Li Chun-Ta, Lee Cheng-Chi, Weng Chi-Yao, Chen Song-Jhih
Department of Information Management, Tainan University of Technology, Tainan, 71002, Taiwan, Republic of China.
Department of Library and Information Science, Fu Jen Catholic University, New Taipei, 24205, Taiwan, Republic of China.
J Med Syst. 2016 Nov;40(11):233. doi: 10.1007/s10916-016-0586-2. Epub 2016 Sep 21.
Secure user authentication schemes in many e-Healthcare applications try to prevent unauthorized users from intruding the e-Healthcare systems and a remote user and a medical server can establish session keys for securing the subsequent communications. However, many schemes does not mask the users' identity information while constructing a login session between two or more parties, even though personal privacy of users is a significant topic for e-Healthcare systems. In order to preserve personal privacy of users, dynamic identity based authentication schemes are hiding user's real identity during the process of network communications and only the medical server knows login user's identity. In addition, most of the existing dynamic identity based authentication schemes ignore the inputs verification during login condition and this flaw may subject to inefficiency in the case of incorrect inputs in the login phase. Regarding the use of secure authentication mechanisms for e-Healthcare systems, this paper presents a new dynamic identity and chaotic maps based authentication scheme and a secure data protection approach is employed in every session to prevent illegal intrusions. The proposed scheme can not only quickly detect incorrect inputs during the phases of login and password change but also can invalidate the future use of a lost/stolen smart card. Compared the functionality and efficiency with other authentication schemes recently, the proposed scheme satisfies desirable security attributes and maintains acceptable efficiency in terms of the computational overheads for e-Healthcare systems.
许多电子医疗保健应用中的安全用户认证方案试图防止未经授权的用户侵入电子医疗保健系统,并且远程用户和医疗服务器可以建立会话密钥以确保后续通信的安全。然而,许多方案在两个或多个参与方之间构建登录会话时并未掩盖用户的身份信息,尽管用户的个人隐私对于电子医疗保健系统而言是一个重要主题。为了保护用户的个人隐私,基于动态身份的认证方案在网络通信过程中隐藏用户的真实身份,只有医疗服务器知道登录用户的身份。此外,大多数现有的基于动态身份的认证方案在登录条件期间忽略输入验证,并且在登录阶段输入错误的情况下,此缺陷可能导致效率低下。关于电子医疗保健系统的安全认证机制的使用,本文提出了一种新的基于动态身份和混沌映射的认证方案,并且在每个会话中采用安全数据保护方法来防止非法入侵。所提出的方案不仅可以在登录和密码更改阶段快速检测到错误输入,而且还可以使丢失/被盗智能卡的未来使用无效。与最近的其他认证方案相比,所提出的方案满足所需的安全属性,并且在电子医疗保健系统的计算开销方面保持可接受的效率。