• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

用于互联医疗保健的一种保持唯一性和匿名性的用户认证方案的改进。

Improvement of a uniqueness-and-anonymity-preserving user authentication scheme for connected health care.

作者信息

Xie Qi, Liu Wenhao, Wang Shengbao, Han Lidong, Hu Bin, Wu Ting

机构信息

Hangzhou Key Laboratory of Cryptography and Network Security, Hangzhou Normal University, Hangzhou, 311121, China,

出版信息

J Med Syst. 2014 Sep;38(9):91. doi: 10.1007/s10916-014-0091-4. Epub 2014 Jul 4.

DOI:10.1007/s10916-014-0091-4
PMID:24994512
Abstract

Patient's privacy-preserving, security and mutual authentication between patient and the medical server are the important mechanism in connected health care applications, such as telecare medical information systems and personally controlled health records systems. In 2013, Wen showed that Das et al.'s scheme is vulnerable to the replay attack, user impersonation attacks and off-line guessing attacks, and then proposed an improved scheme using biometrics, password and smart card to overcome these weaknesses. However, we show that Wen's scheme is still vulnerable to off-line password guessing attacks, does not provide user's anonymity and perfect forward secrecy. Further, we propose an improved scheme to fix these weaknesses, and use the applied pi calculus based formal verification tool ProVerif to prove the security and authentication.

摘要

患者隐私保护、患者与医疗服务器之间的安全性和相互认证是远程医疗保健应用(如远程护理医疗信息系统和个人控制的健康记录系统)中的重要机制。2013年,Wen指出Das等人的方案容易受到重放攻击、用户假冒攻击和离线猜测攻击,随后提出了一种使用生物特征识别、密码和智能卡的改进方案来克服这些弱点。然而,我们表明Wen的方案仍然容易受到离线密码猜测攻击,不提供用户匿名性和完美前向保密性。此外,我们提出了一种改进方案来修复这些弱点,并使用基于应用pi演算的形式化验证工具ProVerif来证明安全性和认证性。

相似文献

1
Improvement of a uniqueness-and-anonymity-preserving user authentication scheme for connected health care.用于互联医疗保健的一种保持唯一性和匿名性的用户认证方案的改进。
J Med Syst. 2014 Sep;38(9):91. doi: 10.1007/s10916-014-0091-4. Epub 2014 Jul 4.
2
Robust anonymous authentication scheme for telecare medical information systems.远程医疗信息系统的健壮匿名认证方案
J Med Syst. 2013 Apr;37(2):9911. doi: 10.1007/s10916-012-9911-6. Epub 2013 Jan 16.
3
Cryptanalysis and improvement of a user authentication scheme preserving uniqueness and anonymity for connected health care.用于连接式医疗保健的保持唯一性和匿名性的用户认证方案的密码分析与改进
J Med Syst. 2015 Feb;39(2):10. doi: 10.1007/s10916-014-0179-x. Epub 2015 Jan 29.
4
A secure and efficient uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.一种用于连接式医疗保健的安全高效的保持唯一性和匿名性的远程用户认证方案。
J Med Syst. 2013 Jun;37(3):9948. doi: 10.1007/s10916-013-9948-1. Epub 2013 May 10.
5
Improved dynamic ID-based authentication scheme for telecare medical information systems.用于远程医疗信息系统的改进型基于动态身份的认证方案。
J Med Syst. 2013 Apr;37(2):9912. doi: 10.1007/s10916-012-9912-5. Epub 2013 Jan 24.
6
A robust uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.一种用于连接式医疗保健的强大的保持唯一性和匿名性的远程用户认证方案。
J Med Syst. 2013 Dec;37(6):9980. doi: 10.1007/s10916-013-9980-1. Epub 2013 Oct 23.
7
On the security of two remote user authentication schemes for telecare medical information systems.关于远程医疗信息系统的两种远程用户认证方案的安全性
J Med Syst. 2014 May;38(5):17. doi: 10.1007/s10916-014-0017-1. Epub 2014 Apr 29.
8
A more secure anonymous user authentication scheme for the integrated EPR information system.一种用于集成电子病历信息系统的更安全的匿名用户认证方案。
J Med Syst. 2014 May;38(5):42. doi: 10.1007/s10916-014-0042-0. Epub 2014 Apr 24.
9
Design of a Secure Authentication and Key Agreement Scheme Preserving User Privacy Usable in Telecare Medicine Information Systems.一种可用于远程医疗信息系统的、保护用户隐私的安全认证与密钥协商方案的设计。
J Med Syst. 2016 Nov;40(11):237. doi: 10.1007/s10916-016-0585-3. Epub 2016 Sep 24.
10
Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems.针对电子医疗保健系统的匿名保护远程用户相互认证和会话密钥协商方案的密码分析与增强。
J Med Syst. 2015 Nov;39(11):140. doi: 10.1007/s10916-015-0318-z. Epub 2015 Sep 5.

