The present authentication scheme has been found to be vulnerable to forged login attack; an intruder could still impersonate legitimate users to login and accesses the remote server in two ways at least. To solve this problem, an improved scheme will be proposed, which can withstand the existing forged attacks by means of improving the security policy and authentication information. The security analysis showed that the improved scheme still keeps the features of the non storage data model authentication scheme and will not add the additional computation cost to the smart card, and will perform better in security and practical operations.