• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

基于椭圆曲线密码学的远程医疗信息系统改进和安全生物认证方案。

An Improved and Secure Biometric Authentication Scheme for Telecare Medicine Information Systems Based on Elliptic Curve Cryptography.

机构信息

Department of Computer Science and Software Engineering, International Islamic University, Islamabad, Pakistan.

Center of Excellence in Information Assurance, King Saud University, Riyadh, Saudi Arabia.

出版信息

J Med Syst. 2015 Nov;39(11):175. doi: 10.1007/s10916-015-0335-y. Epub 2015 Sep 23.

DOI:10.1007/s10916-015-0335-y
PMID:26399937
Abstract

Telecare medicine information system (TMIS) offers the patients convenient and expedite healthcare services remotely anywhere. Patient security and privacy has emerged as key issues during remote access because of underlying open architecture. An authentication scheme can verify patient's as well as TMIS server's legitimacy during remote healthcare services. To achieve security and privacy a number of authentication schemes have been proposed. Very recently Lu et al. (J. Med. Syst. 39(3):1-8, 2015) proposed a biometric based three factor authentication scheme for TMIS to confiscate the vulnerabilities of Arshad et al.'s (J. Med. Syst. 38(12):136, 2014) scheme. Further, they emphasized the robustness of their scheme against several attacks. However, in this paper we establish that Lu et al.'s scheme is vulnerable to numerous attacks including (1) Patient anonymity violation attack, (2) Patient impersonation attack, and (3) TMIS server impersonation attack. Furthermore, their scheme does not provide patient untraceability. We then, propose an improvement of Lu et al.'s scheme. We have analyzed the security of improved scheme using popular automated tool ProVerif. The proposed scheme while retaining the plusses of Lu et al.'s scheme is also robust against known attacks.

摘要

远程医疗信息系统(TMIS)为患者提供了在任何地方远程便捷的医疗服务。由于底层的开放式架构,远程访问中患者的安全和隐私成为关键问题。认证方案可以在远程医疗服务期间验证患者和 TMIS 服务器的合法性。为了实现安全性和隐私性,已经提出了许多认证方案。最近,Lu 等人(J. Med. Syst. 39(3):1-8, 2015)提出了一种基于生物特征的三因素认证方案,用于 TMIS 以消除 Arshad 等人(J. Med. Syst. 38(12):136, 2014)方案的漏洞。此外,他们强调了他们的方案对各种攻击的稳健性。然而,在本文中,我们证明了 Lu 等人的方案容易受到多种攻击,包括(1)患者匿名性侵犯攻击,(2)患者模拟攻击,和(3)TMIS 服务器模拟攻击。此外,他们的方案无法提供患者的不可追踪性。然后,我们提出了 Lu 等人方案的改进。我们使用流行的自动化工具 ProVerif 分析了改进方案的安全性。所提出的方案在保留 Lu 等人方案的优点的同时,也对已知攻击具有稳健性。

