Xie Qi, Zhang Jun, Dong Na
School of Information Science and Engineering, Hangzhou Normal University, Hangzhou, 310036, China,
J Med Syst. 2013 Apr;37(2):9911. doi: 10.1007/s10916-012-9911-6. Epub 2013 Jan 16.
Patient can obtain sorts of health-care delivery services via Telecare Medical Information Systems (TMIS). Authentication, security, patient's privacy protection and data confidentiality are important for patient or doctor accessing to Electronic Medical Records (EMR). In 2012, Chen et al. showed that Khan et al.'s dynamic ID-based authentication scheme has some weaknesses and proposed an improved scheme, and they claimed that their scheme is more suitable for TMIS. However, we show that Chen et al.'s scheme also has some weaknesses. In particular, Chen et al.'s scheme does not provide user's privacy protection and perfect forward secrecy, is vulnerable to off-line password guessing attack and impersonation attack once user's smart card is compromised. Further, we propose a secure anonymity authentication scheme to overcome their weaknesses even an adversary can know all information stored in smart card.
患者可以通过远程医疗信息系统(TMIS)获得各种医疗保健服务。认证、安全、患者隐私保护和数据保密性对于患者或医生访问电子病历(EMR)而言至关重要。2012年,Chen等人指出Khan等人基于动态ID的认证方案存在一些弱点,并提出了一种改进方案,他们声称自己的方案更适用于TMIS。然而,我们发现Chen等人的方案也存在一些弱点。具体而言,Chen等人的方案没有提供用户隐私保护和完美前向保密性,一旦用户的智能卡受到攻击,该方案容易受到离线密码猜测攻击和身份冒用攻击。此外,我们提出了一种安全匿名认证方案,即使对手能够知晓存储在智能卡中的所有信息,也能克服这些弱点。