An Enhanced Biometric Authentication Scheme for Telecare Medicine Information Systems with Nonce Using Chaotic Hash Function

被引:34
|
作者
Das, Ashok Kumar [1 ]
Goswami, Adrijit [2 ]
机构
[1] Int Inst Informat Technol, Ctr Secur Theory & Algorithm Res, Hyderabad 500032, Andhra Pradesh, India
[2] Indian Inst Technol, Dept Math, Kharagpur 721302, W Bengal, India
关键词
Telecare medicine information systems; Chaotic hash function; Biohashing; Security; Biometrics; Password; Anonymity; AVISPA; SMART-CARD SECURITY; PASSWORD AUTHENTICATION; USER; CRYPTANALYSIS; IMPROVEMENT; EFFICIENT;
D O I
10.1007/s10916-014-0027-z
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Recently, Awasthi and Srivastava proposed a novel biometric remote user authentication scheme for the telecare medicine information system (TMIS) with nonce. Their scheme is very efficient as it is based on efficient chaotic one-way hash function and bitwise XOR operations. In this paper, we first analyze Awasthi-Srivastava's scheme and then show that their scheme has several drawbacks: (1) incorrect password change phase, (2) fails to preserve user anonymity property, (3) fails to establish a secret session key beween a legal user and the server, (4) fails to protect strong replay attack, and (5) lacks rigorous formal security analysis. We then a propose a novel and secure biometric-based remote user authentication scheme in order to withstand the security flaw found in Awasthi-Srivastava's scheme and enhance the features required for an idle user authentication scheme. Through the rigorous informal and formal security analysis, we show that our scheme is secure against possible known attacks. In addition, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and show that our scheme is secure against passive and active attacks, including the replay and man-in-the-middle attacks. Our scheme is also efficient as compared to Awasthi-Srivastava's scheme.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] An Enhanced Biometric Authentication Scheme for Telecare Medicine Information Systems with Nonce Using Chaotic Hash Function
    Ashok Kumar Das
    Adrijit Goswami
    Journal of Medical Systems, 2014, 38
  • [2] A Biometric Authentication Scheme for Telecare Medicine Information Systems with Nonce
    Awasthi, Amit K.
    Srivastava, Keerti
    JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (05)
  • [3] A Biometric Authentication Scheme for Telecare Medicine Information Systems with Nonce
    Amit K. Awasthi
    Keerti Srivastava
    Journal of Medical Systems, 2013, 37
  • [4] Security Enhancement of a Biometric based Authentication Scheme for Telecare Medicine Information Systems with Nonce
    Dheerendra Mishra
    Sourav Mukhopadhyay
    Saru Kumari
    Muhammad Khurram Khan
    Ankita Chaturvedi
    Journal of Medical Systems, 2014, 38
  • [5] Security Enhancement of a Biometric based Authentication Scheme for Telecare Medicine Information Systems with Nonce
    Mishra, Dheerendra
    Mukhopadhyay, Sourav
    Kumari, Saru
    Khan, Muhammad Khurram
    Chaturvedi, Ankita
    JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (05)
  • [6] An Enhanced Biometric-Based Authentication Scheme for Telecare Medicine Information Systems Using Elliptic Curve Cryptosystem
    Yanrong Lu
    Lixiang Li
    Haipeng Peng
    Yixian Yang
    Journal of Medical Systems, 2015, 39
  • [7] An Enhanced Biometric-Based Authentication Scheme for Telecare Medicine Information Systems Using Elliptic Curve Cryptosystem
    Lu, Yanrong
    Li, Lixiang
    Peng, Haipeng
    Yang, Yixian
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
  • [8] A Lightweight Biometric-based Authentication Scheme for Telecare Medicine Information Systems Using ECC
    Sahoo, Shreeya Swagatika
    Mohanty, Sujata
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [9] Cryptanalysis of enhanced biometric-based authentication scheme for telecare medicine information systems using elliptic curve cryptosystem
    Mun, Jongho
    Yu, Jiseon
    Kim, Jiye
    Yang, Hyungkyu
    Won, Dongho
    Lecture Notes in Electrical Engineering, 2015, 373 : 1 - 6
  • [10] A Chaotic Map-based Authentication Scheme for Telecare Medicine Information Systems
    Xinhong Hao
    Jiantao Wang
    Qinghai Yang
    Xiaopeng Yan
    Ping Li
    Journal of Medical Systems, 2013, 37