An Improved and Secure Biometric Authentication Scheme for Telecare Medicine Information Systems Based on Elliptic Curve Cryptography

被引:0
|
作者
Shehzad Ashraf Chaudhry
Khalid Mahmood
Husnain Naqvi
Muhammad Khurram Khan
机构
[1] International Islamic University,Department of Computer Science and Software Engineering
[2] King Saud University,Center of Excellence in Information Assurance
来源
关键词
Three factor authentication; BioHashing; Elliptic curve cryptography; Impersonation attack; TMIS; ProVerif; Anonymity; Privacy;
D O I
暂无
中图分类号
学科分类号
摘要
Telecare medicine information system (TMIS) offers the patients convenient and expedite healthcare services remotely anywhere. Patient security and privacy has emerged as key issues during remote access because of underlying open architecture. An authentication scheme can verify patient’s as well as TMIS server’s legitimacy during remote healthcare services. To achieve security and privacy a number of authentication schemes have been proposed. Very recently Lu et al. (J. Med. Syst. 39(3):1–8, 2015) proposed a biometric based three factor authentication scheme for TMIS to confiscate the vulnerabilities of Arshad et al.’s (J. Med. Syst. 38(12):136, 2014) scheme. Further, they emphasized the robustness of their scheme against several attacks. However, in this paper we establish that Lu et al.’s scheme is vulnerable to numerous attacks including (1) Patient anonymity violation attack, (2) Patient impersonation attack, and (3) TMIS server impersonation attack. Furthermore, their scheme does not provide patient untraceability. We then, propose an improvement of Lu et al.’s scheme. We have analyzed the security of improved scheme using popular automated tool ProVerif. The proposed scheme while retaining the plusses of Lu et al.’s scheme is also robust against known attacks.
引用
收藏
相关论文
共 50 条