A Secure and Robust Password-Based Remote User Authentication Scheme Using Smart Cards for the Integrated EPR Information System

被引:0
|
作者
Ashok Kumar Das
机构
[1] Center for Security,
[2] Theory and Algorithmic Research International Institute of Information Technology,undefined
来源
关键词
Integrated EPR information system; User authentication; Password; Mutual authentication; Hash function; Security; Smart cards; AVISPA;
D O I
暂无
中图分类号
学科分类号
摘要
An integrated EPR (Electronic Patient Record) information system of all the patients provides the medical institutions and the academia with most of the patients’ information in details for them to make corrective decisions and clinical decisions in order to maintain and analyze patients’ health. In such system, the illegal access must be restricted and the information from theft during transmission over the insecure Internet must be prevented. Lee et al. proposed an efficient password-based remote user authentication scheme using smart card for the integrated EPR information system. Their scheme is very efficient due to usage of one-way hash function and bitwise exclusive-or (XOR) operations. However, in this paper, we show that though their scheme is very efficient, their scheme has three security weaknesses such as (1) it has design flaws in password change phase, (2) it fails to protect privileged insider attack and (3) it lacks the formal security verification. We also find that another recently proposed Wen’s scheme has the same security drawbacks as in Lee at al.’s scheme. In order to remedy these security weaknesses found in Lee et al.’s scheme and Wen’s scheme, we propose a secure and efficient password-based remote user authentication scheme using smart cards for the integrated EPR information system. We show that our scheme is also efficient as compared to Lee et al.’s scheme and Wen’s scheme as our scheme only uses one-way hash function and bitwise exclusive-or (XOR) operations. Through the security analysis, we show that our scheme is secure against possible known attacks. Furthermore, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and show that our scheme is secure against passive and active attacks.
引用
收藏
相关论文
共 50 条
  • [1] A Secure and Robust Password-Based Remote User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Das, Ashok Kumar
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
  • [2] A Secure and Efficient Password-Based User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Tian-Fu Lee
    I-Pin Chang
    Tsung-Hung Lin
    Ching-Cheng Wang
    [J]. Journal of Medical Systems, 2013, 37
  • [3] A Secure and Efficient Password-Based User Authentication Scheme Using Smart Cards for the Integrated EPR Information System
    Lee, Tian-Fu
    Chang, I-Pin
    Lin, Tsung-Hung
    Wang, Ching-Cheng
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (03)
  • [4] A SECURE PASSWORD-BASED REMOTE USER AUTHENTICATION SCHEME WITHOUT SMART CARDS
    Chen, Bae-Ling
    Kuo, Wen-Chung
    Wuu, Lih-Chyau
    [J]. INFORMATION TECHNOLOGY AND CONTROL, 2012, 41 (01): : 53 - 59
  • [5] A Password-Based User Authentication Scheme for the Integrated EPR Information System
    Zhen-Yu Wu
    Yufang Chung
    Feipei Lai
    Tzer-Shyong Chen
    [J]. Journal of Medical Systems, 2012, 36 : 631 - 638
  • [6] A Password-Based User Authentication Scheme for the Integrated EPR Information System
    Wu, Zhen-Yu
    Chung, Yufang
    Lai, Feipei
    Chen, Tzer-Shyong
    [J]. JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (02) : 631 - 638
  • [7] Password-based access control scheme with remote user authentication using smart cards
    Yang, Chen
    Ma, Wenping
    Huang, Benxiong
    Wang, Xinmei
    [J]. 21ST INTERNATIONAL CONFERENCE ON ADVANCED NETWORKING AND APPLICATIONS WORKSHOPS/SYMPOSIA, VOL 2, PROCEEDINGS, 2007, : 448 - +
  • [8] Secure Password-Based Remote User Authentication Scheme with Non-tamper Resistant Smart Cards
    Wang, Ding
    Ma, Chun-guang
    Wu, Peng
    [J]. DATA AND APPLICATIONS SECURITY AND PRIVACY XXVI, 2012, 7371 : 114 - 121
  • [9] Cryptanalysis and improvement of a password-based user authentication scheme for the integrated EPR information system
    Islam, S. K. Hafizul
    Biswas, G. P.
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2015, 27 (02) : 211 - 221
  • [10] A secure password-based authentication and key agreement scheme using smart cards
    Mishra, Dheerendra
    Das, Ashok Kumar
    Chaturvedi, Ankita
    Mukhopadhyay, Sourav
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2015, 23 : 28 - 43