2013/09/20 by Dheerendra Mishra, Mishra, Dheerendra, Sourav Mukhopadhyay +1
Computer Science · #Advanced Authentication Protocols Security #Cryptography and Data Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #User Authentication and Security Systems #cs.CR
paper · pdf · doi:10.48550/arxiv.1309.5255
arxiv created 2013/09/20 · openalex publication_date 2013/09/20 · arxiv updated 2013/09/23 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Remote user authentication is desirable for a Telecare medicine information system (TMIS) to verify the correctness of remote users. In 2013, Jiang et al. proposed privacy preserving authentication scheme for TMIS. Recently, Wu and Xu analyzed Jiang's scheme and identify serious security flaws in their scheme, namely, user impersonation attack, DoS attack and off-line password guessing attack. In this article, we analyze Wu and Xu's scheme and show that their scheme is also vulnerable to off-line password guessing attack and does not protect user anonymity. Moreover, we identify the inefficiency of incorrect input detection of the login phase in Wu and Xu's scheme, where the smart card executes the login session in-spite of wrong input.