• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

用于远程医疗信息系统的基于密码的安全匿名用户认证和会话密钥协商方案。

Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems.

作者信息

Sutrala Anil Kumar, Das Ashok Kumar, Odelu Vanga, Wazid Mohammad, Kumari Saru

机构信息

Center for Security, Theory and Algorithmic Research, International Institute of Information Technology, Hyderabad 500 032, India.

Center for Security, Theory and Algorithmic Research, International Institute of Information Technology, Hyderabad 500 032, India.

出版信息

Comput Methods Programs Biomed. 2016 Oct;135:167-85. doi: 10.1016/j.cmpb.2016.07.028. Epub 2016 Jul 29.

DOI:10.1016/j.cmpb.2016.07.028
PMID:27586489
Abstract

BACKGROUND AND OBJECTIVES

Information and communication and technology (ICT) has changed the entire paradigm of society. ICT facilitates people to use medical services over the Internet, thereby reducing the travel cost, hospitalization cost and time to a greater extent. Recent advancements in Telecare Medicine Information System (TMIS) facilitate users/patients to access medical services over the Internet by gaining health monitoring facilities at home.

METHODS

Amin and Biswas recently proposed a RSA-based user authentication and session key agreement protocol usable for TMIS, which is an improvement over Giri et al.'s RSA-based user authentication scheme for TMIS. In this paper, we show that though Amin-Biswas's scheme considerably improves the security drawbacks of Giri et al.'s scheme, their scheme has security weaknesses as it suffers from attacks such as privileged insider attack, user impersonation attack, replay attack and also offline password guessing attack. A new RSA-based user authentication scheme for TMIS is proposed, which overcomes the security pitfalls of Amin-Biswas's scheme and also preserves user anonymity property.

RESULTS

The careful formal security analysis using the two widely accepted Burrows-Abadi-Needham (BAN) logic and the random oracle models is done. Moreover, the informal security analysis of the scheme is also done. These security analyses show the robustness of our new scheme against the various known attacks as well as attacks found in Amin-Biswas's scheme. The simulation of the proposed scheme using the widely accepted Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is also done.

CONCLUSIONS

We present a new user authentication and session key agreement scheme for TMIS, which fixes the mentioned security pitfalls found in Amin-Biswas's scheme, and we also show that the proposed scheme provides better security than other existing schemes through the rigorous security analysis and verification tool. Furthermore, we present the formal security verification of our scheme using the widely accepted AVISPA tool. High security and extra functionality features allow our proposed scheme to be applicable for telecare medicine information systems which is used for e-health care medical applications.

摘要

背景与目标

信息通信技术(ICT)改变了整个社会范式。ICT 便于人们通过互联网使用医疗服务,从而在很大程度上降低了出行成本、住院成本和时间成本。远程医疗信息系统(TMIS)的最新进展使得用户/患者能够通过在家中获得健康监测设施,在互联网上获取医疗服务。

方法

阿明和比斯瓦斯最近提出了一种基于 RSA 的用户认证和会话密钥协商协议,可用于 TMIS,这是对吉里等人基于 RSA 的 TMIS 用户认证方案的改进。在本文中,我们表明,尽管阿明 - 比斯瓦斯的方案在很大程度上改善了吉里等人方案的安全缺陷,但他们的方案存在安全弱点,因为它遭受诸如特权内部人员攻击、用户假冒攻击、重放攻击以及离线密码猜测攻击等。本文提出了一种新的基于 RSA 的 TMIS 用户认证方案,该方案克服了阿明 - 比斯瓦斯方案的安全隐患,并且保留了用户匿名属性。

结果

使用两种广泛接受的伯罗斯 - 阿巴迪 - 尼达姆(BAN)逻辑和随机预言模型进行了仔细的形式化安全分析。此外,还对该方案进行了非形式化安全分析。这些安全分析表明我们的新方案针对各种已知攻击以及在阿明 - 比斯瓦斯方案中发现的攻击具有鲁棒性。还使用广泛接受的互联网安全协议与应用自动验证(AVISPA)工具对所提出的方案进行了模拟。

结论

我们提出了一种用于 TMIS 的新的用户认证和会话密钥协商方案,该方案修复了在阿明 - 比斯瓦斯方案中发现的上述安全隐患,并且通过严格的安全分析和验证工具表明所提出的方案比其他现有方案提供了更好的安全性。此外,我们使用广泛接受的 AVISPA 工具对我们的方案进行了形式化安全验证。高安全性和额外的功能特性使得我们提出的方案适用于用于电子医疗保健医疗应用的远程医疗信息系统。

