Suppr超能文献

关于远程医疗信息系统的两种远程用户认证方案的安全性

On the security of two remote user authentication schemes for telecare medical information systems.

作者信息

Kim Kee-Won, Lee Jae-Dong

机构信息

College of Convergence Technology, Dankook University, Cheonan, 330-714, Korea,

出版信息

J Med Syst. 2014 May;38(5):17. doi: 10.1007/s10916-014-0017-1. Epub 2014 Apr 29.

Abstract

The telecare medical information systems (TMISs) support convenient and rapid health-care services. A secure and efficient authentication scheme for TMIS provides safeguarding patients' electronic patient records (EPRs) and helps health care workers and medical personnel to rapidly making correct clinical decisions. Recently, Kumari et al. proposed a password based user authentication scheme using smart cards for TMIS, and claimed that the proposed scheme could resist various malicious attacks. However, we point out that their scheme is still vulnerable to lost smart card and cannot provide forward secrecy. Subsequently, Das and Goswami proposed a secure and efficient uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care. They simulated their scheme for the formal security verification using the widely-accepted automated validation of Internet security protocols and applications (AVISPA) tool to ensure that their scheme is secure against passive and active attacks. However, we show that their scheme is still vulnerable to smart card loss attacks and cannot provide forward secrecy property. The proposed cryptanalysis discourages any use of the two schemes under investigation in practice and reveals some subtleties and challenges in designing this type of schemes.

摘要

远程医疗信息系统(TMIS)支持便捷快速的医疗服务。为TMIS设计一个安全高效的认证方案有助于保护患者的电子病历(EPR),并帮助医护人员迅速做出正确的临床决策。最近,库马里等人提出了一种基于密码的、使用智能卡的TMIS用户认证方案,并声称该方案能够抵御各种恶意攻击。然而,我们指出他们的方案仍然容易受到智能卡丢失的影响,并且无法提供前向保密性。随后,达斯和戈斯瓦米提出了一种用于互联医疗保健的安全高效的保持唯一性和匿名性的远程用户认证方案。他们使用广泛接受的互联网安全协议和应用自动验证(AVISPA)工具对其方案进行了形式化安全验证模拟,以确保该方案能够抵御被动和主动攻击。然而,我们表明他们的方案仍然容易受到智能卡丢失攻击,并且无法提供前向保密性。本文提出的密码分析不鼓励在实际中使用所研究的这两种方案,并揭示了设计此类方案中的一些微妙之处和挑战。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验