An Improved and Secure Biometric Authentication Scheme for Telecare Medicine Information Systems Based on Elliptic Curve Cryptography

被引:40
作者
Chaudhry, Shehzad Ashraf [1 ]
Mahmood, Khalid [1 ]
Naqvi, Husnain [1 ]
Khan, Muhammad Khurram [2 ]
机构
[1] Int Islamic Univ, Dept Comp Sci & Software Engn, Islamabad, Pakistan
[2] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
关键词
Three factor authentication; BioHashing; Elliptic curve cryptography; Impersonation attack; TMIS; ProVerif; Anonymity; Privacy;
D O I
10.1007/s10916-015-0335-y
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Telecare medicine information system (TMIS) offers the patients convenient and expedite healthcare services remotely anywhere. Patient security and privacy has emerged as key issues during remote access because of underlying open architecture. An authentication scheme can verify patient's as well as TMIS server's legitimacy during remote healthcare services. To achieve security and privacy a number of authentication schemes have been proposed. Very recently Lu et al. (J. Med. Syst. 39(3): 1-8, 2015) proposed a biometric based three factor authentication scheme for TMIS to confiscate the vulnerabilities of Arshad et al.'s (J. Med. Syst. 38(12): 136, 2014) scheme. Further, they emphasized the robustness of their scheme against several attacks. However, in this paper we establish that Lu et al.'s scheme is vulnerable to numerous attacks including (1) Patient anonymity violation attack, (2) Patient impersonation attack, and (3) TMIS server impersonation attack. Furthermore, their scheme does not provide patient untraceability. We then, propose an improvement of Lu et al.'s scheme. We have analyzed the security of improved scheme using popular automated tool ProVerif. The proposed scheme while retaining the plusses of Lu et al.'s scheme is also robust against known attacks.
引用
收藏
页数:12
相关论文
共 2 条
[1]   An Enhanced and Secure Three-party Password-based Authenticated Key Exchange Protocol without Using Server's Public-Keys and Symmetric Cryptosystems [J].
Farash, Mohammad Sabzinejad ;
Attari, Mahmoud Ahmadian .
INFORMATION TECHNOLOGY AND CONTROL, 2014, 43 (02) :143-150
[2]   An improved smart card based authentication scheme for session initiation protocol [J].
Kumari, Saru ;
Chaudhry, Shehzad Ashraf ;
Wu, Fan ;
Li, Xiong ;
Farash, Mohammad Sabzinejad ;
Khan, Muhammad Khurram .
PEER-TO-PEER NETWORKING AND APPLICATIONS, 2017, 10 (01) :92-105