In 2002, Fan et al. showed that Yang and Shieh's timestamp-based password authentication scheme is not secure and also proposed an improvement. Later, Wang et al. indicated that the improved version is still insecure, and they also presented another attack. They claimed that their proposed attack can have the attacker construct a valid but forged login request with a non-negligible probability. However, attackers cannot mount Wang et al.'s attack successfully in fact. In this paper, we will show why Wang et al.'s attack cannot work.
Relation:
Journal of Discrete Mathematical Sciences & Cryptography 9(3):549-555