Cryptanalysis and Improvement of Authentication and Key Agreement Protocols for Telecare Medicine Information Systems

被引:76
|
作者
Islam, S. K. Hafizul [1 ]
Khan, Muhammad Khurram [2 ]
机构
[1] Birla Inst Technol & Sci, Dept Comp Sci & Informat Syst, Pilani 333031, Rajasthan, India
[2] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
基金
中国国家自然科学基金;
关键词
Anonymity; Authentication; Random oracle model; Smartcard; Cryptanalysis; Hash function; Password; REMOTE USER AUTHENTICATION; PROVABLY SECURE; SCHEME; EFFICIENT; ANONYMITY; ENVIRONMENT;
D O I
10.1007/s10916-014-0135-9
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Recently, many authentication protocols have been presented using smartcard for the telecare medicine information system (TMIS). In 2014, Xu et al. put forward a two-factor mutual authentication with key agreement protocol using elliptic curve cryptography (ECC). However, the authors have proved that the protocol is not appropriate for practical use as it has many problems (1) it fails to achieve strong authentication in login and authentication phases; (2) it fails to update the password correctly in the password change phase; (3) it fails to provide the revocation of lost/stolen smartcard; and (4) it fails to protect the strong replay attack. We then devised an anonymous and provably secure two-factor authentication protocol based on ECC. Our protocol is analyzed with the random oracle model and demonstrated to be formally secured against the hardness assumption of computational Diffie-Hellman problem. The performance evaluation demonstrated that our protocol sa outperforms from the perspective of security, functionality and computation costs over other existing designs.
引用
收藏
页数:16
相关论文
共 50 条
  • [31] An Enhanced Version of Key Agreement System with User Privacy for Telecare Medicine Information Systems
    Limbasiya, Trupil
    Doshi, Nishant
    PROCEEDINGS OF FIRST INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY FOR INTELLIGENT SYSTEMS: VOL 1, 2016, 50 : 137 - 145
  • [32] An Improved Authentication Scheme for Telecare Medicine Information Systems
    Wei, Jianghong
    Hu, Xuexian
    Liu, Wenfen
    JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (06) : 3597 - 3604
  • [33] Strong Authentication Scheme for Telecare Medicine Information Systems
    Pu, Qiong
    Wang, Jian
    Zhao, Rongyong
    JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (04) : 2609 - 2619
  • [34] An Improved Authentication Scheme for Telecare Medicine Information Systems
    Jianghong Wei
    Xuexian Hu
    Wenfen Liu
    Journal of Medical Systems, 2012, 36 : 3597 - 3604
  • [35] A Survey of Authentication Schemes in Telecare Medicine Information Systems
    Aslam, Muhammad Umair
    Derhab, Abdelouahid
    Saleem, Kashif
    Abbas, Haider
    Orgun, Mehmet
    Iqbal, Waseem
    Aslam, Baber
    JOURNAL OF MEDICAL SYSTEMS, 2017, 41 (01)
  • [36] A Survey of Authentication Schemes in Telecare Medicine Information Systems
    Muhammad Umair Aslam
    Abdelouahid Derhab
    Kashif Saleem
    Haider Abbas
    Mehmet Orgun
    Waseem Iqbal
    Baber Aslam
    Journal of Medical Systems, 2017, 41
  • [37] An Efficient Authentication Scheme for Telecare Medicine Information Systems
    Zhu, Zhian
    JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (06) : 3833 - 3838
  • [38] Strong Authentication Scheme for Telecare Medicine Information Systems
    Qiong Pu
    Jian Wang
    Rongyong Zhao
    Journal of Medical Systems, 2012, 36 : 2609 - 2619
  • [39] An Efficient Authentication Scheme for Telecare Medicine Information Systems
    Zhian Zhu
    Journal of Medical Systems, 2012, 36 : 3833 - 3838
  • [40] A Secure Authentication Scheme for Telecare Medicine Information Systems
    Wu, Zhen-Yu
    Lee, Yueh-Chun
    Lai, Feipei
    Lee, Hung-Chang
    Chung, Yufang
    JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (03) : 1529 - 1535