Recently, Wu and Hsu showed that Lee and Chang’s anonymous user identification and key establishment protocol was insecure
with regard to two attacks and proposed an improved protocol, called the WH protocol. In this paper, we show that the WH protocol
is still vulnerable to an unknown-key share attack. Then, we propose an improved protocol to address this problem by applying
a mutual authentication method.
This research was supported by the MIC (Ministry of Information and Communication), Korea, under the ITRC (Information Technology
Research Center) support program supervised by the IITA (Institute of Information Technology Assessment).