It is proved that the MY-key authentication scheme proposed by (Horng and Y
ang, Computer Communications 19 (1996) 848-850) is vulnerable to the guessi
ng attack (Li et al., IEEE Journal on Selected Areas in Communications 11 (
5) (1993)). The user's password is obtained by the guessing attack, and the
n the user's public key can be forged or the user's private key can be reco
vered. In order to overcome this disadvantage, we propose a new improved MY
-scheme. The attacker cannot recover the user's private key, even though he
has obtained the user's password. (C) 1999 Elsevier Science B.V. All right
s reserved.