL and insecure communication channels among the device, the GL, and the home network (HN) and propose a simplified PUF-based device-to-device authentication scheme to perform mutual authentication and key sharing between the devices and the untrusted GL. Finally, the proposed protocol is evaluated with formal security analysis, where a novel threat model is presented for the physical attacker to overhear the secret in device’s memory. Results show that the proposed protocol can achieve desired authentication and confidentiality goals even the GL is under physical attacks and the communication channels are insecure. Further, simulations are demonstrated to show the outperformance of the proposed protocol in communication overhead, computation overhead, and security, compared with baseline solutions.
Huici Wu, Xiaofeng Tao 0001, Zhiqing Wei, Chenyu Wang 0002, Hui Li 0070
IEEE Internet Things J.5
2024 A robust and effective 3-factor authentication protocol for smart factory in IIoT
Shihong Zou, Qiang Cao 0006, Ruichao Lu, Chenyu Wang 0002, Guoai Xu, Huanhuan Ma, Yingyi Cheng, Jinwen Xi
Comput. Commun.4
2024 Anti-Quantum Certificateless Group Authentication for Massive Accessing IoT Devices
abstract
Internet of Things (IoT) is one of the most representative application scenarios in the 5G and 6G era. The concurrent access of massive IoT devices definitely poses enormous communication, computation, and certificate management challenges to the wireless authentication. Moreover, the emergence of quantum computing makes classical cryptography-based authentication protocols, such as 5G-AKA, more easier to be broken. Facing the challenges posed by the massive concurrent authentication and quantum attacks, this paper proposes a lattice cryptography based group authentication scheme, where lattice-based aggregate signature algorithm and identity-based encryption (IBE) are leveraged to achieve simultaneous authentication of concurrent accessed devices. The proposed authentication scheme eliminates the process of public key certificate management, greatly reducing the storage overhead of core network. Moreover, the utilization of lattice cryptography enables the resistance of quantum attacks. The proposed solution does not rely on additional security assumptions such as security channel or trusted group center, making it more flexible to be deployed in actual network scenario. Finally, formal security analysis of the proposed protocol is provided with the tool ProVerif. It is demonstrated that the proposed protocol can satisfy the goals of identity privacy, authentication, data confidentiality and forward secrecy. In addition, compared with existing advanced solutions, the outperformance of the proposed scheme in terms of computation overhead, signaling overhead, communication overhead, and security properties is validated with simulations.
Pengbo Xu, Huici Wu, Xiaofeng Tao 0001, Chenyu Wang 0002, Dajiang Chen, Guoshun Nan
IEEE Internet Things J.4
2024 A Physician's Privacy-Preserving Authentication and Key Agreement Protocol Based on Decentralized Identity for Medical Data Sharing in IoMT
abstract
As well known, Internet of medical things (IoMT) produces large amounts of medical data and promotes the medical data sharing which serves the data user (i.e., physicians) to boost the clinical treatment and medical research. To protect data user’s privacy and data security during the sharing of medical data, data user must have a self-sovereign decentralized identity (DID) and data access authority. In existing solutions, data user’s privacy protection and authenticated-key-agreement (AKA) for protecting data security are worked independently, which easily results in typical security attacks (e.g., phishing inquiry attacks, ephemeral secret leakage attacks) during data access and system computing overload. To solve the challenge, a new credential-embedded authentication and key agreement scheme (CAKA) is proposed, which can seamlessly combine DID-credentials into AKA. First, CAKA supports bilateral authentication by allowing a digital user to authenticate its service provider, which can enhance the security of unilateral scheme (such as CanDID, IEEE S&P, 2021) and prevent phishing query attacks. Second, for secure data session communication, the user’s DID-credentials are used as the kernel of the session key (SK) generation. In security analysis and performance metrics comparisons, the results indicate that CAKA holds a significant advantage, especially, the storage costs, communication costs and computation costs consumed in CAKA are at least 43% reduction, compared to alternatives. In simulation experiments of CAKA, the results show that decentralized identity authentication and session key agreement are both less than 15 ms, that means CAKA is a practical and promising solution to medical data sharing.
