Remarks on fingerprint-based remote user authentication scheme using smart cards

Abstract

In 2002, Lee, Ryu, and Yoo proposed a fingerprint-based remote user authentication scheme using smart cards. The scheme makes it possible for authenticating the legitimacy of each login user without any password table. In addition, the authors claimed that the scheme can withstand message replay attack and impersonation. In this paper, we shall point out a security flaw in this scheme, that is, <i>n</i> legitimate users can conspire to forge 2<sup><i>n</i></sup>-<i>n</i>-1 valid IDs and PWs for successfully passing the system authentication. Furthermore, we also show that the authentication equation is incorrect. Thus, the scheme is unworkable.

DOI: 10.1145/1031154.1031165

Extracted Key Phrases

02040'06'07'08'09'10'11'12'13'14'15'16'17
Citations per Year

141 Citations

Semantic Scholar estimates that this publication has 141 citations based on the available data.

See our FAQ for additional information.

Cite this paper

@article{Chang2004RemarksOF, title={Remarks on fingerprint-based remote user authentication scheme using smart cards}, author={Chin-Chen Chang and Iuon-Chang Lin}, journal={Operating Systems Review}, year={2004}, volume={38}, pages={91-96} }