An Authentication Scheme for Secure Access to Healthcare Services

被引:28
作者
Khan, Muhammad Khurram [1 ]
Kumari, Saru [2 ]
机构
[1] King Saud Univ, Riyadh 11653, Saudi Arabia
[2] Agra Coll, Dept Math, Agra, Uttar Pradesh, India
关键词
Healthcare services; Telecare medical information system; Smart card; Forward secrecy; Authentication; INFORMATION; EFFICIENT;
D O I
10.1007/s10916-013-9954-3
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Last few decades have witnessed boom in the development of information and communication technologies. Health-sector has also been benefitted with this advancement. To ensure secure access to healthcare services some user authentication mechanisms have been proposed. In 2012, Wei et al. proposed a user authentication scheme for telecare medical information system (TMIS). Recently, Zhu pointed out offline password guessing attack on Wei et al.'s scheme and proposed an improved scheme. In this article, we analyze both of these schemes for their effectiveness in TMIS. We show that Wei et al.'s scheme and its improvement proposed by Zhu fail to achieve some important characteristics necessary for secure user authentication. We find that security problems of Wei et al.'s scheme stick with Zhu's scheme; like undetectable online password guessing attack, inefficacy of password change phase, traceability of user's stolen/lost smart card and denial-of-service threat. We also identify that Wei et al.'s scheme lacks forward secrecy and Zhu's scheme lacks session key between user and healthcare server. We therefore propose an authentication scheme for TMIS with forward secrecy which preserves the confidentiality of air messages even if master secret key of healthcare server is compromised. Our scheme retains advantages of Wei et al.'s scheme and Zhu's scheme, and offers additional security. The security analysis and comparison results show the enhanced suitability of our scheme for TMIS.
引用
收藏
页数:12
相关论文
共 18 条
[1]  
[Anonymous], 2003, MED DATA MANAGEMENT
[2]   An Efficient and Secure Dynamic ID-based Authentication Scheme for Telecare Medical Information Systems [J].
Chen, Hung-Ming ;
Lo, Jung-Wen ;
Yeh, Chang-Kuo .
JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (06) :3907-3915
[3]  
Dunlop Laura, 2007, SHIDLER J L COM TECH, V3, P16
[4]   Electronic patient records and innovation in health care services [J].
Elberg, PB .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2001, 64 (2-3) :201-205
[5]   A More Secure Authentication Scheme for Telecare Medicine Information Systems [J].
He Debiao ;
Chen Jianhua ;
Zhang Rui .
JOURNAL OF MEDICAL SYSTEMS, 2012, 36 (03) :1989-1995
[6]   Cryptanalysis and security enhancement of a 'more efficient & secure dynamic ID-based remote user authentication scheme' [J].
Khan, Muhammad Khurram ;
Kim, Soo-Kyun ;
Alghathbar, Khaled .
COMPUTER COMMUNICATIONS, 2011, 34 (03) :305-309
[7]  
Kocher P., 1999, Advances in Cryptology - CRYPTO'99. 19th Annual International Cryptology Conference. Proceedings, P388
[8]   Cryptanalysis and security enhancement of Chen et al.'s remote user authentication scheme using smart card [J].
Kumari, Saru ;
Gupta, Mridul K. ;
Kumar, Manoj .
OPEN COMPUTER SCIENCE, 2012, 2 (01) :60-75
[9]   Managing medical and insurance information through a smart-card-based information system [J].
Lambrinoudakis C. ;
Gritzalis S. .
Journal of Medical Systems, 2000, 24 (4) :213-234
[10]   Internet integrated in the daily medical practice within an electronic patient record [J].
Lovis, C ;
Baud, RH ;
Scherrer, JR .
COMPUTERS IN BIOLOGY AND MEDICINE, 1998, 28 (05) :567-579