Cryptanalysis and Improvement of Authentication and Key Agreement Protocols for Telecare Medicine Information Systems

被引:76
|
作者
Islam, S. K. Hafizul [1 ]
Khan, Muhammad Khurram [2 ]
机构
[1] Birla Inst Technol & Sci, Dept Comp Sci & Informat Syst, Pilani 333031, Rajasthan, India
[2] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
基金
中国国家自然科学基金;
关键词
Anonymity; Authentication; Random oracle model; Smartcard; Cryptanalysis; Hash function; Password; REMOTE USER AUTHENTICATION; PROVABLY SECURE; SCHEME; EFFICIENT; ANONYMITY; ENVIRONMENT;
D O I
10.1007/s10916-014-0135-9
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Recently, many authentication protocols have been presented using smartcard for the telecare medicine information system (TMIS). In 2014, Xu et al. put forward a two-factor mutual authentication with key agreement protocol using elliptic curve cryptography (ECC). However, the authors have proved that the protocol is not appropriate for practical use as it has many problems (1) it fails to achieve strong authentication in login and authentication phases; (2) it fails to update the password correctly in the password change phase; (3) it fails to provide the revocation of lost/stolen smartcard; and (4) it fails to protect the strong replay attack. We then devised an anonymous and provably secure two-factor authentication protocol based on ECC. Our protocol is analyzed with the random oracle model and demonstrated to be formally secured against the hardness assumption of computational Diffie-Hellman problem. The performance evaluation demonstrated that our protocol sa outperforms from the perspective of security, functionality and computation costs over other existing designs.
引用
收藏
页数:16
相关论文
共 50 条
  • [11] Three-Factor Anonymous Authentication and Key Agreement Scheme for Telecare Medicine Information Systems
    Hamed Arshad
    Morteza Nikooghadam
    Journal of Medical Systems, 2014, 38
  • [12] A Secure and Efficient Authentication and Key Agreement Scheme Based on ECC for Telecare Medicine Information Systems
    Xu, Xin
    Zhu, Ping
    Wen, Qiaoyan
    Jin, Zhengping
    Zhang, Hua
    He, Lian
    JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (01)
  • [13] Three-Factor Anonymous Authentication and Key Agreement Scheme for Telecare Medicine Information Systems
    Arshad, Hamed
    Nikooghadam, Morteza
    JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (12)
  • [14] On the Security of a Two-Factor Authentication and Key Agreement Scheme for Telecare Medicine Information Systems
    Arshad, Hamed
    Teymoori, Vahid
    Nikooghadam, Morteza
    Abbassi, Hassan
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (08)
  • [15] Understanding Security Failures of Two Authentication and Key Agreement Schemes for Telecare Medicine Information Systems
    Mishra, Dheerendra
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
  • [16] A Secure Smart-Card Based Authentication and Key Agreement Scheme for Telecare Medicine Information Systems
    Lee, Tian-Fu
    Liu, Chuan-Ming
    JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (03)
  • [17] A Secure Smart-Card Based Authentication and Key Agreement Scheme for Telecare Medicine Information Systems
    Tian-Fu Lee
    Chuan-Ming Liu
    Journal of Medical Systems, 2013, 37
  • [18] Cryptanalysis and Improvement of an Improved Two Factor Authentication Protocol for Telecare Medical Information Systems
    Chaudhry, Shehzad Ashraf
    Naqvi, Husnain
    Shon, Taeshik
    Sher, Muhammad
    Farash, Mohammad Sabzinejad
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (06)
  • [19] Cryptanalysis and Improvement of an Improved Two Factor Authentication Protocol for Telecare Medical Information Systems
    Shehzad Ashraf Chaudhry
    Husnain Naqvi
    Taeshik Shon
    Muhammad Sher
    Mohammad Sabzinejad Farash
    Journal of Medical Systems, 2015, 39
  • [20] Design of a Secure Authentication and Key Agreement Scheme Preserving User Privacy Usable in Telecare Medicine Information Systems
    Hamed Arshad
    Abbas Rasoolzadegan
    Journal of Medical Systems, 2016, 40