Literature DB >> 23660745

A secure and efficient uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.

Ashok Kumar Das1, Adrijit Goswami.   

Abstract

Connected health care has several applications including telecare medicine information system, personally controlled health records system, and patient monitoring. In such applications, user authentication can ensure the legality of patients. In user authentication for such applications, only the legal user/patient himself/herself is allowed to access the remote server, and no one can trace him/her according to transmitted data. Chang et al. proposed a uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care (Chang et al., J Med Syst 37:9902, 2013). Their scheme uses the user's personal biometrics along with his/her password with the help of the smart card. The user's biometrics is verified using BioHashing. Their scheme is efficient due to usage of one-way hash function and exclusive-or (XOR) operations. In this paper, we show that though their scheme is very efficient, their scheme has several security weaknesses such as (1) it has design flaws in login and authentication phases, (2) it has design flaws in password change phase, (3) it fails to protect privileged insider attack, (4) it fails to protect the man-in-the middle attack, and (5) it fails to provide proper authentication. In order to remedy these security weaknesses in Chang et al.'s scheme, we propose an improvement of their scheme while retaining the original merit of their scheme. We show that our scheme is efficient as compared to Chang et al.'s scheme. Through the security analysis, we show that our scheme is secure against possible attacks. Further, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool to ensure that our scheme is secure against passive and active attacks. In addition, after successful authentication between the user and the server, they establish a secret session key shared between them for future secure communication.

Entities:  

Mesh:

Year:  2013        PMID: 23660745     DOI: 10.1007/s10916-013-9948-1

Source DB:  PubMed          Journal:  J Med Syst        ISSN: 0148-5598            Impact factor:   4.460


  1 in total

1.  A uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.

Authors:  Ya-Fen Chang; Shih-Hui Yu; Ding-Rui Shiao
Journal:  J Med Syst       Date:  2013-01-15       Impact factor: 4.460

  1 in total
  31 in total

1.  Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems.

Authors:  Ruhul Amin; S K Hafizul Islam; G P Biswas; Muhammad Khurram Khan; Xiong Li
Journal:  J Med Syst       Date:  2015-09-05       Impact factor: 4.460

2.  A secure and robust password-based remote user authentication scheme using smart cards for the integrated EPR information system.

Authors:  Ashok Kumar Das
Journal:  J Med Syst       Date:  2015-02-10       Impact factor: 4.460

3.  A robust uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.

Authors:  Fengtong Wen
Journal:  J Med Syst       Date:  2013-10-23       Impact factor: 4.460

4.  An improved and effective secure password-based authentication and key agreement scheme using smart cards for the telecare medicine information system.

Authors:  Ashok Kumar Das; Bezawada Bruhadeshwar
Journal:  J Med Syst       Date:  2013-09-06       Impact factor: 4.460

5.  On the security flaws in ID-based password authentication schemes for telecare medical information systems.

Authors:  Dheerendra Mishra
Journal:  J Med Syst       Date:  2014-11-23       Impact factor: 4.460

6.  Meeting the security requirements of electronic medical records in the ERA of high-speed computing.

Authors:  H O Alanazi; A A Zaidan; B B Zaidan; M L Mat Kiah; S H Al-Bakri
Journal:  J Med Syst       Date:  2014-12-07       Impact factor: 4.460

7.  Three-factor anonymous authentication and key agreement scheme for Telecare Medicine Information Systems.

Authors:  Hamed Arshad; Morteza Nikooghadam
Journal:  J Med Syst       Date:  2014-10-29       Impact factor: 4.460

8.  A security framework for nationwide health information exchange based on telehealth strategy.

Authors:  B B Zaidan; Ahmed Haiqi; A A Zaidan; Mohamed Abdulnabi; M L Mat Kiah; Hussaen Muzamel
Journal:  J Med Syst       Date:  2015-03-03       Impact factor: 4.460

9.  A Double Chaotic Layer Encryption Algorithm for Clinical Signals in Telemedicine.

Authors:  M A Murillo-Escobar; L Cardoza-Avendaño; R M López-Gutiérrez; C Cruz-Hernández
Journal:  J Med Syst       Date:  2017-02-28       Impact factor: 4.460

10.  On the security of two remote user authentication schemes for telecare medical information systems.

Authors:  Kee-Won Kim; Jae-Dong Lee
Journal:  J Med Syst       Date:  2014-04-29       Impact factor: 4.460

View more

北京卡尤迪生物科技股份有限公司 © 2022-2023.