Cryptanalysis and Improvement of Authentication and Key Agreement Protocols for Telecare Medicine Information Systems

被引:76
|
作者
Islam, S. K. Hafizul [1 ]
Khan, Muhammad Khurram [2 ]
机构
[1] Birla Inst Technol & Sci, Dept Comp Sci & Informat Syst, Pilani 333031, Rajasthan, India
[2] King Saud Univ, Ctr Excellence Informat Assurance, Riyadh, Saudi Arabia
基金
中国国家自然科学基金;
关键词
Anonymity; Authentication; Random oracle model; Smartcard; Cryptanalysis; Hash function; Password; REMOTE USER AUTHENTICATION; PROVABLY SECURE; SCHEME; EFFICIENT; ANONYMITY; ENVIRONMENT;
D O I
10.1007/s10916-014-0135-9
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Recently, many authentication protocols have been presented using smartcard for the telecare medicine information system (TMIS). In 2014, Xu et al. put forward a two-factor mutual authentication with key agreement protocol using elliptic curve cryptography (ECC). However, the authors have proved that the protocol is not appropriate for practical use as it has many problems (1) it fails to achieve strong authentication in login and authentication phases; (2) it fails to update the password correctly in the password change phase; (3) it fails to provide the revocation of lost/stolen smartcard; and (4) it fails to protect the strong replay attack. We then devised an anonymous and provably secure two-factor authentication protocol based on ECC. Our protocol is analyzed with the random oracle model and demonstrated to be formally secured against the hardness assumption of computational Diffie-Hellman problem. The performance evaluation demonstrated that our protocol sa outperforms from the perspective of security, functionality and computation costs over other existing designs.
引用
收藏
页数:16
相关论文
共 50 条
  • [41] A Secure Authentication Scheme for Telecare Medicine Information Systems
    Zhen-Yu Wu
    Yueh-Chun Lee
    Feipei Lai
    Hung-Chang Lee
    Yufang Chung
    Journal of Medical Systems, 2012, 36 : 1529 - 1535
  • [42] Cryptanalysis and improvement of 'a secure authentication scheme for telecare medical information system' with nonce verification
    Siddiqui, Zeeshan
    Abdullah, Abdul Hanan
    Khan, Muhammad Khurram
    Alghamdi, Abdullah Sharaf
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2016, 9 (05) : 841 - 853
  • [43] Cryptanalysis and security enhancement of Zhu's authentication scheme for Telecare medicine information system
    Bin Muhaya, Fahad T.
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (02) : 149 - 158
  • [44] Cryptanalysis and improvement of ‘a secure authentication scheme for telecare medical information system’ with nonce verification
    Zeeshan Siddiqui
    Abdul Hanan Abdullah
    Muhammad Khurram Khan
    Abdullah Sharaf Alghamdi
    Peer-to-Peer Networking and Applications, 2016, 9 : 841 - 853
  • [45] Cryptanalysis and Improvement of "An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems"
    Khan, Muhammad Khurram
    Kumari, Saru
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (02) : 399 - 408
  • [46] A Secure Chaotic Maps and Smart Cards Based Password Authentication and Key Agreement Scheme with User Anonymity for Telecare Medicine Information Systems
    Li, Chun-Ta
    Lee, Cheng-Chi
    Weng, Chi-Yao
    JOURNAL OF MEDICAL SYSTEMS, 2014, 38 (09)
  • [47] A Secure Chaotic Maps and Smart Cards Based Password Authentication and Key Agreement Scheme with User Anonymity for Telecare Medicine Information Systems
    Chun-Ta Li
    Cheng-Chi Lee
    Chi-Yao Weng
    Journal of Medical Systems, 2014, 38
  • [48] Cryptanalysis and Improvement of ‘A Privacy Enhanced Scheme for Telecare Medical Information Systems’
    Saru Kumari
    Muhammad Khurram Khan
    Rahul Kumar
    Journal of Medical Systems, 2013, 37
  • [49] Cryptanalysis and Improvement of 'A Privacy Enhanced Scheme for Telecare Medical Information Systems'
    Kumari, Saru
    Khan, Muhammad Khurram
    Kumar, Rahul
    JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (04)
  • [50] Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems
    Sutrala, Anil Kumar
    Das, Ashok Kumar
    Odelu, Vanga
    Wazid, Mohammad
    Kumari, Saru
    COMPUTER METHODS AND PROGRAMS IN BIOMEDICINE, 2016, 135 : 167 - 185