Recently, Lee, Ryu and Yoo proposed a fingerprint-based remote user authentication scheme by using smart cards and biometrics. Their scheme is based on two tiers of ElGamal's private key cryptosystem and fingerprint verification. The scheme is novel by introducing biometrics verification technology into authentication scheme using smart cards. In this paper, we point out that their scheme is vulnerable to masquerade attack. We propose a new scheme to enhance their security. Furthermore, by using our scheme, users can conveniently choose and change their passwords. Our scheme is suitable for applications with high security requirement. D 2004 Elsevier B.V. All rights reserved.