An Improved and Effective Secure Password-Based Authentication and Key Agreement Scheme Using Smart Cards for the Telecare Medicine Information System

被引:71
作者
Das, Ashok Kumar [1 ]
Bruhadeshwar, Bezawada [1 ]
机构
[1] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
关键词
Telecare medicine information system; User authentication; Password; Mutual authentication; Key agreement; Security; Smart cards; AVISPA; USER AUTHENTICATION; EFFICIENT; CRYPTANALYSIS;
D O I
10.1007/s10916-013-9969-9
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Recently Lee and Liu proposed an efficient password based authentication and key agreement scheme using smart card for the telecare medicine information system [J. Med. Syst. (2013) 37: 9933]. In this paper, we show that though their scheme is efficient, their scheme still has two security weaknesses such as (1) it has design flaws in authentication phase and (2) it has design flaws in password change phase. In order to withstand these flaws found in Lee-Liu's scheme, we propose an improvement of their scheme. Our improved scheme keeps also the original merits of Lee-Liu's scheme. We show that our scheme is efficient as compared to Lee-Liu's scheme. Further, through the security analysis, we show that our scheme is secure against possible known attacks. In addition, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool to show that our scheme is secure against passive and active attacks.
引用
收藏
页数:17
相关论文
共 31 条
[1]  
[Anonymous], 1995, 1801 FIPS PUB NIST U
[2]  
[Anonymous], AVISPA WEB TOOL
[3]  
Aumasson JP, 2010, LECT NOTES COMPUT SC, V6225, P1, DOI 10.1007/978-3-642-15031-9_1
[4]  
Basin D., 2005, Int J Inf Secur, V4, P181, DOI DOI 10.1007/S10207-004-0055-7
[5]   A Uniqueness-and-Anonymity-Preserving Remote User Authentication Scheme for Connected Health Care [J].
Chang, Ya-Fen ;
Yu, Shih-Hui ;
Shiao, Ding-Rui .
JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (02)
[6]   Analysis and improvement on an efficient biometric-based remote user authentication scheme using smart cards [J].
Das, A. K. .
IET INFORMATION SECURITY, 2011, 5 (03) :145-151
[7]  
Das A. K., 2013, "Netw.Sci., V2, P12
[8]  
Das A. K, INT J FDN C IN PRESS
[9]   A novel proxy signature scheme based on user hierarchical access control policy [J].
Das, Ashok Kumar ;
Massand, Ashish ;
Patil, Sagar .
JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2013, 25 (02) :219-228
[10]   A Secure and Efficient Uniqueness-and-Anonymity-Preserving Remote User Authentication Scheme for Connected Health Care [J].
Das, Ashok Kumar ;
Goswami, Adrijit .
JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (03)