In 2006, Peyravian and Jeffries presented secure remote user access over insecure network. There exists a problem which isn?t resistant against off-line password-guessing attack in Diffie-Hellman Peyravian-Jeffries (DH-PJ) scheme of their paper. Similarly, password change protocol isn?t resistant against Denial-of-Service attack. Therefore, we shall present schemes to overcome above two attacks. We deliver original value with exclusion-or operation, and make originally exposed value unable to let the assailant know, improved the original method. In this thesis, the proposed technique can increase the system?s security and achieve the goal of promoting the system safely.