• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

远程医疗信息系统隐私认证方案的安全性分析与改进。

Security analysis and improvement of a privacy authentication scheme for telecare medical information systems.

机构信息

Department of Computer Science and Engineering, Xiamen Institute of Technology, Huaqiao University, Xiamen, 361021, China,

出版信息

J Med Syst. 2013 Aug;37(4):9958. doi: 10.1007/s10916-013-9958-z. Epub 2013 Jul 2.

DOI:10.1007/s10916-013-9958-z
PMID:23818249
Abstract

Nowadays, patients can gain many kinds of medical service on line via Telecare Medical Information Systems(TMIS) due to the fast development of computer technology. So security of communication through network between the users and the server is very significant. Authentication plays an important part to protect information from being attacked by malicious attackers. Recently, Jiang et al. proposed a privacy enhanced scheme for TMIS using smart cards and claimed their scheme was better than Chen et al.'s. However, we have showed that Jiang et al.'s scheme has the weakness of ID uselessness and is vulnerable to off-line password guessing attack and user impersonation attack if an attacker compromises the legal user's smart card. Also, it can't resist DoS attack in two cases: after a successful impersonation attack and wrong password input in Password change phase. Then we propose an improved mutual authentication scheme used for a telecare medical information system. Remote monitoring, checking patients' past medical history record and medical consultant can be applied in the system where information transmits via Internet. Finally, our analysis indicates that the suggested scheme overcomes the disadvantages of Jiang et al.'s scheme and is practical for TMIS.

摘要

如今,由于计算机技术的飞速发展,患者可以通过远程医疗信息系统(TMIS)在线获得多种医疗服务。因此,用户与服务器之间通过网络进行通信的安全性非常重要。认证对于保护信息免受恶意攻击者的攻击起着重要作用。最近,Jiang 等人提出了一种使用智能卡的 TMIS 隐私增强方案,并声称他们的方案优于 Chen 等人的方案。然而,我们已经表明,如果攻击者破坏了合法用户的智能卡,Jiang 等人的方案存在 ID 无用性的弱点,并且容易受到离线密码猜测攻击和用户冒充攻击。此外,如果在密码更改阶段发生成功的冒充攻击和错误的密码输入,它也无法抵抗两种情况下的拒绝服务攻击。然后,我们提出了一种改进的用于远程医疗信息系统的相互认证方案。该系统可用于远程监控、检查患者的既往病史记录和医疗咨询,信息通过互联网传输。最后,我们的分析表明,所提出的方案克服了 Jiang 等人方案的缺点,适用于 TMIS。

相似文献

1
Security analysis and improvement of a privacy authentication scheme for telecare medical information systems.远程医疗信息系统隐私认证方案的安全性分析与改进。
J Med Syst. 2013 Aug;37(4):9958. doi: 10.1007/s10916-013-9958-z. Epub 2013 Jul 2.
2
Improved dynamic ID-based authentication scheme for telecare medical information systems.用于远程医疗信息系统的改进型基于动态身份的认证方案。
J Med Syst. 2013 Apr;37(2):9912. doi: 10.1007/s10916-012-9912-5. Epub 2013 Jan 24.
3
Robust anonymous authentication scheme for telecare medical information systems.远程医疗信息系统的健壮匿名认证方案
J Med Syst. 2013 Apr;37(2):9911. doi: 10.1007/s10916-012-9911-6. Epub 2013 Jan 16.
4
An efficient authentication scheme for telecare medicine information systems.远程医疗保健信息系统的高效认证方案。
J Med Syst. 2012 Dec;36(6):3833-8. doi: 10.1007/s10916-012-9856-9. Epub 2012 Apr 25.
5
Cryptanalysis and improvement of 'A privacy enhanced scheme for telecare medical information systems'.《远程医疗信息系统的一种隐私增强方案》的密码分析与改进
J Med Syst. 2013 Aug;37(4):9952. doi: 10.1007/s10916-013-9952-5. Epub 2013 May 22.
6
Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems.用于远程医疗信息系统的基于密码的安全匿名用户认证和会话密钥协商方案。
Comput Methods Programs Biomed. 2016 Oct;135:167-85. doi: 10.1016/j.cmpb.2016.07.028. Epub 2016 Jul 29.
7
A secure chaotic maps and smart cards based password authentication and key agreement scheme with user anonymity for telecare medicine information systems.一种基于安全混沌映射和智能卡的用于远程医疗信息系统的具有用户匿名性的密码认证和密钥协商方案。
J Med Syst. 2014 Sep;38(9):77. doi: 10.1007/s10916-014-0077-2. Epub 2014 Jul 6.
8
A privacy enhanced authentication scheme for telecare medical information systems.一种用于远程医疗信息系统的隐私增强认证方案。
J Med Syst. 2013 Feb;37(1):9897. doi: 10.1007/s10916-012-9897-0. Epub 2013 Jan 12.
9
An improved anonymous authentication scheme for telecare medical information systems.一种用于远程医疗信息系统的改进型匿名认证方案。
J Med Syst. 2014 May;38(5):26. doi: 10.1007/s10916-014-0026-0. Epub 2014 Apr 30.
10
Security analysis of a chaotic map-based authentication scheme for telecare medicine information systems.远程医疗信息系统中基于混沌映射的认证方案的安全性分析
J Med Syst. 2013 Dec;37(6):9993. doi: 10.1007/s10916-013-9993-9. Epub 2013 Nov 6.

