Design of a secure and privacy preserving authentication protocol for telecare medical information systems

被引:4
作者
Sumithra, V [1 ]
Shashidhara, R. [1 ]
Mukhopadhyay, Debajyoti [2 ]
机构
[1] Bennett Univ, Sch Engn & Appl Sci, Greater Noida, Uttar Pradesh, India
[2] Bennett Univ, WIDIiCoReL Res Lab, Greater Noida, Uttar Pradesh, India
关键词
cryptanalysis; formal verification; healthcare; HLPSL; mutual authentication; privacy; security; TMIS; KEY AGREEMENT PROTOCOL; SCHEME; TMIS;
D O I
10.1002/spy2.228
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the advancement of communication technology, Telecare Medicine Information Systems (TMIS) provides convenient healthcare services for patients, doctors, and health organizations over the insecure Internet. As a result, when accessing sensitive medical data over an insecure connection, user privacy, data security, and user authentication is very crucial. A secure authentication protocol plays a crucial role in securing communications over TMIS, these environments are very vulnerable to numerous attacks due to resource constraints and the nature of the communication medium. Recently, an efficient authentication framework has been introduced for TMIS to address various security issues. However, the existing mutual authentication and key agreement protocols are vulnerable to replay attacks, insider attacks, impersonation attacks, and password guessing attacks. Furthermore, the current authentication systems do not guarantee user privacy and the fair key agreement between the patient and the medical server. We propose a more robust authentication approach for healthcare information systems to address these security issues. To assess the authentication protocol's security strength, we employ formal verification tools like Automated Validation of Internet Security Protocols and Applications (AVISPA). Finally, a thorough performance analysis demonstrates that the proposed mutual authentication framework not only ensures privacy but also maintains a low computing overhead. As a result, when compared to other related systems, the proposed authentication protocol is both secure and computationally efficient.
引用
收藏
页数:17
相关论文
共 28 条
[1]   Anonymity Preserving and Lightweight Multimedical Server Authentication Protocol for Telecare Medical Information System [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Gope, Prosanta ;
Choo, Kim-Kwang Raymond ;
Tapas, Nachiket .
IEEE JOURNAL OF BIOMEDICAL AND HEALTH INFORMATICS, 2019, 23 (04) :1749-1759
[2]   A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity [J].
Amin, Ruhul ;
Biswas, G. P. .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (08)
[3]  
Armando A., 2006, ERCIM NEWS, V64, P1
[4]   Design of a Secure Authentication and Key Agreement Scheme Preserving User Privacy Usable in Telecare Medicine Information Systems [J].
Arshad, Hamed ;
Rasoolzadegan, Abbas .
JOURNAL OF MEDICAL SYSTEMS, 2016, 40 (11)
[5]  
Basin D., 2005, Int. J. Inf. Secur, V4, P181, DOI [DOI 10.1007/S10207-004-0055-7, 10.1007/s10207-004-0055-7]
[6]   Security Analysis and Enhancement of the Most Recent RFID Authentication Protocol for Telecare Medicine Information System [J].
Benssalah, Mustapha ;
Djeddou, Mustapha ;
Drouiche, Karim .
WIRELESS PERSONAL COMMUNICATIONS, 2017, 96 (04) :6221-6238
[7]  
Dai W., 2011, Crypto++ library 5.1-a free c++ class library of cryptographic schemes
[9]   Smart Mutual Authentication Protocol for Cloud Based Medical Healthcare Systems Using Internet of Medical Things [J].
Deebak, B. D. ;
Al-Turjman, Fadi .
IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2021, 39 (02) :346-360
[10]   ON THE SECURITY OF PUBLIC KEY PROTOCOLS [J].
DOLEV, D ;
YAO, AC .
IEEE TRANSACTIONS ON INFORMATION THEORY, 1983, 29 (02) :198-208