• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

一种用于远程医疗信息系统的改进型认证密钥协商协议。

An improved authenticated key agreement protocol for telecare medicine information system.

作者信息

Liu Wenhao, Xie Qi, Wang Shengbao, Hu Bin

机构信息

Hangzhou Key Laboratory of Cryptography and Network Security, Hangzhou Normal University, Hangzhou, 311121 China.

出版信息

Springerplus. 2016 May 3;5:555. doi: 10.1186/s40064-016-2018-7. eCollection 2016.

DOI:10.1186/s40064-016-2018-7
PMID:27218005
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC4854862/
Abstract

In telecare medicine information systems (TMIS), identity authentication of patients plays an important role and has been widely studied in the research field. Generally, it is realized by an authenticated key agreement protocol, and many such protocols were proposed in the literature. Recently, Zhang et al. pointed out that Islam et al.'s protocol suffers from the following security weaknesses: (1) Any legal but malicious patient can reveal other user's identity; (2) An attacker can launch off-line password guessing attack and the impersonation attack if the patient's identity is compromised. Zhang et al. also proposed an improved authenticated key agreement scheme with privacy protection for TMIS. However, in this paper, we point out that Zhang et al.'s scheme cannot resist off-line password guessing attack, and it fails to provide the revocation of lost/stolen smartcard. In order to overcome these weaknesses, we propose an improved protocol, the security and authentication of which can be proven using applied pi calculus based formal verification tool ProVerif.

摘要

在远程医疗信息系统(TMIS)中,患者身份认证起着重要作用,并且在研究领域已经得到广泛研究。一般来说,它是通过认证密钥协商协议来实现的,文献中提出了许多这样的协议。最近,Zhang等人指出Islam等人的协议存在以下安全弱点:(1)任何合法但恶意的患者都可以泄露其他用户的身份;(2)如果患者的身份被泄露,攻击者可以发起离线密码猜测攻击和身份冒充攻击。Zhang等人还提出了一种改进的具有隐私保护的TMIS认证密钥协商方案。然而,在本文中,我们指出Zhang等人的方案无法抵抗离线密码猜测攻击,并且它未能提供对丢失/被盗智能卡的撤销功能。为了克服这些弱点,我们提出了一种改进的协议,其安全性和认证性可以使用基于应用pi演算的形式化验证工具ProVerif来证明。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ed1f/4854862/10870883ebcf/40064_2016_2018_Fig1_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ed1f/4854862/10870883ebcf/40064_2016_2018_Fig1_HTML.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/ed1f/4854862/10870883ebcf/40064_2016_2018_Fig1_HTML.jpg

相似文献

1
An improved authenticated key agreement protocol for telecare medicine information system.一种用于远程医疗信息系统的改进型认证密钥协商协议。
Springerplus. 2016 May 3;5:555. doi: 10.1186/s40064-016-2018-7. eCollection 2016.
2
Robust ECC-based authenticated key agreement scheme with privacy protection for Telecare medicine information systems.基于鲁棒 ECC 的带隐私保护的认证密钥协商方案在远程医疗信息系统中的应用。
J Med Syst. 2015 May;39(5):49. doi: 10.1007/s10916-015-0233-3. Epub 2015 Mar 3.
3
Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems.用于远程医疗信息系统的基于密码的安全匿名用户认证和会话密钥协商方案。
Comput Methods Programs Biomed. 2016 Oct;135:167-85. doi: 10.1016/j.cmpb.2016.07.028. Epub 2016 Jul 29.
4
Security and efficiency enhancement of an anonymous three-party password-authenticated key agreement using extended chaotic maps.使用扩展混沌映射增强匿名三方密码认证密钥协商的安全性和效率。
PLoS One. 2018 Oct 5;13(10):e0203984. doi: 10.1371/journal.pone.0203984. eCollection 2018.
5
Security analysis and improvement of a privacy authentication scheme for telecare medical information systems.远程医疗信息系统隐私认证方案的安全性分析与改进。
J Med Syst. 2013 Aug;37(4):9958. doi: 10.1007/s10916-013-9958-z. Epub 2013 Jul 2.
6
A biometrics-based mutual authentication and key agreement protocol for TMIS using elliptic curve cryptography.一种基于生物特征识别的、使用椭圆曲线密码学的TMIS相互认证和密钥协商协议。
Multimed Tools Appl. 2023;82(11):16009-16032. doi: 10.1007/s11042-022-14007-3. Epub 2022 Oct 12.
7
Improved dynamic ID-based authentication scheme for telecare medical information systems.用于远程医疗信息系统的改进型基于动态身份的认证方案。
J Med Syst. 2013 Apr;37(2):9912. doi: 10.1007/s10916-012-9912-5. Epub 2013 Jan 24.
8
An efficient authentication scheme for telecare medicine information systems.远程医疗保健信息系统的高效认证方案。
J Med Syst. 2012 Dec;36(6):3833-8. doi: 10.1007/s10916-012-9856-9. Epub 2012 Apr 25.
9
Robust anonymous authentication scheme for telecare medical information systems.远程医疗信息系统的健壮匿名认证方案
J Med Syst. 2013 Apr;37(2):9911. doi: 10.1007/s10916-012-9911-6. Epub 2013 Jan 16.
10
Improvement of a uniqueness-and-anonymity-preserving user authentication scheme for connected health care.用于互联医疗保健的一种保持唯一性和匿名性的用户认证方案的改进。
J Med Syst. 2014 Sep;38(9):91. doi: 10.1007/s10916-014-0091-4. Epub 2014 Jul 4.

