A Secure and Robust Password-Based Remote User Authentication Scheme Using Smart Cards for the Integrated EPR Information System

被引:0
|
作者
Ashok Kumar Das
机构
[1] Center for Security,
[2] Theory and Algorithmic Research International Institute of Information Technology,undefined
来源
关键词
Integrated EPR information system; User authentication; Password; Mutual authentication; Hash function; Security; Smart cards; AVISPA;
D O I
暂无
中图分类号
学科分类号
摘要
An integrated EPR (Electronic Patient Record) information system of all the patients provides the medical institutions and the academia with most of the patients’ information in details for them to make corrective decisions and clinical decisions in order to maintain and analyze patients’ health. In such system, the illegal access must be restricted and the information from theft during transmission over the insecure Internet must be prevented. Lee et al. proposed an efficient password-based remote user authentication scheme using smart card for the integrated EPR information system. Their scheme is very efficient due to usage of one-way hash function and bitwise exclusive-or (XOR) operations. However, in this paper, we show that though their scheme is very efficient, their scheme has three security weaknesses such as (1) it has design flaws in password change phase, (2) it fails to protect privileged insider attack and (3) it lacks the formal security verification. We also find that another recently proposed Wen’s scheme has the same security drawbacks as in Lee at al.’s scheme. In order to remedy these security weaknesses found in Lee et al.’s scheme and Wen’s scheme, we propose a secure and efficient password-based remote user authentication scheme using smart cards for the integrated EPR information system. We show that our scheme is also efficient as compared to Lee et al.’s scheme and Wen’s scheme as our scheme only uses one-way hash function and bitwise exclusive-or (XOR) operations. Through the security analysis, we show that our scheme is secure against possible known attacks. Furthermore, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and show that our scheme is secure against passive and active attacks.
引用
收藏
相关论文
共 50 条
  • [21] Study on A Secure Remote User Authentication Scheme Using Smart Cards
    Jin Qiuyan
    Lee, Kwangwoo
    Won, Dongho
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (02): : 105 - 115
  • [22] A secure remote user mutual authentication scheme using smart cards
    Karuppiah, Marimuthu
    Saravanan, R.
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2014, 19 (4-5) : 282 - 294
  • [23] A secure remote user mutual authentication scheme using smart cards
    Li, Xiong
    Liao, Junguo
    Zhang, Jiao
    Niu, Jianwei
    Kumari, Saru
    [J]. 2014 IEEE COMPUTING, COMMUNICATIONS AND IT APPLICATIONS CONFERENCE (COMCOMAP), 2014, : 89 - 92
  • [24] An Improvement of Secure Remote User Authentication Scheme using Smart Cards
    Mun, Jongho
    Jin, Qiuyan
    Jeon, Woongryul
    Won, Dongho
    [J]. 2013 INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2013,
  • [25] Study on a secure remote user authentication scheme using smart cards
    [J]. Won, D. (dhwon@security.re.kr), 1600, Science and Engineering Research Support Society, 20 Virginia Court, Sandy Bay, Tasmania, Prof B.H.Kang's Office,, Australia (07):
  • [26] Further improvement of an efficient password based remote user authentication scheme using smart cards
    Yoon, EJ
    Ryu, EK
    Yoo, KY
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (02) : 612 - 614
  • [27] Weaknesses and improvements of an efficient password based remote user authentication scheme using smart cards
    Ku, WC
    Chen, SM
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2004, 50 (01) : 204 - 207
  • [28] A New Secure Password Authentication Scheme Using Smart Cards
    WANG Bangju1
    2. School of Science
    3. College of Information Science and Engineering
    Zhengzhou 450001
    [J]. Wuhan University Journal of Natural Sciences, 2008, (06) : 739 - 743
  • [29] A new secure remote user authentication scheme with smart cards
    Kumar, Manoj
    [J]. International Journal of Network Security, 2010, 11 (02) : 88 - 93
  • [30] An efficient and secure biometric remote user authentication scheme using smart cards
    Wang, Xiaomin
    Zhang, Wenfang
    [J]. PACIIA: 2008 PACIFIC-ASIA WORKSHOP ON COMPUTATIONAL INTELLIGENCE AND INDUSTRIAL APPLICATION, VOLS 1-3, PROCEEDINGS, 2008, : 1864 - +