King Saud University, PO Box 92144, Riyadh, 11653, Kingdom of Saudi Arabia,
J Med Syst. 2013 Aug;37(4):9954. doi: 10.1007/s10916-013-9954-3. Epub 2013 Jul 5.
Last few decades have witnessed boom in the development of information and communication technologies. Health-sector has also been benefitted with this advancement. To ensure secure access to healthcare services some user authentication mechanisms have been proposed. In 2012, Wei et al. proposed a user authentication scheme for telecare medical information system (TMIS). Recently, Zhu pointed out offline password guessing attack on Wei et al.'s scheme and proposed an improved scheme. In this article, we analyze both of these schemes for their effectiveness in TMIS. We show that Wei et al.'s scheme and its improvement proposed by Zhu fail to achieve some important characteristics necessary for secure user authentication. We find that security problems of Wei et al.'s scheme stick with Zhu's scheme; like undetectable online password guessing attack, inefficacy of password change phase, traceability of user's stolen/lost smart card and denial-of-service threat. We also identify that Wei et al.'s scheme lacks forward secrecy and Zhu's scheme lacks session key between user and healthcare server. We therefore propose an authentication scheme for TMIS with forward secrecy which preserves the confidentiality of air messages even if master secret key of healthcare server is compromised. Our scheme retains advantages of Wei et al.'s scheme and Zhu's scheme, and offers additional security. The security analysis and comparison results show the enhanced suitability of our scheme for TMIS.
过去几十年见证了信息和通信技术的蓬勃发展。医疗保健领域也受益于这一进步。为了确保对医疗服务的安全访问,已经提出了一些用户认证机制。2012 年,Wei 等人提出了远程医疗信息系统(TMIS)的用户认证方案。最近,Zhu 指出了 Wei 等人的方案存在离线密码猜测攻击,并提出了一个改进的方案。在本文中,我们分析了这两种方案在 TMIS 中的有效性。我们表明,Wei 等人的方案及其由 Zhu 提出的改进方案未能实现安全用户认证所需的一些重要特性。我们发现 Wei 等人的方案的安全问题仍然存在于 Zhu 的方案中,如在线密码猜测攻击不可检测、密码更改阶段无效、用户被盗/丢失的智能卡的可追踪性和拒绝服务威胁。我们还发现 Wei 等人的方案缺乏前向保密性,而 Zhu 的方案缺乏用户和医疗保健服务器之间的会话密钥。因此,我们提出了一种具有前向保密性的 TMIS 认证方案,即使医疗保健服务器的主密钥被泄露,也能保护空中消息的机密性。我们的方案保留了 Wei 等人的方案和 Zhu 的方案的优点,并提供了额外的安全性。安全性分析和比较结果表明,我们的方案更适合 TMIS。