Suppr超能文献

用于互联医疗保健的一种保持唯一性和匿名性的用户认证方案的改进。

Improvement of a uniqueness-and-anonymity-preserving user authentication scheme for connected health care.

作者信息

Xie Qi, Liu Wenhao, Wang Shengbao, Han Lidong, Hu Bin, Wu Ting

机构信息

Hangzhou Key Laboratory of Cryptography and Network Security, Hangzhou Normal University, Hangzhou, 311121, China,

出版信息

J Med Syst. 2014 Sep;38(9):91. doi: 10.1007/s10916-014-0091-4. Epub 2014 Jul 4.

Abstract

Patient's privacy-preserving, security and mutual authentication between patient and the medical server are the important mechanism in connected health care applications, such as telecare medical information systems and personally controlled health records systems. In 2013, Wen showed that Das et al.'s scheme is vulnerable to the replay attack, user impersonation attacks and off-line guessing attacks, and then proposed an improved scheme using biometrics, password and smart card to overcome these weaknesses. However, we show that Wen's scheme is still vulnerable to off-line password guessing attacks, does not provide user's anonymity and perfect forward secrecy. Further, we propose an improved scheme to fix these weaknesses, and use the applied pi calculus based formal verification tool ProVerif to prove the security and authentication.

摘要

患者隐私保护、患者与医疗服务器之间的安全性和相互认证是远程医疗保健应用(如远程护理医疗信息系统和个人控制的健康记录系统)中的重要机制。2013年,Wen指出Das等人的方案容易受到重放攻击、用户假冒攻击和离线猜测攻击,随后提出了一种使用生物特征识别、密码和智能卡的改进方案来克服这些弱点。然而,我们表明Wen的方案仍然容易受到离线密码猜测攻击,不提供用户匿名性和完美前向保密性。此外,我们提出了一种改进方案来修复这些弱点,并使用基于应用pi演算的形式化验证工具ProVerif来证明安全性和认证性。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验