Literature DB >> 25666924

A secure and robust password-based remote user authentication scheme using smart cards for the integrated EPR information system.

Ashok Kumar Das1.   

Abstract

An integrated EPR (Electronic Patient Record) information system of all the patients provides the medical institutions and the academia with most of the patients' information in details for them to make corrective decisions and clinical decisions in order to maintain and analyze patients' health. In such system, the illegal access must be restricted and the information from theft during transmission over the insecure Internet must be prevented. Lee et al. proposed an efficient password-based remote user authentication scheme using smart card for the integrated EPR information system. Their scheme is very efficient due to usage of one-way hash function and bitwise exclusive-or (XOR) operations. However, in this paper, we show that though their scheme is very efficient, their scheme has three security weaknesses such as (1) it has design flaws in password change phase, (2) it fails to protect privileged insider attack and (3) it lacks the formal security verification. We also find that another recently proposed Wen's scheme has the same security drawbacks as in Lee at al.'s scheme. In order to remedy these security weaknesses found in Lee et al.'s scheme and Wen's scheme, we propose a secure and efficient password-based remote user authentication scheme using smart cards for the integrated EPR information system. We show that our scheme is also efficient as compared to Lee et al.'s scheme and Wen's scheme as our scheme only uses one-way hash function and bitwise exclusive-or (XOR) operations. Through the security analysis, we show that our scheme is secure against possible known attacks. Furthermore, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and show that our scheme is secure against passive and active attacks.

Entities:  

Mesh:

Year:  2015        PMID: 25666924     DOI: 10.1007/s10916-015-0204-8

Source DB:  PubMed          Journal:  J Med Syst        ISSN: 0148-5598            Impact factor:   4.460


  8 in total

1.  On the security flaws in ID-based password authentication schemes for telecare medical information systems.

Authors:  Dheerendra Mishra
Journal:  J Med Syst       Date:  2014-11-23       Impact factor: 4.460

2.  A secure and efficient chaotic map-based authenticated key agreement scheme for telecare medicine information systems.

Authors:  Dheerendra Mishra; Jangirala Srinivas; Sourav Mukhopadhyay
Journal:  J Med Syst       Date:  2014-08-16       Impact factor: 4.460

3.  A more secure anonymous user authentication scheme for the integrated EPR information system.

Authors:  Fengtong Wen
Journal:  J Med Syst       Date:  2014-04-24       Impact factor: 4.460

4.  Security enhancement of a biometric based authentication scheme for telecare medicine information systems with nonce.

Authors:  Dheerendra Mishra; Sourav Mukhopadhyay; Saru Kumari; Muhammad Khurram Khan; Ankita Chaturvedi
Journal:  J Med Syst       Date:  2014-04-26       Impact factor: 4.460

5.  A password-based user authentication scheme for the integrated EPR information system.

Authors:  Zhen-Yu Wu; Yufang Chung; Feipei Lai; Tzer-Shyong Chen
Journal:  J Med Syst       Date:  2010-05-27       Impact factor: 4.460

6.  A uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.

Authors:  Ya-Fen Chang; Shih-Hui Yu; Ding-Rui Shiao
Journal:  J Med Syst       Date:  2013-01-15       Impact factor: 4.460

7.  A secure and efficient password-based user authentication scheme using smart cards for the integrated EPR information system.

Authors:  Tian-Fu Lee; I-Pin Chang; Tsung-Hung Lin; Ching-Cheng Wang
Journal:  J Med Syst       Date:  2013-04-04       Impact factor: 4.460

8.  A secure and efficient uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.

Authors:  Ashok Kumar Das; Adrijit Goswami
Journal:  J Med Syst       Date:  2013-05-10       Impact factor: 4.460

  8 in total
  4 in total

1.  A Hash Based Remote User Authentication and Authenticated Key Agreement Scheme for the Integrated EPR Information System.

Authors:  Chun-Ta Li; Chi-Yao Weng; Cheng-Chi Lee; Chun-Cheng Wang
Journal:  J Med Syst       Date:  2015-09-09       Impact factor: 4.460

2.  A Secure User Anonymity and Authentication Scheme Using AVISPA for Telecare Medical Information Systems.

Authors:  Omid Mir; Theo van der Weide; Cheng-Chi Lee
Journal:  J Med Syst       Date:  2015-08-05       Impact factor: 4.460

3.  Cryptanalysis and improvement of an improved two factor authentication protocol for telecare medical information systems.

Authors:  Shehzad Ashraf Chaudhry; Husnain Naqvi; Taeshik Shon; Muhammad Sher; Mohammad Sabzinejad Farash
Journal:  J Med Syst       Date:  2015-04-26       Impact factor: 4.460

4.  An Improved and Secure Anonymous Biometric-Based User Authentication with Key Agreement Scheme for the Integrated EPR Information System.

Authors:  Jaewook Jung; Dongwoo Kang; Donghoon Lee; Dongho Won
Journal:  PLoS One       Date:  2017-01-03       Impact factor: 3.240

  4 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.