Shihong Zou, Qiang Cao 0006, Chonghui Huangqi, Anpeng Huang, Yanping Li 0001, Chenyu Wang 0002, Guoai Xu
IEEE Internet Things J.6
2023 Tree-IDS: An Incremental Intrusion Detection System for Connected Vehicles
abstract
The rapid development of Internet of Vehicles technology has led to the continuous upgrading of the functions of connected vehicles. While connected vehicles bring convenience to people’s life, there are also many security threats. Connected vehicles not only have intra-vehicle networks communication, but also communicate with the external network. The diversity of communication methods makes the attack surface wider, and some new attacks are constantly emerging. In order to ensure vehicle security, This paper focuses on the attacks that are vulnerable to vehicles, and proposes an incremental intrusion detection system, which can not only detect attacks, but also incrementally learn new types of attacks. Experimental results illustrate that the proposed system can incrementally learn new attacks and avoid catastrophic forgetting problems, and can detect various types of known attacks with 99.99% accuracy on the Car-Hacking Dataset and 99.37% accuracy on the CICIDS2017.
Zixiang Bi, Guosheng Xu 0001, Chenyu Wang 0002, Guoai Xu
LCN4
2023 Secure and Lightweight User Authentication Scheme for Cloud-Assisted Internet of Things
abstract
Cloud-assisted Internet of Things (IoT) overcomes the resource-constrained nature of the traditional IoT and is developing rapidly in such fields as smart grids and intelligent transportation. In a cloud-assisted IoT system, users can remotely control the IoT devices and send specific instructions to them. If the users’ identities are not verified, adversaries can pretend as legitimate users to send fake and malicious instructions to IoT devices, thereby compromising the security of the entire system. Thus, a sound authentication mechanism is indispensable to ensure security. At the same time, it should be noted that a gateway may connect to massive IoT devices with the exponential growth of interconnected devices in a cloud-assisted IoT system. The efficiency of authentication schemes is easily impacted by the computation capability of the gateway. Recently, several schemes have been designed for cloud-assisted IoT systems, but they have problems of one kind or another, making them not very suitable for cloud-assisted IoT systems. In this paper, we take a typical scheme (proposed at IEEE TDSC 2020) as an example to identify the common weaknesses and challenges of designing a user authentication scheme for cloud-assisted IoT systems. In addition, we propose a new secure user authentication scheme with lightweight computation on gateways. The proposed scheme provides secure access between remote users and IoT devices with many ideal attributions, such as forward secrecy and multi-factor security. Meanwhile, the security of this scheme is proved under the random-oracle model, heuristic analysis, the ProVerif tool and BAN logic. Compared with ten state-of-the-art schemes in security and performance, the proposed scheme achieves all the listed twelve security requirements with minimum computation and storage costs on gateways.
Chenyu Wang 0002, Ding Wang 0002, Yihe Duan, Xiaofeng Tao 0001
IEEE Trans. Inf. Forensics Secur.1
2022 Demystifying the underground ecosystem of account registration bots
abstract
Member services are a core part of most online systems. For example, member services in online social networks and video platforms make it possible to serve users customized content or track their footprint for a recommendation. However, there is a dark side to membership that lurks behind influencer marketing, coupon harvesting, and spreading fake news. All these activities rely heavily on owning masses of fake accounts, and to create new accounts efficiently, malicious registrants use automated registration bots with anti-human verification services that can easily bypass a website’s security strategies.
