An anonymous and provably secure biometric-based authentication scheme using chaotic maps for accessing medical drop box data

被引:11
作者
Khan, Imran [1 ]
Chaudhry, Shehzad Ashraf [1 ]
Sher, Muhammad [1 ]
Khan, Javed I. [2 ]
Khan, Muhammad Khurram [3 ]
机构
[1] Int Islamic Univ, Dept Comp Sci & Software Engn, Islamabad, Pakistan
[2] Kent State Univ, Dept Comp Sci, Kent, OH 44242 USA
[3] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
关键词
Chaotic maps; Medical drop box; Privacy; Authentication; National health information exchange; Electronic health record; Biometrics; Anonymity violation; ProVerif; TMIS; KEY AGREEMENT SCHEME; INFORMATION EXCHANGE;
D O I
10.1007/s11227-016-1886-5
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Telecare medicine information systems (TMISs) provides a platform to the participating medical entities to share medical data over an insecure public channel. Medical drop box (MDB) is used for the said purpose, where electronic health record (EHR) is maintained for national health information exchange (NHIX). EHR is a crucial part of MDB. Therefore, the main challenge in NHIX is to restrict MDB access to only the authenticated entities. Very Recently, Moon et al. introduced a biometrics-based authentication scheme using chaotic maps for TMISs. The authors claimed that their scheme is efficient and robust in terms of its usage and implementation. However, this paper unveils that due to storage of verifier table on server, their scheme is having scalability and efficiency issues. Furthermore, the use of the same parameters and during different login requests makes the scheme traceable. Therefore, an improved scheme using chaotic maps has been proposed in this paper, which provides user anonymity and untraceability along with computational efficiency. The security of the proposed scheme is evaluated in detail through the random oracle model. The analysis reveals that the proposed scheme is robust and secure against the known attacks. Moreover, analysis is further verified through popular automated tool ProVerif.
引用
收藏
页码:3685 / 3703
页数:19
相关论文
共 41 条
[31]   A Tale Of Two Large Community Electronic Health Record Extension Projects [J].
Mostashari, Farzad ;
Tripathi, Micky ;
Kendall, Mat .
HEALTH AFFAIRS, 2009, 28 (02) :345-356
[32]   An anonymous key agreement protocol based on chaotic maps [J].
Niu, Yujun ;
Wang, Xingyuan .
COMMUNICATIONS IN NONLINEAR SCIENCE AND NUMERICAL SIMULATION, 2011, 16 (04) :1986-1992
[33]   Designing chaotic S-boxes based on time-delay chaotic system [J].
Ozkaynak, Fatih ;
Yavuz, Sirma .
NONLINEAR DYNAMICS, 2013, 74 (03) :551-557
[34]  
Qazi Muhammad Suleman, 2009, J Pak Med Assoc, V59, P10
[35]  
Sinha P.K., 2012, Electronic Health Record: Standards, Coding Systems, Frameworks, and Infrastructures
[36]   Disassembly-oriented assessment methodology for product modularity [J].
Tseng, Hwai-En ;
Chang, Chien-Chen ;
Cheng, Chih-Jen .
INTERNATIONAL JOURNAL OF PRODUCTION RESEARCH, 2010, 48 (14) :4297-4320
[37]  
Vest JR, 2012, ADV HEALTH CARE MANA, V12, P3, DOI 10.1108/1474-8231(2012)0000012005
[38]   An Improved Authentication Scheme for Telecare Medicine Information Systems [J].
Wei, Jianghong ;
Hu, Xuexian ;
Liu, Wenfen .
JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (06) :3597-3604
[39]   An efficient entire chaos-based scheme for deniable authentication [J].
Xiao, D ;
Liao, XF ;
Wong, KW .
CHAOS SOLITONS & FRACTALS, 2005, 23 (04) :1327-1331
[40]   Anonymous Three-Party Password-Authenticated Key Exchange Scheme for Telecare Medical Information Systems [J].
Xie, Qi ;
Hu, Bin ;
Dong, Na ;
Wong, Duncan S. .
PLOS ONE, 2014, 9 (07)