相似文献

1
An Improved and Secure Biometric Authentication Scheme for Telecare Medicine Information Systems Based on Elliptic Curve Cryptography.基于椭圆曲线密码学的远程医疗信息系统改进和安全生物认证方案。
J Med Syst. 2015 Nov;39(11):175. doi: 10.1007/s10916-015-0335-y. Epub 2015 Sep 23.
2
A Multiserver Biometric Authentication Scheme for TMIS using Elliptic Curve Cryptography.一种使用椭圆曲线密码学的用于TMIS的多服务器生物特征认证方案。
J Med Syst. 2016 Nov;40(11):230. doi: 10.1007/s10916-016-0592-4. Epub 2016 Sep 19.
3
An enhanced biometric-based authentication scheme for telecare medicine information systems using elliptic curve cryptosystem.一种使用椭圆曲线密码系统的远程医疗信息系统增强型基于生物特征的认证方案。
J Med Syst. 2015 Mar;39(3):32. doi: 10.1007/s10916-015-0221-7. Epub 2015 Feb 14.
4
A secure user anonymity-preserving three-factor remote user authentication scheme for the telecare medicine information systems.一种用于远程医疗信息系统的安全的、保护用户匿名性的三因素远程用户认证方案。
J Med Syst. 2015 Mar;39(3):30. doi: 10.1007/s10916-015-0218-2. Epub 2015 Feb 13.
5
A secure biometrics-based authentication key exchange protocol for multi-server TMIS using ECC.基于椭圆曲线密码的 TMIS 多服务器安全生物认证密钥交换协议
Comput Methods Programs Biomed. 2018 Oct;164:101-109. doi: 10.1016/j.cmpb.2018.07.008. Epub 2018 Jul 18.
6
Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems.用于远程医疗信息系统的基于密码的安全匿名用户认证和会话密钥协商方案。
Comput Methods Programs Biomed. 2016 Oct;135:167-85. doi: 10.1016/j.cmpb.2016.07.028. Epub 2016 Jul 29.
7
Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems.针对电子医疗保健系统的匿名保护远程用户相互认证和会话密钥协商方案的密码分析与增强。
J Med Syst. 2015 Nov;39(11):140. doi: 10.1007/s10916-015-0318-z. Epub 2015 Sep 5.
8
Cryptanalysis and improvement of an improved two factor authentication protocol for telecare medical information systems.远程医疗信息系统中一种改进的双因素认证协议的密码分析与改进
J Med Syst. 2015 Jun;39(6):66. doi: 10.1007/s10916-015-0244-0. Epub 2015 Apr 26.
9
Understanding security failures of two authentication and key agreement schemes for telecare medicine information systems.理解远程医疗信息系统中两种认证与密钥协商方案的安全漏洞。
J Med Syst. 2015 Mar;39(3):19. doi: 10.1007/s10916-015-0193-7. Epub 2015 Feb 5.
10
A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity.一种具有用户匿名性的 TMIS 的安全三方用户认证和密钥协商协议。
J Med Syst. 2015 Aug;39(8):78. doi: 10.1007/s10916-015-0258-7. Epub 2015 Jun 26.

引用本文的文献

1
A biometrics-based mutual authentication and key agreement protocol for TMIS using elliptic curve cryptography.一种基于生物特征识别的、使用椭圆曲线密码学的TMIS相互认证和密钥协商协议。
Multimed Tools Appl. 2023;82(11):16009-16032. doi: 10.1007/s11042-022-14007-3. Epub 2022 Oct 12.
2
Metaheuristic secured transmission in Telecare Medical Information System (TMIS) in the face of post-COVID-19.面对新冠疫情后的远程医疗信息系统(TMIS)中的元启发式安全传输
J Ambient Intell Humaniz Comput. 2023;14(6):6623-6644. doi: 10.1007/s12652-021-03531-z. Epub 2021 Oct 23.
3
Heartbeats Do Not Make Good Pseudo-Random Number Generators: An Analysis of the Randomness of Inter-Pulse Intervals.