相似文献

1
Secure anonymity-preserving password-based user authentication and session key agreement scheme for telecare medicine information systems.用于远程医疗信息系统的基于密码的安全匿名用户认证和会话密钥协商方案。
Comput Methods Programs Biomed. 2016 Oct;135:167-85. doi: 10.1016/j.cmpb.2016.07.028. Epub 2016 Jul 29.
2
A Secure and Robust User Authenticated Key Agreement Scheme for Hierarchical Multi-medical Server Environment in TMIS.TMIS 中分层多医疗服务器环境的安全稳健的用户认证密钥协商方案。
J Med Syst. 2015 Sep;39(9):92. doi: 10.1007/s10916-015-0276-5. Epub 2015 Aug 6.
3
Design of a Secure Authentication and Key Agreement Scheme Preserving User Privacy Usable in Telecare Medicine Information Systems.一种可用于远程医疗信息系统的、保护用户隐私的安全认证与密钥协商方案的设计。
J Med Syst. 2016 Nov;40(11):237. doi: 10.1007/s10916-016-0585-3. Epub 2016 Sep 24.
4
A secure user anonymity-preserving three-factor remote user authentication scheme for the telecare medicine information systems.一种用于远程医疗信息系统的安全的、保护用户匿名性的三因素远程用户认证方案。
J Med Syst. 2015 Mar;39(3):30. doi: 10.1007/s10916-015-0218-2. Epub 2015 Feb 13.
5
An Improved RSA Based User Authentication and Session Key Agreement Protocol Usable in TMIS.基于 RSA 的改进型用户认证和会话密钥协商协议,可用于 TMIS。
J Med Syst. 2015 Aug;39(8):79. doi: 10.1007/s10916-015-0262-y. Epub 2015 Jun 28.
6
A Robust and Efficient ECC-based Mutual Authentication and Session Key Generation Scheme for Healthcare Applications.基于 ECC 的强健高效的医疗应用互认证和会话密钥生成方案。
J Med Syst. 2018 Dec 1;43(1):10. doi: 10.1007/s10916-018-1120-5.
7
A Secure User Anonymity and Authentication Scheme Using AVISPA for Telecare Medical Information Systems.使用 AVISPA 实现远程医疗信息系统中的安全用户匿名和认证方案。
J Med Syst. 2015 Sep;39(9):89. doi: 10.1007/s10916-015-0265-8. Epub 2015 Aug 5.
8
A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity.一种具有用户匿名性的 TMIS 的安全三方用户认证和密钥协商协议。
J Med Syst. 2015 Aug;39(8):78. doi: 10.1007/s10916-015-0258-7. Epub 2015 Jun 26.
9
A privacy preserving secure and efficient authentication scheme for telecare medical information systems.一种用于远程医疗信息系统的隐私保护安全高效认证方案。
J Med Syst. 2015 May;39(5):54. doi: 10.1007/s10916-015-0215-5. Epub 2015 Mar 8.
10
Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems.针对电子医疗保健系统的匿名保护远程用户相互认证和会话密钥协商方案的密码分析与增强。
J Med Syst. 2015 Nov;39(11):140. doi: 10.1007/s10916-015-0318-z. Epub 2015 Sep 5.

引用本文的文献

1
Blockchain Enabled Anonymous Privacy-Preserving Authentication Scheme for Internet of Health Things.用于健康物联网的基于区块链的匿名隐私保护认证方案
Sensors (Basel). 2022 Dec 26;23(1):240. doi: 10.3390/s23010240.
2
A Robust and Efficient ECC-based Mutual Authentication and Session Key Generation Scheme for Healthcare Applications.基于 ECC 的强健高效的医疗应用互认证和会话密钥生成方案。
J Med Syst. 2018 Dec 1;43(1):10. doi: 10.1007/s10916-018-1120-5.
3
An Efficient Mutual Authentication Framework for Healthcare System in Cloud Computing.
云计算中医疗保健系统的高效相互认证框架。
J Med Syst. 2018 Jun 28;42(8):142. doi: 10.1007/s10916-018-0987-5.
4
An enhanced password authentication scheme for session initiation protocol with perfect forward secrecy.具有完美前向保密性的会话初始协议的增强密码身份验证方案。
PLoS One. 2018 Mar 16;13(3):e0194072. doi: 10.1371/journal.pone.0194072. eCollection 2018.
5
Security analysis and enhanced user authentication in proxy mobile IPv6 networks.代理移动IPv6网络中的安全分析与增强用户认证
PLoS One. 2017 Jul 18;12(7):e0181031. doi: 10.1371/journal.pone.0181031. eCollection 2017.
6
A Standard Mutual Authentication Protocol for Cloud Computing Based Health Care System.一种用于基于云计算的医疗保健系统的标准相互认证协议。
J Med Syst. 2017 Apr;41(4):50. doi: 10.1007/s10916-017-0699-2. Epub 2017 Feb 17.
7
Analysis of Security Protocols for Mobile Healthcare.移动医疗安全协议分析
J Med Syst. 2016 Nov;40(11):229. doi: 10.1007/s10916-016-0596-0. Epub 2016 Sep 17.