On the Security Flaws in ID-based Password Authentication Schemes for Telecare Medical Information Systems

被引:0
|
作者
Dheerendra Mishra
机构
[1] Indian Institute of Technology Kharagpur,Department of Mathematics
来源
关键词
Telecare medical information system; Password based authentication; Smart card; Security; Privacy;
D O I
暂无
中图分类号
学科分类号
摘要
Telecare medical information systems (TMIS) enable healthcare delivery services. However, access of these services via public channel raises security and privacy issues. In recent years, several smart card based authentication schemes have been introduced to ensure secure and authorized communication between remote entities over the public channel for the (TMIS). We analyze the security of some of the recently proposed authentication schemes of Lin, Xie et al., Cao and Zhai, and Wu and Xu’s for TMIS. Unfortunately, we identify that these schemes failed to satisfy desirable security attributes. In this article we briefly discuss four dynamic ID-based authentication schemes and demonstrate their failure to satisfy desirable security attributes. The study is aimed to demonstrate how inefficient password change phase can lead to denial of server scenario for an authorized user, and how an inefficient login phase causes the communication and computational overhead and decrease the performance of the system. Moreover, we show the vulnerability of Cao and Zhai’s scheme to known session specific temporary information attack, vulnerability of Wu and Xu’s scheme to off-line password guessing attack, and vulnerability of Xie et al.’s scheme to untraceable on-line password guessing attack.
引用
收藏
相关论文
共 50 条
  • [31] A Secure Authentication Scheme for Telecare Medical Information Systems
    Chang, Chin-Chen
    Lee, Jung-San
    Lo, Yu-Ya
    Liu, Yanjun
    ADVANCES IN INTELLIGENT INFORMATION HIDING AND MULTIMEDIA SIGNAL PROCESSING, VOL 1, 2017, 63 : 303 - 312
  • [32] An ID-based authentication scheme to achieve the security of smart card
    Xu N.
    Huang H.
    Li Z.
    Wang Y.
    Sha C.
    International Journal of Security and Networks, 2018, 13 (01) : 42 - 50
  • [33] A robust authentication scheme for telecare medical information systems
    Madhusudhan, R.
    Nayak, Chaitanya S.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (11) : 15255 - 15273
  • [34] DoS-resistant ID-based password authentication scheme using smart cards
    Hwang, Min-Shiang
    Chong, Song-Kong
    Chen, Te-Yu
    JOURNAL OF SYSTEMS AND SOFTWARE, 2010, 83 (01) : 163 - 172
  • [35] An Improved Biometrics-Based Authentication Scheme for Telecare Medical Information Systems
    Guo, Dianli
    Wen, Qiaoyan
    Li, Wenmin
    Zhang, Hua
    Jin, Zhengping
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
  • [36] An Improved Biometrics-Based Authentication Scheme for Telecare Medical Information Systems
    Dianli Guo
    Qiaoyan Wen
    Wenmin Li
    Hua Zhang
    Zhengping Jin
    Journal of Medical Systems, 2015, 39
  • [37] Security Analysis of Three Password Authentication Schemes
    Shim, Kyung-Ah
    JOURNAL OF UNIVERSAL COMPUTER SCIENCE, 2011, 17 (11) : 1623 - 1633
  • [38] Security Analysis of Two Password Authentication Schemes
    Tan, Zuowen
    EIGHTH INTERNATIONAL CONFERENCE ON MOBILE BUSINESS, PROCEEDINGS, 2009, : 62 - 62
  • [39] Security weaknesses of dynamic ID-based remote user authentication protocol
    Lee, Hyoungseob
    Choi, Donghyun
    Lee, Yunho
    Won, Dongho
    Kim, Seungjoo
    World Academy of Science, Engineering and Technology, 2009, 35 : 190 - 193
  • [40] Security enhancement for a dynamic ID-based remote user authentication scheme
    Liao, IE
    Lee, CC
    Hwang, MS
    International Conference on Next Generation Web Services Practices, 2005, : 437 - 440