Yuhao Gao, Guoai Xu, Li Li 0029, Xiapu Luo, Chenyu Wang 0002, Yulei Sui
ESEC/SIGSOFT FSE5
2022 Efficient privacy-preserving user authentication scheme with forward secrecy for industry 4.0
Chenyu Wang 0002, Ding Wang 0002, Guoai Xu, Debiao He
Sci. China Inf. Sci.1
2022 A new efficient hierarchical multi-secret sharing scheme based on linear homogeneous recurrence relations
Jiangtao Yuan, Jing Yang 0035, Chenyu Wang 0002, Xingxing Jia, Fang-Wei Fu 0001, Guoai Xu
Inf. Sci.3
2022 A novel model for voice command fingerprinting using deep learning
abstract
Smart speakers are becoming increasingly popular and permeate many aspects of human life. To improve the security of smart speakers, voice commands transmitted over a network are encrypted; however, user privacy issues related to smart speakers continue to emerge. In fact, attackers are still able to infer the content of a user’s specific voice commands from encrypted traffic through machine learning methods to obtain private information for advertising or to carry out malicious attacks. This traffic analysis attack is referred to as a voice command fingerprinting attack. In recent years, research on improving the accuracy of voice command fingerprinting attacks has become a hot topic and remains a challenging task. To improve the accuracy of voice command fingerprinting attacks, we design a new method in this paper. We use an adaptive and dilated residual network to process spatial features. In addition, we find that using temporal features helps improve fingerprinting attack accuracy, and therefore design an attention-based bidirectional gated recurrent unit. Then, we effectively combine the two models. Our method achieves an accuracy greater than 93.36% in a closed-world scenario, which exceeds those of other state-of-the-art methods (2020 WiSec Wang et al.). In a more realistic open-world setting, our model is still effective, obtaining a true-positive rate of 99.50% and a false-positive rate of 0.1% compared to Sirinam et al.’s rates of 90.66% and 0.1%, respectively. We also demonstrate that our model has good generalizability, as our model can also be applied to website fingerprinting and outperforms 2018 CCS Sirinam et al.
Jianghan Mao, Chenyu Wang 0002, Guoai Xu, Shoufeng Cao, Xuanwen Zhang, Zixiang Bi
J. Inf. Secur. Appl.2
2022 Understanding Node Capture Attacks in User Authentication Schemes for Wireless Sensor Networks
abstract
Despite decades of intensive research, it is still challenging to design a practical multi-factor user authentication scheme for wireless sensor networks (WSNs). This is because protocol designers are confronted with a long-standing “security versus efficiency” dilemma: sensor nodes are lightweight devices with limited storage and computation capabilities, while the security requirements are demanding as WSNs are generally deployed for sensitive applications. Hundreds of proposals have been proposed, yet most of them have been found to be problematic, and the same mistakes are repeated again and again. Two of the most common security failures are regarding smart card loss attacks and node capture attacks. The former has been extensively investigated in the literature, while little attention has been given to understanding the node capture attacks. To alleviate this undesirable situation, this article takes a substantial step towards systematically exploring node capture attacks against multi-factor user authentication schemes for WSNs. We first investigate the various causes and consequences of node capture attacks, and classify them into ten different types in terms of the attack targets, adversary’s capabilities and vulnerabilities exploited. Then, we elaborate on each type of attack through examining 11 typical vulnerable protocols, and suggest corresponding countermeasures. Finally, we conduct a large-scale comparative measurement of 61 representative user authentication schemes for WSNs under our extended evaluation criteria. We believe that such a systematic understanding of node capture attacks would help design secure user authentication schemes for WSNs.
Chenyu Wang 0002, Ding Wang 0002, Guoai Xu, Huaxiong Wang
IEEE Trans. Dependable Secur. Comput.1
2020 Efficient Multi-Factor User Authentication Protocol with Forward Secrecy for Real-Time Data Access in WSNs
abstract
It is challenging to design a secure and efficient multi-factor authentication scheme for real-time data access in wireless sensor networks. On the one hand, such real-time applications are generally security critical, and various security goals need to be met. On the other hand, sensor nodes and users’ mobile devices are typically of a resource-constrained nature, and expensive cryptographic primitives cannot be used. In this work, we first revisit four foremost multi-factor authentication schemes (i.e., those of Amin et al. (JNCA’18), Srinivas et al. (IEEE TDSC’18), Li et al. (JNCA’18), and Li et al. (IEEE TII’18)) and use them as case studies to reveal the difficulties and challenges in designing a multi-factor authentication scheme for wireless sensor networks correctly. We identify the root causes for their failures in achieving truly multi-factor security and forward secrecy. We further propose a robust multi-factor authentication scheme that makes use of the imbalanced computational nature of the RSA cryptosystem, particularly suitable for scenarios where sensor nodes (but not the user’s device) are the main energy bottleneck. Comparison results demonstrate the superiority of our scheme. As far as we know, it is the first two-factor authentication scheme for real-time data access in WSNs that can satisfy all 12 criteria of the state-of-the-art evaluation metric under the harshest adversary model so far.
