分析了刘聪等提出的一个具有匿名性的无线漫游认证协议,指出该方案无法实现匿名性,易遭受冒充攻击、离线字典攻击.提出了一种改进协议,分析表明改进后的协议不仅克服了刘聪等的协议的安全缺陷,而且保持了原有方案的优点.
Recently, Liu et al proposed an anonymous authentication scheme for roaming service in wireless networks. However, security analysis demonstrates that their scheme does not achieve user's anonymity, easily suffers from impersonation attack and offline password guessing attack. Then, an improved scheme is proposed, and our scheme not only overcomes these weaknesses but also keep the merits of the original scheme.