Abstract
In an open networking environment, a server usually needs to identify its legal users for providing its services. In 2006, Shieh and Wang pointed out the weakness of Juang's remote mutual authentication scheme using smart card and further proposed an efficient remote mutual authentication and key agreement scheme using smart card. Recently, Yoon and Yoo demonstrated that Shieh and Wang's scheme does not provide perfect forward secrecy and is vulnerable to a privileged insider's attack. In this paper, we propose a security improvement to resolve the security problems. The proposed scheme not only inherits the merits of their scheme but also enhances the security of their scheme. © 2009 Springer-Verlag Berlin Heidelberg.