Ding Wang 0002, Ping Wang 0003, Chenyu Wang 0002
ACM Trans. Cyber Phys. Syst.3
2020 Security Analysis on "Anonymous Authentication Scheme for Smart Home Environment with Provable Security"
abstract
As an important application of the Internet of Things, smart home has greatly facilitated our life. Since the communication channels of smart home are insecure and the transmitted data are usually sensitive, a secure and anonymous user authentication scheme is required. Numerous attempts have been taken to design such authentication schemes. Recently, Shuai et al. (Computer & Security 86(2019):132146) designed an anonymous authentication scheme for smart home using elliptic curve cryptography. They claimed that the proposed scheme is secure against various attacks and provides ideal attributes. However, we show that their scheme cannot resist inside attack and offline dictionary attack and also fails to achieve forward secrecy. Furthermore, we give some suggestions to enhance the security of the scheme. These suggestions also apply to other user authentication schemes with similar flaws.
Meijia Xu, Qiying Dong, Mai Zhou, Chenyu Wang 0002
Wirel. Commun. Mob. Comput.4
2019 A Provably Secure Biometrics-Based Authentication Scheme for Multiserver Environment
abstract
With the rapid development of mobile services, multiserver authentication protocol with its high efficiency has emerged as an indispensable security mechanism for mobile services. Recently, Ali et al. introduced a biometric-based multiserver authentication scheme and claimed the scheme is resistant to various attacks. However, after a careful examination, we find that Ali et al.’s scheme is vulnerable to various security attacks, such as user impersonation attack, server impersonation attack, privileged insider attack, denial of service attack, fails to provide forward secrecy and three-factor secrecy. To overcome these weaknesses, we propose an improved biometric-based multiserver authentication scheme using elliptic curve cryptosystem. Formal security analysis under the random oracle model proves that our scheme is provably secure. Furthermore, BAN (Burrows-Abadi-Needham) logic analysis demonstrates our scheme achieves mutual authentication and session key agreement. In addition, the informal analysis proves that our scheme is secure against all current known attacks and achieves desirable features. Besides, the performance and security comparison shows that our scheme is superior to related schemes.
Guoai Xu, Chenyu Wang 0002, Junhao Peng
Secur. Commun. Networks3
2018 A New Approach to Security Analysis of Smart Home Authentication Systems
abstract
ZigBee networks, with their characteristics of high availability, low power consumption and cost-effective devices, are perfectly appropriate to construct Wireless Sensor Networks (WSNs). Also, the natures of WSN listed above bring significant benefits over traditional communication networks used i n smart home systems. A smart home system is meant to improve the quality of life through offering various automated, interactive and comfortable services, such as sensing and communicating the family member’s health information with their doctors, or remotely controlling the appliances via cellular phones, emails etc. These critical services make the security of personal privacy and the authority of control commands vital issues in Smart Home environments. While the smart home system suffer from many attacks, the security of the smart home system become an important and hard problem. And the authentication is the first parclose to the security of the system. However, according to our analysis, most system fail to achieve the authentication between the user and the device, Which leading to the compromise of the whole system. In this paper, we analyze the authentication challenges between the user the device in WSNs and in smart home Systems. To thoroughly detect, defense and foresee the authentication vulnerabilities existing in smart home networks, we proposed a security evaluation technique based on attack graph generation. We discuss the distinction between the attack graphs deployed in traditional networks and in smart home networks. Furthermore, we apply this technique into an experiment, and the results prove its practicality. And we then suggest a widely used protocol to the smart home authentication system.
