Recently, Shen, Lin, and Hwang proposed a modified Yang-Shieh's password authentication scheme to enhance security. In 2004, Yang and Chen et al. point out that Shen-Lin-Hwang's scheme was vulnerable to the forged login attack. Later, Wang and Li present a new efficient timestamp-based remote user authentication scheme via further modified Shen-Lin-Hwan's scheme. And they also claimed that their new modified scheme could withstand the forged login attack. However, in this paper, we show that the Yang and Li's improvement scheme is still vulnerable to the reflection attack, and propose our improvement scheme
Published in:
Communications, Circuits and Systems Proceedings, 2006 International Conference on
(Volume:3
)
Date of Conference: 25-28 June 2006