Chaudhry Shehzad Ashraf, Naqvi Husnain, Shon Taeshik, Sher Muhammad, Farash Mohammad Sabzinejad
International Islamic University Islamabad, Islamabad, Pakistan,
J Med Syst. 2015 Jun;39(6):66. doi: 10.1007/s10916-015-0244-0. Epub 2015 Apr 26.
Telecare medical information systems (TMIS) provides rapid and convenient health care services remotely. Efficient authentication is a prerequisite to guarantee the security and privacy of patients in TMIS. Authentication is used to verify the legality of the patients and TMIS server during remote access. Very recently Islam et al. (J. Med. Syst. 38(10):135, 2014) proposed a two factor authentication protocol for TMIS using elliptic curve cryptography (ECC) to improve Xu et al.'s (J. Med. Syst. 38(1):9994, 2014) protocol. They claimed their improved protocol to be efficient and provides all security requirements. However our analysis reveals that Islam et al.'s protocol suffers from user impersonation and server impersonation attacks. Furthermore we proposed an enhanced protocol. The proposed protocol while delivering all the virtues of Islam et al.'s protocol resists all known attacks.
远程医疗信息系统(TMIS)可远程提供快速便捷的医疗服务。高效认证是保障TMIS中患者安全和隐私的前提条件。认证用于在远程访问期间验证患者和TMIS服务器的合法性。最近,伊斯兰等人(《医学系统杂志》38(10):135,2014年)提出了一种用于TMIS的双因素认证协议,该协议使用椭圆曲线密码学(ECC)来改进徐等人(《医学系统杂志》38(1):9994,2014年)的协议。他们声称其改进后的协议高效且满足所有安全要求。然而,我们的分析表明,伊斯兰等人的协议遭受用户假冒和服务器假冒攻击。此外,我们提出了一种增强协议。所提出的协议在具备伊斯兰等人协议所有优点的同时,能抵御所有已知攻击。