Das Ashok Kumar
Center for Security, Theory and Algorithmic Research International Institute of Information Technology, Hyderabad, 500 032, India,
J Med Syst. 2015 Mar;39(3):30. doi: 10.1007/s10916-015-0218-2. Epub 2015 Feb 13.
Recent advanced technology enables the telecare medicine information system (TMIS) for the patients to gain the health monitoring facility at home and also to access medical services over the Internet of mobile networks. Several remote user authentication schemes have been proposed in the literature for TMIS. However, most of them are either insecure against various known attacks or they are inefficient. Recently, Tan proposed an efficient user anonymity preserving three-factor authentication scheme for TMIS. In this paper, we show that though Tan's scheme is efficient, it has several security drawbacks such as (1) it fails to provide proper authentication during the login phase, (2) it fails to provide correct updation of password and biometric of a user during the password and biometric update phase, and (3) it fails to protect against replay attack. In addition, Tan's scheme lacks the formal security analysis and verification. Later, Arshad and Nikooghadam also pointed out some security flaws in Tan's scheme and then presented an improvement on Tan's s scheme. However, we show that Arshad and Nikooghadam's scheme is still insecure against the privileged-insider attack through the stolen smart-card attack, and it also lacks the formal security analysis and verification. In order to withstand those security loopholes found in both Tan's scheme, and Arshad and Nikooghadam's scheme, we aim to propose an effective and more secure three-factor remote user authentication scheme for TMIS. Our scheme provides the user anonymity property. Through the rigorous informal and formal security analysis using random oracle models and the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool, we show that our scheme is secure against various known attacks, including the replay and man-in-the-middle attacks. Furthermore, our scheme is also efficient as compared to other related schemes.
最近的先进技术使远程护理医学信息系统(TMIS)能够让患者在家中获得健康监测设施,并通过移动网络的互联网访问医疗服务。文献中已经为TMIS提出了几种远程用户认证方案。然而,它们中的大多数要么对各种已知攻击不安全,要么效率低下。最近,谭提出了一种用于TMIS的高效的保持用户匿名性的三因素认证方案。在本文中,我们表明,尽管谭的方案效率高,但它存在几个安全缺陷,例如:(1)它在登录阶段未能提供适当的认证;(2)它在密码和生物特征更新阶段未能正确更新用户的密码和生物特征;(3)它无法防范重放攻击。此外,谭的方案缺乏形式化的安全分析和验证。后来,阿尔沙德和尼库加德姆也指出了谭的方案中的一些安全缺陷,然后对谭的方案提出了改进。然而,我们表明,通过被盗智能卡攻击,阿尔沙德和尼库加德姆的方案仍然无法抵御特权内部人员攻击,并且它也缺乏形式化的安全分析和验证。为了克服在谭的方案以及阿尔沙德和尼库加德姆的方案中发现的那些安全漏洞,我们旨在为TMIS提出一种有效且更安全的三因素远程用户认证方案。我们提出的方案具有用户匿名性。通过使用随机预言模型和广泛接受的AVISPA(互联网安全协议和应用的自动验证)工具进行严格的非形式化和形式化安全分析,我们表明我们的方案能够抵御各种已知攻击,包括重放攻击和中间人攻击。此外,与其他相关方案相比,我们的方案也具有高效性。