A Secure Authentication Protocol for Multi-Sever-Based E-Healthcare Using a Fuzzy Commitment Scheme

被引:47
作者
Barman, Subhas [1 ]
Shum, Hubert P. H. [2 ]
Chattopadhyay, Samiran [3 ]
Samanta, Debasis [4 ]
机构
[1] Jalpaiguri Govt Engn Coll, Jalpaiguri, India
[2] Northumbria Univ, Fac Engn & Environm, Newcastle Upon Tyne NE1 8ST, Tyne & Wear, England
[3] Jadavpur Univ, Dept Informat Technol, Kolkata 700098, India
[4] IIT Kharagpur, Dept Comp Sci & Engn, Kharagpur 721302, W Bengal, India
基金
英国工程与自然科学研究理事会;
关键词
Telecare medicine information system (THIS); fuzzy commitment scheme; BAN logic; real-or-random (ROR); AVISPA tool; KEY AGREEMENT PROTOCOL; USER AUTHENTICATION; PASSWORD AUTHENTICATION; INFORMATION; EFFICIENT; BIOMETRICS; DESIGN; EXCHANGE; PRIVACY; ATTACKS;
D O I
10.1109/ACCESS.2019.2893185
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smart card-based remote authentication schemes are widely used in multi-medicalserver-based telecare medicine information systems (TMISs). Biometric is one of the most trustworthy authenticators and is presently being advocated to use in the remote authentication of THIS. However, most of the existing TMISs consider a single-server-environment-based authentication system. Therefore, patients need to register and log into every server separately for different services. Furthermore, these schemes do not employ error correction technique to remove the errors from biometric data. Also, biometrics are inherent and demand diversification to generate a revocable template from inherent biometric data. In this paper, we propose a mutual authentication and key agreement scheme for a multi-medical server environment to overcome the limitations of the existing schemes. In the proposed scheme, a cancelable transformation of the raw biometric data is used to provide the privacy and the diversification of biometric data. The errors of the biometric data are corrected with error-correction techniques under the fuzzy commitment mechanism. A formal security analysis using the widely accepted real-or-random model, the Burrows-Abadi-Needham logic, and the automated validation of Internet security protocols and applications tool concludes that the proposed scheme is safe against known attacks. We also compare the computation and communication costs of our scheme to evaluate the performance with the others.
引用
收藏
页码:12557 / 12574
页数:18
相关论文
共 50 条
  • [21] Design of a Password Authentication and Key Agreement Scheme to Access e-Healthcare Services
    Saru Kumari
    Km. Renuka
    [J]. Wireless Personal Communications, 2021, 117 : 27 - 45
  • [22] An Authentic-Based Privacy Preservation Protocol for Smart e-Healthcare Systems in IoT
    Deebak, B. D.
    Al-Turjman, Fadi
    Aloqaily, Moayad
    Alfandi, Omar
    [J]. IEEE ACCESS, 2019, 7 : 135632 - 135649
  • [23] SPOT: Secure and Privacy-Preserving PrOximiTy Protocol for e-Healthcare Systems
    Masmoudi, Souha
    Kaaniche, Nesrine
    Laurent, Maryline
    [J]. IEEE ACCESS, 2022, 10 : 106400 - 106414
  • [24] A Secure Multi-factor Authentication Protocol for Healthcare Services Using Cloud-based SDN
    Midha, Sugandhi
    Verma, Sahil
    Kavita
    Mittal, Mohit
    Jhanjhi, Nz
    Masud, Mehedi
    AlZain, Mohammed A.
    [J]. CMC-COMPUTERS MATERIALS & CONTINUA, 2023, 74 (02): : 3711 - 3726
  • [25] A secure multi-factor ECC based authentication scheme for Cloud-IoT based healthcare services
    Dhillon, Parwinder Kaur
    Kalra, Sheetal
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND SMART ENVIRONMENTS, 2019, 11 (02) : 149 - 164
  • [26] A privacy-preserving and energy efficient authentication protocol for the cloud-based e-healthcare system
    Alzahrani, Abdulrahman
    Alzahrani, Hamdan A.
    [J]. ALEXANDRIA ENGINEERING JOURNAL, 2025, 118 : 59 - 90
  • [27] A Provably Secure Multi-server Based Authentication Scheme
    Yeh, Kuo-Hui
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2014, 79 (03) : 1621 - 1634
  • [28] A Note on “Design of a Password Authentication and Key Agreement Scheme to Access e-Healthcare Services”
    Zhengjun Cao
    [J]. Wireless Personal Communications, 2023, 133 : 2439 - 2444
  • [29] A Hybrid and Fast Authentication Protocol for Handoff Support in e-Healthcare Systems among WSNs
    Bruce, Ndibanje
    Hwang, Gi-Hyun
    Lee, Hoon Jae
    [J]. 2013 INTERNATIONAL CONFERENCE ON ICT CONVERGENCE (ICTC 2013): FUTURE CREATIVE CONVERGENCE TECHNOLOGIES FOR NEW ICT ECOSYSTEMS, 2013, : 72 - 77
  • [30] A Note on "Design of a Password Authentication and Key Agreement Scheme to Access e-Healthcare Services"
    Cao, Zhengjun
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2023, 133 (04) : 2439 - 2444