Secure Privacy-Preserving Biometric Authentication Scheme for Telecare Medicine Information Systems

被引:15
作者
Li, Xuelei [1 ]
Wen, Qiaoyan [1 ]
Li, Wenmin [1 ]
Zhang, Hua [1 ]
Jin, Zhengping [1 ]
机构
[1] Beijing Univ Posts & Telecommun, State Key Lab Networking & Switching Technol, Beijing 100876, Peoples R China
关键词
Telecare medicine information system; Authentication; Biometric; Anonymity; Key agreement; REMOTE USER AUTHENTICATION; SMART-CARD; POWER ANALYSIS; EFFICIENT;
D O I
10.1007/s10916-014-0139-5
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Healthcare delivery services via telecare medicine information systems (TMIS) can help patients to obtain their desired telemedicine services conveniently. However, information security and privacy protection are important issues and crucial challenges in healthcare information systems, where only authorized patients and doctors can employ telecare medicine facilities and access electronic medical records. Therefore, a secure authentication scheme is urgently required to achieve the goals of entity authentication, data confidentiality and privacy protection. This paper investigates a new biometric authentication with key agreement scheme, which focuses on patient privacy and medical data confidentiality in TMIS. The new scheme employs hash function, fuzzy extractor, nonce and authenticated Diffie-Hellman key agreement as primitives. It provides patient privacy protection, e.g., hiding identity from being theft and tracked by unauthorized participant, and preserving password and biometric template from being compromised by trustless servers. Moreover, key agreement supports secure transmission by symmetric encryption to protect patient's medical data from being leaked. Finally, the analysis shows that our proposal provides more security and privacy protection for TMIS.
引用
收藏
页数:8
相关论文
共 34 条
  • [1] Identity theft
    Anderson, Keith B.
    Durbin, Erik
    Salinger, Michael A.
    [J]. JOURNAL OF ECONOMIC PERSPECTIVES, 2008, 22 (02) : 171 - 192
  • [2] [Anonymous], 2013, J. Med. Syst.
  • [3] Awasthi A.K., 2004, ARXIV PREPRINT CS041
  • [4] An improved timestamp-based remote user authentication scheme
    Awasthi, Amit K.
    Srivastava, Keerti
    Mittal, R. C.
    [J]. COMPUTERS & ELECTRICAL ENGINEERING, 2011, 37 (06) : 869 - 874
  • [5] A LOGIC OF AUTHENTICATION
    BURROWS, M
    ABADI, M
    NEEDHAM, RM
    [J]. PROCEEDINGS OF THE ROYAL SOCIETY OF LONDON SERIES A-MATHEMATICAL PHYSICAL AND ENGINEERING SCIENCES, 1989, 426 (1871): : 233 - 271
  • [6] Improved Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Cao, Tianjie
    Zhai, Jingxuan
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (02)
  • [7] An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Chen, Hung-Ming
    Lo, Jung-Wen
    Yeh, Chang-Kuo
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (06) : 3907 - 3915
  • [8] An efficient and practical solution to remote authentication: Smart card
    Chien, HY
    Jan, JK
    Tseng, YM
    [J]. COMPUTERS & SECURITY, 2002, 21 (04) : 372 - 375
  • [10] A dynamic ID-based remote user authentication scheme
    Das, ML
    Saxena, A
    Gulati, VP
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 629 - 631