JOURNAL ARTICLE

Remarks on fingerprint-based remote user authentication scheme using smart cards

Chin‐Chen ChangIuon‐Chang Lin

Year: 2004 Journal:   ACM SIGOPS Operating Systems Review Vol: 38 (4)Pages: 91-96   Publisher: Association for Computing Machinery

Abstract

In 2002, Lee, Ryu, and Yoo proposed a fingerprint-based remote user authentication scheme using smart cards. The scheme makes it possible for authenticating the legitimacy of each login user without any password table. In addition, the authors claimed that the scheme can withstand message replay attack and impersonation. In this paper, we shall point out a security flaw in this scheme, that is, <i>n</i> legitimate users can conspire to forge 2<sup><i>n</i></sup>-<i>n</i>-1 valid IDs and PWs for successfully passing the system authentication. Furthermore, we also show that the authentication equation is incorrect. Thus, the scheme is unworkable.

Keywords:
Computer science Password Scheme (mathematics) Login Computer security Authentication (law) Smart card Replay attack Fingerprint (computing) Computer network Mathematics

Metrics

56
Cited By
3.16
FWCI (Field Weighted Citation Impact)
9
Refs
0.92
Citation Normalized Percentile
Is in top 1%
Is in top 10%

Citation History

Topics

User Authentication and Security Systems
Physical Sciences →  Computer Science →  Information Systems
Advanced Authentication Protocols Security
Physical Sciences →  Computer Science →  Computer Networks and Communications
Biometric Identification and Security
Physical Sciences →  Computer Science →  Signal Processing
© 2026 ScienceGate Book Chapters — All rights reserved.