本文引用的文献

1
An Improved RSA Based User Authentication and Session Key Agreement Protocol Usable in TMIS.基于 RSA 的改进型用户认证和会话密钥协商协议,可用于 TMIS。
J Med Syst. 2015 Aug;39(8):79. doi: 10.1007/s10916-015-0262-y. Epub 2015 Jun 28.
2
A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity.一种具有用户匿名性的 TMIS 的安全三方用户认证和密钥协商协议。
J Med Syst. 2015 Aug;39(8):78. doi: 10.1007/s10916-015-0258-7. Epub 2015 Jun 26.
3
Cryptanalysis and improvement of an improved two factor authentication protocol for telecare medical information systems.
心跳并非良好的伪随机数生成器:对脉搏间期随机性的分析。
Entropy (Basel). 2018 Jan 30;20(2):94. doi: 10.3390/e20020094.
4
A Robust and Efficient ECC-based Mutual Authentication and Session Key Generation Scheme for Healthcare Applications.基于 ECC 的强健高效的医疗应用互认证和会话密钥生成方案。
J Med Syst. 2018 Dec 1;43(1):10. doi: 10.1007/s10916-018-1120-5.
5
A Study on Secure Medical-Contents Strategies with DRM Based on Cloud Computing.基于云计算的安全医疗内容策略研究。
J Healthc Eng. 2018 Mar 29;2018:6410180. doi: 10.1155/2018/6410180. eCollection 2018.
6
A Double Chaotic Layer Encryption Algorithm for Clinical Signals in Telemedicine.一种用于远程医疗中临床信号的双混沌层加密算法。
J Med Syst. 2017 Apr;41(4):59. doi: 10.1007/s10916-017-0698-3. Epub 2017 Feb 28.
7
An Improved and Secure Anonymous Biometric-Based User Authentication with Key Agreement Scheme for the Integrated EPR Information System.一种用于集成电子病历信息系统的、具有密钥协商方案的改进型安全匿名生物特征用户认证方法。
PLoS One. 2017 Jan 3;12(1):e0169414. doi: 10.1371/journal.pone.0169414. eCollection 2017.
8
A Survey of Authentication Schemes in Telecare Medicine Information Systems.远程医疗信息系统中的认证方案调查
J Med Syst. 2017 Jan;41(1):14. doi: 10.1007/s10916-016-0658-3. Epub 2016 Nov 30.
9
Biometrics based authentication scheme for session initiation protocol.用于会话发起协议的基于生物识别技术的认证方案。
Springerplus. 2016 Jul 11;5(1):1045. doi: 10.1186/s40064-016-2725-0. eCollection 2016.
10
Chaotic Visual Cryptosystem Using Empirical Mode Decomposition Algorithm for Clinical EEG Signals.基于经验模态分解算法的用于临床脑电图信号的混沌视觉密码系统。
J Med Syst. 2016 Mar;40(3):52. doi: 10.1007/s10916-015-0414-0. Epub 2015 Dec 8.
远程医疗信息系统中一种改进的双因素认证协议的密码分析与改进
J Med Syst. 2015 Jun;39(6):66. doi: 10.1007/s10916-015-0244-0. Epub 2015 Apr 26.
4
An enhanced biometric-based authentication scheme for telecare medicine information systems using elliptic curve cryptosystem.一种使用椭圆曲线密码系统的远程医疗信息系统增强型基于生物特征的认证方案。
J Med Syst. 2015 Mar;39(3):32. doi: 10.1007/s10916-015-0221-7. Epub 2015 Feb 14.
5
A novel user authentication and key agreement protocol for accessing multi-medical server usable in TMIS.一种适用于TMIS的可访问多医疗服务器的新型用户认证与密钥协商协议。
J Med Syst. 2015 Mar;39(3):33. doi: 10.1007/s10916-015-0217-3. Epub 2015 Feb 15.
6
An efficient and robust RSA-based remote user authentication for telecare medical information systems.一种用于远程医疗信息系统的高效且稳健的基于RSA的远程用户认证方法。
J Med Syst. 2015 Jan;39(1):145. doi: 10.1007/s10916-014-0145-7. Epub 2014 Nov 18.
7
Three-factor anonymous authentication and key agreement scheme for Telecare Medicine Information Systems.远程医疗信息系统的三因素匿名认证与密钥协商方案
J Med Syst. 2014 Dec;38(12):136. doi: 10.1007/s10916-014-0136-8. Epub 2014 Oct 29.
8
Secure privacy-preserving biometric authentication scheme for telecare medicine information systems.用于远程医疗信息系统的安全隐私保护生物特征认证方案。
J Med Syst. 2014 Nov;38(11):139. doi: 10.1007/s10916-014-0139-5. Epub 2014 Oct 9.
9
Cryptanalysis and improvement of authentication and key agreement protocols for telecare medicine information systems.远程医疗信息系统认证与密钥协商协议的密码分析及改进
J Med Syst. 2014 Oct;38(10):135. doi: 10.1007/s10916-014-0135-9. Epub 2014 Sep 5.
10
Anonymous three-party password-authenticated key exchange scheme for Telecare Medical Information Systems.用于远程医疗信息系统的匿名三方密码认证密钥交换方案。
PLoS One. 2014 Jul 21;9(7):e102747. doi: 10.1371/journal.pone.0102747. eCollection 2014.