An Estimated Model of Risk Analysis of Attacks on Smart Card Authentication Schemes
نویسندگان
چکیده
With the rapid growth of computer networks, more and more users access the remote server’s service in a distributed computing environment. Due to the fast development of the Internet and wireless communications, many activities like online-shopping, online banking, online voting are conducted over it. Authentication is one of the essential security features of network communication. The authentication process ascertains the legitimacy of the communicating partners in communication. In the authentication procedure, the promoter of the communication and the defendant derives some identification codes of each other prior to start of the message transaction. Sundry methods have been introduced regarding the authentication process from time to time. The static approach authentication schemes are vulnerable to different types of attacks. The growth of smart card systems faces security threats to both the card and its environment. Issues related to readers, protocol implementations, the smart card’s hardware security features or a combination of logical and physical attacks is of legitimate concern. All the elements of a smart card system have their own specific behavior. They could be attacked in various ways. In this paper we analyze the smart card attacks through a noncyclic attack graph. Noncyclic attack graphs provide an intuitive aid in threat analysis. We dissert that such a formal interpretation is indispensable to precisely understand how noncyclic attack graphs can be framed up during design and analysis. We provide an educational semantics, based on a mapping to attack stack, which abstracts from the internal structure of a Noncyclic attack graph, we study transformations between Noncyclic attack graphs, and we study the attribution and the projection of a Noncyclic attack graph. General Terms: Smart Card, Attack Graph, Security.
منابع مشابه
Comparative Analysis of Smart Card Authentication Schemes
Various kinds of authentication schemes have been deployed to secure the information or resources from unauthorized access. In these schemes, server maintains a verification table which is vulnerable to a variety of attacks. To withstand the possible attacks for verification table, smart card based authentication scheme has been proposed as an alternative solution. Smart card is a small, tamper...
متن کاملRemote User Authentication Schemes: A Review
To secure the resources or information from illegitimate users various kinds of authentication schemes have been designed and developed. Some of these schemes are vulnerable to a variety of attacks. In last decade authentication schemes based on smart card has been proposed to withstand the possible attacks on verification table. Smart card provides a convenient storage and processing capabilit...
متن کاملEfficient and Anonymous Two-Factor User Authentication in Wireless Sensor Networks: Achieving User Anonymity with Lightweight Sensor Computation
A smart-card-based user authentication scheme for wireless sensor networks (hereafter referred to as a SCA-WSN scheme) is designed to ensure that only users who possess both a smart card and the corresponding password are allowed to gain access to sensor data and their transmissions. Despite many research efforts in recent years, it remains a challenging task to design an efficient SCA-WSN sche...
متن کاملTwo - factor Authentication Schemes Based Smart Card and Password with User Anonymity ⋆
Two-factor anonymous authentication using password and smart card could preserve user privacy and reduce the risk than the use of a single authentication factor. Recently, Chang et al. pointed some security weaknesses in Wang et al.’s anonymous authentication scheme and proposed enhanced scheme. They claimed that their scheme provides desired security properties. However, we show that Chang et ...
متن کاملSecure Password-based Remote User Authentication Scheme Against Smart Card Security Breach
It is a challenge for password authentication protocols using non-tamper resistant smart cards to achieve user anonymity, forward secrecy, immunity to various attacks and high performance at the same time. In 2011, Li and Lee showed that both Hsiang-Shih’s password-based remote user authentication schemes are vulnerable to various attacks if the smart card is non-tamper resistant. Consequently,...
متن کامل