Abstract
Recently, Yang et al. proposed a smart card and password–based mutual authentication scheme under trusted computing, and they claimed that their scheme can resist kinds of attacks. But they did not consider the stolen smart card attack which is an important attack in smart card–based authentication scheme. In this paper, we first analyse the stolen smart card attack to Yang et al.'s scheme, and then propose an enhanced mutual authentication scheme for trusted computing. Our scheme can resist the stolen smart card attack and other attacks, and can quickly detect the unauthorised login at the beginning when the user input the wrong identity or wrong password.