{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,28]],"date-time":"2025-09-28T04:14:04Z","timestamp":1759032844572,"version":"3.41.0"},"reference-count":10,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2005,1,1]],"date-time":"2005-01-01T00:00:00Z","timestamp":1104537600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["SIGOPS Oper. Syst. Rev."],"published-print":{"date-parts":[[2005,1]]},"abstract":"<jats:p>In 2000, Peyravian and Zunic proposed an efficient hash-based password authentication scheme that can be easily implemented. Later, Lee, Li, and Hwang demonstrated that Peyravian-Zunic's scheme is vulnerable to an off-line guessing attack, and then proposed an improved version. However, Ku, Chen, and Lee pointed out that their scheme can not resist an off-line guessing attack, a denial-of-service attack, and a stolen-verifier attack. Recently, Yoon, Ryu, and Yoo proposed an improved scheme of Lee-Li-Hwang's scheme. Unfortunately, we find that Yoon-Ryu-Yoo's scheme is still vulnerable to an off-line guessing attack and a stolen-verifier attack. Furthermore, their scheme can not achieve backward secrecy. Herein, we first briefly review Yoon-Ryu-Yoo's scheme and then describe its weaknesses.<\/jats:p>","DOI":"10.1145\/1044552.1044561","type":"journal-article","created":{"date-parts":[[2005,11,7]],"date-time":"2005-11-07T19:28:32Z","timestamp":1131391712000},"page":"85-89","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":11,"title":["Weaknesses of Yoon-Ryu-Yoo's hash-based password authentication scheme"],"prefix":"10.1145","volume":"39","author":[{"given":"Wei-Chi","family":"Ku","sequence":"first","affiliation":[{"name":"Fu Jen Catholic University, Hsinchuang, Taipei County, Taiwan, R.O.C."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Min-Hung","family":"Chiang","sequence":"additional","affiliation":[{"name":"Fu Jen Catholic University, Hsinchuang, Taipei County, Taiwan, R.O.C."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shen-Tien","family":"Chang","sequence":"additional","affiliation":[{"name":"Fu Jen Catholic University, Hsinchuang, Taipei County, Taiwan, R.O.C."}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2005,1]]},"reference":[{"key":"e_1_2_1_1_1","first-page":"11","article-title":"Stolen-verifier attack on two new strong-password authentication protocols","volume":"58","author":"Chen C. M.","year":"2002","unstructured":"C. M. Chen and W. C. Ku , \" Stolen-verifier attack on two new strong-password authentication protocols ,\" IEICE Transactions on Communications , vol. E58 -B, no. 11 , pp. 2519--2521, Nov. 2002 .]] C. M. Chen and W. C. Ku, \"Stolen-verifier attack on two new strong-password authentication protocols,\" IEICE Transactions on Communications, vol. E58-B, no. 11, pp. 2519--2521, Nov. 2002.]]","journal-title":"IEICE Transactions on Communications"},{"key":"e_1_2_1_2_1","first-page":"4","article-title":"Improvement on Peyravian-Zunic's password authentication schemes","volume":"85","author":"Hwang J. J.","year":"2002","unstructured":"J. J. Hwang and T. C. Yeh , \" Improvement on Peyravian-Zunic's password authentication schemes ,\" IEICE Transactions on Communications , vol. E85 -B, no. 4 , pp. 823--825, April 2002 .]] J. J. Hwang and T. C. Yeh, \"Improvement on Peyravian-Zunic's password authentication schemes,\" IEICE Transactions on Communications, vol. E85-B, no. 4, pp. 823--825, April 2002.]]","journal-title":"IEICE Transactions on Communications"},{"key":"e_1_2_1_3_1","first-page":"5","article-title":"Cryptanalysis of a variant of Peyravian-Zunic's password authentication scheme","volume":"86","author":"Ku W. C.","year":"2003","unstructured":"W. C. Ku , C. M. Chen , and H. L. Lee , \" Cryptanalysis of a variant of Peyravian-Zunic's password authentication scheme ,\" IEICE Transactions on Communications , vol. E86 -B, no. 5 , pp. 1682--1684, May 2003 .]] W. C. Ku, C. M. Chen, and H. L. Lee, \"Cryptanalysis of a variant of Peyravian-Zunic's password authentication scheme,\" IEICE Transactions on Communications, vol. E86-B, no. 5, pp. 1682--1684, May 2003.]]","journal-title":"IEICE Transactions on Communications"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/958965.958967"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/583800.583803"},{"key":"e_1_2_1_6_1","first-page":"9","article-title":"Attacks and solutions on strong-password authentication","volume":"84","author":"Lin C. L.","year":"2001","unstructured":"C. L. Lin , H. M. Sun , and T. Hwang , \" Attacks and solutions on strong-password authentication ,\" IEICE Transactions on Communications , vol. E84 -B, no. 9 , pp. 2622--2627, Sept. 2001 .]] C. L. Lin, H. M. Sun, and T. Hwang, \"Attacks and solutions on strong-password authentication,\" IEICE Transactions on Communications, vol. E84-B, no. 9, pp. 2622--2627, Sept. 2001.]]","journal-title":"IEICE Transactions on Communications"},{"key":"e_1_2_1_7_1","unstructured":"National Institute of Standards and Technology \"Secure hash standard \" FIPS Publication 180-1 April 1995.]]  National Institute of Standards and Technology \"Secure hash standard \" FIPS Publication 180-1 April 1995.]]"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(00)05032-X"},{"key":"e_1_2_1_9_1","doi-asserted-by":"crossref","unstructured":"R. Rivest \"The MD5 message-digest algorithm \" RFC 1321 April 1992.]]   R. Rivest \"The MD5 message-digest algorithm \" RFC 1321 April 1992.]]","DOI":"10.17487\/rfc1321"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/991130.991135"}],"container-title":["ACM SIGOPS Operating Systems Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1044552.1044561","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/1044552.1044561","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T16:25:06Z","timestamp":1750263906000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/1044552.1044561"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2005,1]]},"references-count":10,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2005,1]]}},"alternative-id":["10.1145\/1044552.1044561"],"URL":"https:\/\/doi.org\/10.1145\/1044552.1044561","relation":{},"ISSN":["0163-5980"],"issn-type":[{"type":"print","value":"0163-5980"}],"subject":[],"published":{"date-parts":[[2005,1]]},"assertion":[{"value":"2005-01-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}