Literature DB >> 27586489

Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems.

Anil Kumar Sutrala1, Ashok Kumar Das2, Vanga Odelu3, Mohammad Wazid1, Saru Kumari4.   

Abstract

BACKGROUND AND OBJECTIVES: Information and communication and technology (ICT) has changed the entire paradigm of society. ICT facilitates people to use medical services over the Internet, thereby reducing the travel cost, hospitalization cost and time to a greater extent. Recent advancements in Telecare Medicine Information System (TMIS) facilitate users/patients to access medical services over the Internet by gaining health monitoring facilities at home.
METHODS: Amin and Biswas recently proposed a RSA-based user authentication and session key agreement protocol usable for TMIS, which is an improvement over Giri et al.'s RSA-based user authentication scheme for TMIS. In this paper, we show that though Amin-Biswas's scheme considerably improves the security drawbacks of Giri et al.'s scheme, their scheme has security weaknesses as it suffers from attacks such as privileged insider attack, user impersonation attack, replay attack and also offline password guessing attack. A new RSA-based user authentication scheme for TMIS is proposed, which overcomes the security pitfalls of Amin-Biswas's scheme and also preserves user anonymity property.
RESULTS: The careful formal security analysis using the two widely accepted Burrows-Abadi-Needham (BAN) logic and the random oracle models is done. Moreover, the informal security analysis of the scheme is also done. These security analyses show the robustness of our new scheme against the various known attacks as well as attacks found in Amin-Biswas's scheme. The simulation of the proposed scheme using the widely accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is also done.
CONCLUSIONS: We present a new user authentication and session key agreement scheme for TMIS, which fixes the mentioned security pitfalls found in Amin-Biswas's scheme, and we also show that the proposed scheme provides better security than other existing schemes through the rigorous security analysis and verification tool. Furthermore, we present the formal security verification of our scheme using the widely accepted AVISPA tool. High security and extra functionality features allow our proposed scheme to be applicable for telecare medicine information systems which is used for e-health care medical applications.
Copyright © 2016 Elsevier Ireland Ltd. All rights reserved.

Entities:  

Keywords:  AVISPA; Authentication; BAN logic; Security; Telecare medicine information systems; User anonymity

Mesh:

Year:  2016        PMID: 27586489     DOI: 10.1016/j.cmpb.2016.07.028

Source DB:  PubMed          Journal:  Comput Methods Programs Biomed        ISSN: 0169-2607            Impact factor:   5.428


  6 in total

1.  An Efficient Mutual Authentication Framework for Healthcare System in Cloud Computing.

Authors:  Vinod Kumar; Srinivas Jangirala; Musheer Ahmad
Journal:  J Med Syst       Date:  2018-06-28       Impact factor: 4.460

2.  A Robust and Efficient ECC-based Mutual Authentication and Session Key Generation Scheme for Healthcare Applications.

Authors:  Arezou Ostad-Sharif; Dariush Abbasinezhad-Mood; Morteza Nikooghadam
Journal:  J Med Syst       Date:  2018-12-01       Impact factor: 4.460

3.  Analysis of Security Protocols for Mobile Healthcare.

Authors:  Mohammad Wazid; Sherali Zeadally; Ashok Kumar Das; Vanga Odelu
Journal:  J Med Syst       Date:  2016-09-17       Impact factor: 4.460

4.  A Standard Mutual Authentication Protocol for Cloud Computing Based Health Care System.

Authors:  Prerna Mohit; Ruhul Amin; Arijit Karati; G P Biswas; Muhammad Khurram Khan
Journal:  J Med Syst       Date:  2017-02-17       Impact factor: 4.460

5.  Security analysis and enhanced user authentication in proxy mobile IPv6 networks.

Authors:  Dongwoo Kang; Jaewook Jung; Donghoon Lee; Hyoungshick Kim; Dongho Won
Journal:  PLoS One       Date:  2017-07-18       Impact factor: 3.240

6.  An enhanced password authentication scheme for session initiation protocol with perfect forward secrecy.

Authors:  Shuming Qiu; Guoai Xu; Haseeb Ahmad; Yanhui Guo
Journal:  PLoS One       Date:  2018-03-16       Impact factor: 3.240

  6 in total

北京卡尤迪生物科技股份有限公司 © 2022-2023.