引用本文的文献

1
Provably secure and lightweight blockchain based cross hospital authentication scheme for IoMT-based healthcare.用于基于物联网的医疗保健的、可证明安全且轻量级的基于区块链的跨医院认证方案。
Sci Rep. 2025 Feb 22;15(1):6461. doi: 10.1038/s41598-025-90219-5.
2
The Extent and Coverage of Current Knowledge of Connected Health: Systematic Mapping Study.当前互联健康知识的范围与覆盖情况:系统映射研究
J Med Internet Res. 2019 Sep 25;21(9):e14394. doi: 10.2196/14394.
3
A Survey of Authentication Schemes in Telecare Medicine Information Systems.远程医疗信息系统中的认证方案调查

本文引用的文献

1
An enhanced biometric authentication scheme for telecare medicine information systems with nonce using chaotic hash function.一种使用混沌哈希函数的带现时值的远程医疗信息系统增强型生物特征认证方案。
J Med Syst. 2014 Jun;38(6):27. doi: 10.1007/s10916-014-0027-z. Epub 2014 Jun 3.
2
Cryptanalysis and improvement of Yan et al.'s biometric-based authentication scheme for telecare medicine information systems.基于生物特征的远程医疗信息系统中闫等人认证方案的密码分析与改进
J Med Syst. 2014 Jun;38(6):24. doi: 10.1007/s10916-014-0024-2. Epub 2014 Jun 1.
3
An improved anonymous authentication scheme for telecare medical information systems.
J Med Syst. 2017 Jan;41(1):14. doi: 10.1007/s10916-016-0658-3. Epub 2016 Nov 30.
4
An improved authenticated key agreement protocol for telecare medicine information system.一种用于远程医疗信息系统的改进型认证密钥协商协议。
Springerplus. 2016 May 3;5:555. doi: 10.1186/s40064-016-2018-7. eCollection 2016.
5
An Efficient and Practical Smart Card Based Anonymity Preserving User Authentication Scheme for TMIS using Elliptic Curve Cryptography.基于椭圆曲线密码学的 TMIS 中高效实用的智能卡匿名保护用户认证方案。
J Med Syst. 2015 Nov;39(11):180. doi: 10.1007/s10916-015-0351-y. Epub 2015 Oct 3.
6
New Authentication Scheme for Wireless Body Area Networks Using the Bilinear Pairing.基于双线性对的无线体域网新型认证方案
J Med Syst. 2015 Nov;39(11):136. doi: 10.1007/s10916-015-0331-2. Epub 2015 Sep 1.
7
An Improved RSA Based User Authentication and Session Key Agreement Protocol Usable in TMIS.基于 RSA 的改进型用户认证和会话密钥协商协议,可用于 TMIS。
J Med Syst. 2015 Aug;39(8):79. doi: 10.1007/s10916-015-0262-y. Epub 2015 Jun 28.
8
Cryptanalysis and improvement of a user authentication scheme preserving uniqueness and anonymity for connected health care.用于连接式医疗保健的保持唯一性和匿名性的用户认证方案的密码分析与改进
J Med Syst. 2015 Feb;39(2):10. doi: 10.1007/s10916-014-0179-x. Epub 2015 Jan 29.
9
Three-factor anonymous authentication and key agreement scheme for Telecare Medicine Information Systems.远程医疗信息系统的三因素匿名认证与密钥协商方案
J Med Syst. 2014 Dec;38(12):136. doi: 10.1007/s10916-014-0136-8. Epub 2014 Oct 29.
10
Cryptanalysis and improvement of authentication and key agreement protocols for telecare medicine information systems.远程医疗信息系统认证与密钥协商协议的密码分析及改进
J Med Syst. 2014 Oct;38(10):135. doi: 10.1007/s10916-014-0135-9. Epub 2014 Sep 5.
一种用于远程医疗信息系统的改进型匿名认证方案。
J Med Syst. 2014 May;38(5):26. doi: 10.1007/s10916-014-0026-0. Epub 2014 Apr 30.
4
On the security of two remote user authentication schemes for telecare medical information systems.关于远程医疗信息系统的两种远程用户认证方案的安全性
J Med Syst. 2014 May;38(5):17. doi: 10.1007/s10916-014-0017-1. Epub 2014 Apr 29.
5
Security enhancement of a biometric based authentication scheme for telecare medicine information systems with nonce.基于一次性随机数的远程医疗信息系统生物特征认证方案的安全性增强
J Med Syst. 2014 May;38(5):41. doi: 10.1007/s10916-014-0041-1. Epub 2014 Apr 26.
6
A more secure anonymous user authentication scheme for the integrated EPR information system.一种用于集成电子病历信息系统的更安全的匿名用户认证方案。
J Med Syst. 2014 May;38(5):42. doi: 10.1007/s10916-014-0042-0. Epub 2014 Apr 24.
7
A user anonymity preserving three-factor authentication scheme for telecare medicine information systems.一种用于远程医疗信息系统的保护用户匿名性的三因素认证方案。
J Med Syst. 2014 Mar;38(3):16. doi: 10.1007/s10916-014-0016-2. Epub 2014 Mar 19.
8
A robust uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.一种用于连接式医疗保健的强大的保持唯一性和匿名性的远程用户认证方案。
J Med Syst. 2013 Dec;37(6):9980. doi: 10.1007/s10916-013-9980-1. Epub 2013 Oct 23.
9
A secure biometrics-based authentication scheme for telecare medicine information systems.一种用于远程医疗信息系统的基于生物识别技术的安全认证方案。
J Med Syst. 2013 Oct;37(5):9972. doi: 10.1007/s10916-013-9972-1. Epub 2013 Aug 31.
10
A biometric authentication scheme for telecare medicine information systems with nonce.一种用于远程护理医学信息系统的带现时值的生物特征认证方案。
J Med Syst. 2013 Oct;37(5):9964. doi: 10.1007/s10916-013-9964-1. Epub 2013 Aug 16.