Chenyu Wang 0002, Jiteng Wang, Si Tian
Fundam. Informaticae2
2018 A Secure and Anonymous Two-Factor Authentication Protocol in Multiserver Environment
abstract
With the great development of network technology, the multiserver system gets widely used in providing various of services. And the two-factor authentication protocols in multiserver system attract more and more attention. Recently, there are two new schemes for multiserver environment which claimed to be secure against the known attacks. However, after a scrutinization of these two schemes, we found that (1) their description of the adversary’s abilities is inaccurate; (2) their schemes suffer from many attacks. Thus, firstly, we corrected their description on the adversary capacities to introduce a widely accepted adversary model and then summarized fourteen security requirements of multiserver based on the works of pioneer contributors. Secondly, we revealed that one of the two schemes fails to preserve forward secrecy and user anonymity and cannot resist stolen-verifier attack and off-line dictionary attack and so forth and also demonstrated that another scheme fails to preserve forward secrecy and user anonymity and is not secure to insider attack and off-line dictionary attack, and so forth. Finally, we designed an enhanced scheme to overcome these identified weaknesses, proved its security via BAN logic and heuristic analysis, and then compared it with other relevant schemes. The comparison results showed the superiority of our scheme.
Chenyu Wang 0002, Guoai Xu, Wenting Li 0002
Secur. Commun. Networks1
2018 An Enhanced User Authentication Protocol Based on Elliptic Curve Cryptosystem in Cloud Computing Environment
abstract
With the popularity of cloud computing, information security issues in the cloud environment are becoming more and more prominent. As the first line of defense to ensure cloud computing security, user authentication has attracted extensive attention. Though considerable efforts have been paid for a secure and practical authentication scheme in cloud computing environment, most attempts ended in failure. The design of a secure and efficient user authentication scheme for cloud computing remains a challenge on the one hand and user’s smart card or mobile devices are of limited resource; on the other hand, with the combination of cloud computing and the Internet of Things, applications in cloud environments often need to meet various security requirements and are vulnerable to more attacks. In 2018, Amin et al. proposed an enhanced user authentication scheme in cloud computing, hoping to overcome the identified security flaws of two previous schemes. However, after a scrutinization of their scheme, we revealed that it still suffers from the same attacks (such as no user anonymity, no forward secrecy, and being vulnerable to offline dictionary attack) as the two schemes they compromised. Consequently, we take the scheme of Amin et al. (2018) as a study case, we discussed the inherent reason and the corresponding solutions to authentication schemes for cloud computing environment in detail. Next, we not only proposed an enhanced secure and efficient scheme, but also explained the design rationales for a secure cloud environment protocol. Finally, we applied BAN logic and heuristic analysis to show the security of the protocol and compared our scheme with related schemes. The results manifest the superiority of our scheme.
Chenyu Wang 0002, Guoai Xu, Ping Wang 0003
Wirel. Commun. Mob. Comput.1
2017 Cryptanalysis of Three Password-Based Remote User Authentication Schemes with Non-Tamper-Resistant Smart Card
abstract
Remote user authentication is the first step to guarantee the security of online services. Online services grow rapidly and numerous remote user authentication schemes were proposed with high capability and efficiency. Recently, there are three new improved remote user authentication schemes which claim to be resistant to various attacks. Unfortunately, according to our analysis, these schemes all fail to achieve some critical security goals. This paper demonstrates that they all suffer from offline dictionary attack or fail to achieve forward secrecy and user anonymity. It is worth mentioning that we divide offline dictionary attacks into two categories: (1) the ones using the verification from smart cards and (2) the ones using the verification from the open channel. The second is more complicated and intractable than the first type. Such distinction benefits the exploration of better design principles. We also discuss some practical solutions to the two kinds of attacks, respectively. Furthermore, we proposed a reference model to deal with the first kind of attack and proved its effectiveness by taking one of our cryptanalysis schemes as an example.
Chenyu Wang 0002, Guoai Xu
Secur. Commun. Networks1