A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity

被引:51
作者
Amin, Ruhul [1 ]
Biswas, G. P. [1 ]
机构
[1] Indian Sch Mines, Dept Comp Sci & Engn, Dhanbad 826004, Bihar, India
关键词
Authentication; AVISPA Tool; Elliptic curve; Security attacks; Smart card; MEDICINE INFORMATION-SYSTEMS; SCHEME; EFFICIENT; CRYPTANALYSIS; IMPROVEMENT;
D O I
10.1007/s10916-015-0258-7
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Telecare medical information system (TMIS) makes an efficient and convenient connection between patient(s)/user(s) and doctor(s) over the insecure internet. Therefore, data security, privacy and user authentication are enormously important for accessing important medical data over insecure communication. Recently, many user authentication protocols for TMIS have been proposed in the literature and it has been observed that most of the protocols cannot achieve complete security requirements. In this paper, we have scrutinized two (Mishra et al., Xu et al.) remote user authentication protocols using smart card and explained that both the protocols are suffering against several security weaknesses. We have then presented three-factor user authentication and key agreement protocol usable for TMIS, which fix the security pitfalls of the above mentioned schemes. The informal cryptanalysis makes certain that the proposed protocol provides well security protection on the relevant security attacks. Furthermore, the simulator AVISPA tool confirms that the protocol is secure against active and passive attacks including replay and man-in-the-middle attacks. The security functionalities and performance comparison analysis confirm that our protocol not only provide strong protection on security attacks, but it also achieves better complexities along with efficient login and password change phase as well as session key verification property.
引用
收藏
页数:19
相关论文
共 56 条
[1]   Remote Access Control Mechanism Using Rabin Public Key Cryptosystem [J].
Amin, Ruhul ;
Biswas, G. P. .
INFORMATION SYSTEMS DESIGN AND INTELLIGENT APPLICATIONS, VOL 1, 2015, 339 :525-533
[2]   A Novel User Authentication and Key Agreement Protocol for Accessing Multi-Medical Server Usable in TMIS [J].
Amin, Ruhul ;
Biswas, G. P. .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
[3]  
[Anonymous], 2011, INT J NETW SECUR, DOI DOI 10.1007/S00607-013-0308-2
[4]  
[Anonymous], ARXIV13110151 CORR
[5]  
[Anonymous], 2015, TOOL A W
[6]  
[Anonymous], ARXIV14063943 CORR
[7]  
[Anonymous], 2013, INT J COMPUTER APPL
[8]  
[Anonymous], 2013, INT J COMPUTER APPL
[9]  
[Anonymous], 2015, P 2015 3 INT C COMP
[10]  
Armando A, 2005, LECT NOTES COMPUT SC, V3576, P281