Binary Information Press
Two-factor anonymous authentication using password and smart card could preserve user privacy and reduce the risk than the use of a single authentication factor. Recently, the researcher pointed some security weaknesses in the researcher anonymous authentication scheme and proposed enhanced scheme. They claimed that their scheme provides desired security properties. However, the authors show that Chang et al.'s scheme is still vulnerable to the off-line dictionary attack and denial of service attacks. To resist these attacks, they propose an improved two-factor authentication and key agreement scheme with user anonymity.