On the Security Flaws in ID-based Password Authentication Schemes for Telecare Medical Information Systems

被引:0
|
作者
Dheerendra Mishra
机构
[1] Indian Institute of Technology Kharagpur,Department of Mathematics
来源
关键词
Telecare medical information system; Password based authentication; Smart card; Security; Privacy;
D O I
暂无
中图分类号
学科分类号
摘要
Telecare medical information systems (TMIS) enable healthcare delivery services. However, access of these services via public channel raises security and privacy issues. In recent years, several smart card based authentication schemes have been introduced to ensure secure and authorized communication between remote entities over the public channel for the (TMIS). We analyze the security of some of the recently proposed authentication schemes of Lin, Xie et al., Cao and Zhai, and Wu and Xu’s for TMIS. Unfortunately, we identify that these schemes failed to satisfy desirable security attributes. In this article we briefly discuss four dynamic ID-based authentication schemes and demonstrate their failure to satisfy desirable security attributes. The study is aimed to demonstrate how inefficient password change phase can lead to denial of server scenario for an authorized user, and how an inefficient login phase causes the communication and computational overhead and decrease the performance of the system. Moreover, we show the vulnerability of Cao and Zhai’s scheme to known session specific temporary information attack, vulnerability of Wu and Xu’s scheme to off-line password guessing attack, and vulnerability of Xie et al.’s scheme to untraceable on-line password guessing attack.
引用
收藏
相关论文
共 50 条
  • [1] On the Security Flaws in ID-based Password Authentication Schemes for Telecare Medical Information Systems
    Mishra, Dheerendra
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (01)
  • [2] On the Security of A Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Lin, Han-Yu
    JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (02)
  • [3] On the Security of A Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Han-Yu Lin
    Journal of Medical Systems, 2013, 37
  • [4] Improved Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Cao, Tianjie
    Zhai, Jingxuan
    JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (02)
  • [5] Improved Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Tianjie Cao
    Jingxuan Zhai
    Journal of Medical Systems, 2013, 37
  • [6] An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Hung-Ming Chen
    Jung-Wen Lo
    Chang-Kuo Yeh
    Journal of Medical Systems, 2012, 36 : 3907 - 3915
  • [7] An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems
    Chen, Hung-Ming
    Lo, Jung-Wen
    Yeh, Chang-Kuo
    JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (06) : 3907 - 3915
  • [8] Security on Dynamic ID-based Authentication Schemes
    Zhai, Jingxuan
    Cao, Tianjie
    Chen, Xiuqing
    Huang, Shi
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (01): : 387 - 396
  • [9] Cryptanalysis and Improvement of "An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems"
    Khan, Muhammad Khurram
    Kumari, Saru
    SECURITY AND COMMUNICATION NETWORKS, 2014, 7 (02) : 399 - 408
  • [10] A Dynamic ID-based Authentication Scheme based on ECC for Telecare Medicine Information Systems
    Xu, Xin
    Jin, Zheng-Ping
    Zhang, Hua
    Zhu, Ping
    FRONTIERS OF MECHANICAL ENGINEERING AND MATERIALS ENGINEERING II, PTS 1 AND 2, 2014, 457-458 : 861 - 866