Yet another attack on a QR-based password authentication system

In 1988, Laih, Harn, and Huang proposed a password authentication scheme using quadratic residues (QR). In 1995, Chang, Wu, and Laih showed that the proposed password authentication scheme is suffered from an attack, where the attacker needs to apply to the system for four valid accounts, and then the desired password corresponding to an identity can be easily obtained. We propose another more effective attack and we show that only one extra valid account is needed in our new attack.