Design of an efficient and provably secure anonymity preserving three-factor user authentication and key agreement scheme for TMIS

被引:67
|
作者
Wazid, Mohammad [1 ]
Das, Ashok Kumar [1 ]
Kumari, Saru [2 ]
Li, Xiong [3 ]
Wu, Fan [4 ]
机构
[1] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
[2] Chaudhary Charan Singh Univ, Dept Math, Meerut 250 005H, Uttar Pradesh, India
[3] Hunan Univ Sci & Technol, Sch Comp Sci & Engn, Xiangtan 411201, Peoples R China
[4] Huaqiao Univ, Xiamen Inst Technol, Dept Comp Sci & Engn, Xiamen 361021, Peoples R China
关键词
telecare medicine information systems; user authentication; user anonymity; smart card; provable security; AVISPA; PASSWORD AUTHENTICATION; MUTUAL AUTHENTICATION; PROTOCOL; IMPROVEMENT; BIOMETRICS; CRYPTANALYSIS; EXCHANGE; IDENTITY;
D O I
10.1002/sec.1452
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Several remote user authentication techniques for telecare medicine information system (TMIS) have been proposed in the literature. But most existing techniques have limitations such as vulnerable to various attacks, lack of functionalities, and inefficiency. Recently, Amin and Biswas proposed a three-factor authentication and key agreement technique for TMIS. But their scheme is inefficient and has several security drawbacks. The attacks such as privileged-insider, user impersonation, and strong reply attacks are possible on their scheme. It also has flaw in password update phase. In order to overcome drawbacks of their scheme, a new provably secure and efficient three-factor remote user authentication scheme for TMIS is proposed in this paper. The proposed scheme overcomes all drawbacks of their scheme and also provides additional features such as user unlinkability, user anonymity, efficient password, and biometric update. The rigorous informal and formal security analysis using random oracle models and the mostly acceptable Automated Validation of Internet Security Protocols and Applications tool is also performed. During the experimentation, it has been observed that the proposed scheme is secure against various known attacks that include replay and man-in-the-middle attacks. Furthermore, the analysis of computation and communication cost estimation of the proposed scheme depicts that our scheme is efficient as compared with other related exiting schemes. Copyright (c) 2016 John Wiley & Sons, Ltd.
引用
收藏
页码:1983 / 2001
页数:19
相关论文
共 50 条
  • [11] Applying biometrics to design three-factor remote user authentication scheme with key agreement
    Li, Xiong
    Niu, Jianwei
    Wang, Zhibo
    Chen, Caisen
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (10) : 1488 - 1497
  • [12] An Exquisite Authentication Scheme with Key Agreement Preserving User Anonymity
    Kim, Mijin
    Kim, Seungjoo
    Won, Dongho
    WEB INFORMATION SYSTEMS AND MINING, 2010, 6318 : 244 - 253
  • [13] An improved and provably secure three-factor user authentication scheme for wireless sensor networks
    Fan Wu
    Lili Xu
    Saru Kumari
    Xiong Li
    Peer-to-Peer Networking and Applications, 2018, 11 : 1 - 20
  • [14] An efficient ECC-based provably secure three-factor user authentication and key agreement protocol for wireless healthcare sensor networks
    Challa, Sravani
    Das, Ashok Kumar
    Odelu, Vanga
    Kumar, Neeraj
    Kumari, Saru
    Khan, Muhammad Khurram
    Vasilakos, Athanasios V.
    COMPUTERS & ELECTRICAL ENGINEERING, 2018, 69 : 534 - 554
  • [15] Provably secure and efficient identification and key agreement protocol with user anonymity
    Wang, Ren-Chiun
    Juang, Wen-Shenq
    Lei, Chin-Laung
    JOURNAL OF COMPUTER AND SYSTEM SCIENCES, 2011, 77 (04) : 790 - 798
  • [16] An improved and provably secure three-factor user authentication scheme for wireless sensor networks
    Wu, Fan
    Xu, Lili
    Kumari, Saru
    Li, Xiong
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2018, 11 (01) : 1 - 20
  • [17] A User Anonymity Preserving Three-Factor Authentication Scheme for Telecare Medicine Information Systems
    Tan, Zuowen
    JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (03)
  • [18] A User Anonymity Preserving Three-Factor Authentication Scheme for Telecare Medicine Information Systems
    Zuowen Tan
    Journal of Medical Systems, 2014, 38
  • [19] A secure authentication and key agreement scheme for roaming service with user anonymity
    Arshad, Hamed
    Rasoolzadegan, Abbas
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2017, 30 (18)
  • [20] Cryptanalysis of Improved and Provably Secure Three-Factor User Authentication Scheme for Wireless Sensor Networks
    Ryu, Jihyeon
    Song, Taeui
    Moon, Jongho
    Kim, Hyoungshick
    Won, Dongho
    COMPUTATIONAL SCIENCE AND TECHNOLOGY, 2019, 481 : 49 - 58