引用本文的文献

1
A construction of a conformal Chebyshev chaotic map based authentication protocol for healthcare telemedicine services.一种用于医疗远程医疗服务的基于共形切比雪夫混沌映射的认证协议构建。
Complex Intell Systems. 2021;7(5):2531-2542. doi: 10.1007/s40747-021-00441-7. Epub 2021 Jun 19.
2
Ethical Implications of User Perceptions of Wearable Devices.可穿戴设备用户感知的伦理问题
Sci Eng Ethics. 2018 Feb;24(1):1-28. doi: 10.1007/s11948-017-9872-8. Epub 2017 Feb 2.
3
Design and Analysis of an Enhanced Patient-Server Mutual Authentication Protocol for Telecare Medical Information System.

本文引用的文献

1
On the security of a dynamic ID-based authentication scheme for telecare medical information systems.关于远程医疗信息系统中基于动态身份的认证方案的安全性
J Med Syst. 2013 Apr;37(2):9929. doi: 10.1007/s10916-013-9929-4. Epub 2013 Jan 24.
2
Improved dynamic ID-based authentication scheme for telecare medical information systems.用于远程医疗信息系统的改进型基于动态身份的认证方案。
J Med Syst. 2013 Apr;37(2):9912. doi: 10.1007/s10916-012-9912-5. Epub 2013 Jan 24.
3
Robust anonymous authentication scheme for telecare medical information systems.
远程医疗信息系统中增强的医患相互认证协议的设计与分析。
J Med Syst. 2015 Nov;39(11):137. doi: 10.1007/s10916-015-0307-2. Epub 2015 Sep 1.
4
On the Security of a Two-Factor Authentication and Key Agreement Scheme for Telecare Medicine Information Systems.远程医疗信息系统中基于双因素认证和密钥协商方案的安全性研究
J Med Syst. 2015 Aug;39(8):76. doi: 10.1007/s10916-015-0259-6. Epub 2015 Jun 18.
5
A novel authentication scheme using self-certified public keys for telecare medical information systems.一种用于远程医疗信息系统的使用自认证公钥的新型认证方案。
J Med Syst. 2015 Jun;39(6):62. doi: 10.1007/s10916-015-0245-z. Epub 2015 Apr 2.
6
Robust ECC-based authenticated key agreement scheme with privacy protection for Telecare medicine information systems.基于鲁棒 ECC 的带隐私保护的认证密钥协商方案在远程医疗信息系统中的应用。
J Med Syst. 2015 May;39(5):49. doi: 10.1007/s10916-015-0233-3. Epub 2015 Mar 3.
7
An enhanced biometric-based authentication scheme for telecare medicine information systems using elliptic curve cryptosystem.一种使用椭圆曲线密码系统的远程医疗信息系统增强型基于生物特征的认证方案。
J Med Syst. 2015 Mar;39(3):32. doi: 10.1007/s10916-015-0221-7. Epub 2015 Feb 14.
8
The current and future needs of our medical systems.我们医疗系统当前及未来的需求。
J Med Syst. 2015 Feb;39(2):16. doi: 10.1007/s10916-015-0212-8. Epub 2015 Feb 1.
9
Cryptanalysis and improvement of a user authentication scheme preserving uniqueness and anonymity for connected health care.用于连接式医疗保健的保持唯一性和匿名性的用户认证方案的密码分析与改进
J Med Syst. 2015 Feb;39(2):10. doi: 10.1007/s10916-014-0179-x. Epub 2015 Jan 29.
10
On the security flaws in ID-based password authentication schemes for telecare medical information systems.关于远程医疗信息系统中基于身份的密码认证方案的安全漏洞。
J Med Syst. 2015 Jan;39(1):154. doi: 10.1007/s10916-014-0154-6. Epub 2014 Nov 23.
远程医疗信息系统的健壮匿名认证方案
J Med Syst. 2013 Apr;37(2):9911. doi: 10.1007/s10916-012-9911-6. Epub 2013 Jan 16.
4
A privacy enhanced authentication scheme for telecare medical information systems.一种用于远程医疗信息系统的隐私增强认证方案。
J Med Syst. 2013 Feb;37(1):9897. doi: 10.1007/s10916-012-9897-0. Epub 2013 Jan 12.
5
An efficient and secure dynamic ID-based authentication scheme for telecare medical information systems.用于远程医疗信息系统的高效安全的动态 ID 基于身份的认证方案。
J Med Syst. 2012 Dec;36(6):3907-15. doi: 10.1007/s10916-012-9862-y. Epub 2012 Jun 7.
6
An efficient authentication scheme for telecare medicine information systems.远程医疗保健信息系统的高效认证方案。
J Med Syst. 2012 Dec;36(6):3833-8. doi: 10.1007/s10916-012-9856-9. Epub 2012 Apr 25.
7
An improved authentication scheme for telecare medicine information systems.远程医疗信息系统的改进型认证方案。
J Med Syst. 2012 Dec;36(6):3597-604. doi: 10.1007/s10916-012-9835-1. Epub 2012 Feb 29.
8
A more secure authentication scheme for telecare medicine information systems.远程医疗保健信息系统的更安全认证方案。
J Med Syst. 2012 Jun;36(3):1989-95. doi: 10.1007/s10916-011-9658-5. Epub 2011 Mar 1.
9
A secure authentication scheme for telecare medicine information systems.远程医疗保健信息系统的安全认证方案。
J Med Syst. 2012 Jun;36(3):1529-35. doi: 10.1007/s10916-010-9614-9. Epub 2010 Oct 27.