Suppr超能文献

远程医疗信息系统中增强的医患相互认证协议的设计与分析。

Design and Analysis of an Enhanced Patient-Server Mutual Authentication Protocol for Telecare Medical Information System.

机构信息

Department of Computer Science and Engineering, Indian School of Mines, Dhanbad-826004, Jharkhand, India,

出版信息

J Med Syst. 2015 Nov;39(11):137. doi: 10.1007/s10916-015-0307-2. Epub 2015 Sep 1.

Abstract

In order to access remote medical server, generally the patients utilize smart card to login to the server. It has been observed that most of the user (patient) authentication protocols suffer from smart card stolen attack that means the attacker can mount several common attacks after extracting smart card information. Recently, Lu et al.'s proposes a session key agreement protocol between the patient and remote medical server and claims that the same protocol is secure against relevant security attacks. However, this paper presents several security attacks on Lu et al.'s protocol such as identity trace attack, new smart card issue attack, patient impersonation attack and medical server impersonation attack. In order to fix the mentioned security pitfalls including smart card stolen attack, this paper proposes an efficient remote mutual authentication protocol using smart card. We have then simulated the proposed protocol using widely-accepted AVISPA simulation tool whose results make certain that the same protocol is secure against active and passive attacks including replay and man-in-the-middle attacks. Moreover, the rigorous security analysis proves that the proposed protocol provides strong security protection on the relevant security attacks including smart card stolen attack. We compare the proposed scheme with several related schemes in terms of computation cost and communication cost as well as security functionalities. It has been observed that the proposed scheme is comparatively better than related existing schemes.

摘要

为了访问远程医疗服务器,一般情况下,患者会使用智能卡登录服务器。据观察,大多数用户(患者)认证协议都存在智能卡被盗攻击的问题,这意味着攻击者在提取智能卡信息后可以进行多种常见攻击。最近,Lu 等人提出了一种患者和远程医疗服务器之间的会话密钥协商协议,并声称该协议可以抵御相关的安全攻击。然而,本文对 Lu 等人的协议提出了几种安全攻击,如身份追踪攻击、新智能卡问题攻击、患者冒充攻击和医疗服务器冒充攻击。为了解决包括智能卡被盗攻击在内的上述安全缺陷,本文提出了一种使用智能卡的高效远程相互认证协议。然后,我们使用广泛接受的 AVISPA 仿真工具对所提出的协议进行了仿真,结果表明该协议可以抵御主动和被动攻击,包括重播和中间人攻击。此外,严格的安全分析证明,所提出的协议对包括智能卡被盗攻击在内的相关安全攻击提供了强大的安全保护。我们在计算成本、通信成本和安全功能方面将所提出的方案与几个相关方案进行了比较。结果表明,所提出的方案明显优于相关的现有方案。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验