A password authentication scheme with secure password updating

Chun Li Lin, Tzonelih Hwang

Recently, Hwang and Yeh proposed an improvement on the Peyravian-Zunic password scheme. The Hwang-Yeh scheme comprises a password authentication protocol, a password change protocol, and can also provide key distribution. Though the Hwang-Yeh scheme repaired several security problems of the Peyravian-Zunic scheme, it has several security problems: the password change protocol in the Hwang-Yeh scheme is vulnerable to a denial of service attack; and it does not provide the forward secrecy property in session key distribution. Furthermore, we shall fix the Hwang-Yeh scheme to avoid these problems.

Original languageEnglish
Pages (from-to)68-72
Number of pages5
JournalComputers and Security
Issue number1
Publication statusPublished - 2003