引用本文的文献

1
Design of a Secure Authentication and Key Agreement Scheme Preserving User Privacy Usable in Telecare Medicine Information Systems.一种可用于远程医疗信息系统的、保护用户隐私的安全认证与密钥协商方案的设计。
J Med Syst. 2016 Nov;40(11):237. doi: 10.1007/s10916-016-0585-3. Epub 2016 Sep 24.

本文引用的文献

1
Cryptanalysis and improvement of an improved two factor authentication protocol for telecare medical information systems.远程医疗信息系统中一种改进的双因素认证协议的密码分析与改进
J Med Syst. 2015 Jun;39(6):66. doi: 10.1007/s10916-015-0244-0. Epub 2015 Apr 26.
2
Robust ECC-based authenticated key agreement scheme with privacy protection for Telecare medicine information systems.基于鲁棒 ECC 的带隐私保护的认证密钥协商方案在远程医疗信息系统中的应用。
J Med Syst. 2015 May;39(5):49. doi: 10.1007/s10916-015-0233-3. Epub 2015 Mar 3.
3
Cryptanalysis and improvement of authentication and key agreement protocols for telecare medicine information systems.
远程医疗信息系统认证与密钥协商协议的密码分析及改进
J Med Syst. 2014 Oct;38(10):135. doi: 10.1007/s10916-014-0135-9. Epub 2014 Sep 5.
4
Improvement of a uniqueness-and-anonymity-preserving user authentication scheme for connected health care.用于互联医疗保健的一种保持唯一性和匿名性的用户认证方案的改进。
J Med Syst. 2014 Sep;38(9):91. doi: 10.1007/s10916-014-0091-4. Epub 2014 Jul 4.
5
Security enhancement of a biometric based authentication scheme for telecare medicine information systems with nonce.基于一次性随机数的远程医疗信息系统生物特征认证方案的安全性增强
J Med Syst. 2014 May;38(5):41. doi: 10.1007/s10916-014-0041-1. Epub 2014 Apr 26.
6
Smart environment as a service: three factor cloud based user authentication for telecare medical information system.智能环境即服务:用于远程医疗信息系统的基于云的三因素用户认证
J Med Syst. 2014 Jan;38(1):9997. doi: 10.1007/s10916-013-9997-5. Epub 2013 Dec 7.
7
A secure and efficient authentication and key agreement scheme based on ECC for telecare medicine information systems.一种基于椭圆曲线密码体制(ECC)的用于远程医疗信息系统的安全高效认证与密钥协商方案。
J Med Syst. 2014 Jan;38(1):9994. doi: 10.1007/s10916-013-9994-8. Epub 2013 Nov 21.
8
A robust uniqueness-and-anonymity-preserving remote user authentication scheme for connected health care.一种用于连接式医疗保健的强大的保持唯一性和匿名性的远程用户认证方案。
J Med Syst. 2013 Dec;37(6):9980. doi: 10.1007/s10916-013-9980-1. Epub 2013 Oct 23.
9
RFID authentication protocol to enhance patient medication safety.用于提高患者用药安全性的射频识别认证协议。
J Med Syst. 2013 Dec;37(6):9979. doi: 10.1007/s10916-013-9979-7. Epub 2013 Oct 13.
10
A biometric authentication scheme for telecare medicine information systems with nonce.一种用于远程护理医学信息系统的带现时值的生物特征认证方案。
J Med Syst. 2013 Oct;37(5):9964. doi: 10.1007/s10916-013-9964-1. Epub 2013 Aug 16.