Jung Jaewook, Kang Dongwoo, Lee Donghoon, Won Dongho
Department of Computer Engineering, Sungkyunkwan University, 2066 Seoburo, Suwon, Gyeonggido 16419, Korea.
PLoS One. 2017 Jan 3;12(1):e0169414. doi: 10.1371/journal.pone.0169414. eCollection 2017.
Nowadays, many hospitals and medical institutes employ an authentication protocol within electronic patient records (EPR) services in order to provide protected electronic transactions in e-medicine systems. In order to establish efficient and robust health care services, numerous studies have been carried out on authentication protocols. Recently, Li et al. proposed a user authenticated key agreement scheme according to EPR information systems, arguing that their scheme is able to resist various types of attacks and preserve diverse security properties. However, this scheme possesses critical vulnerabilities. First, the scheme cannot prevent off-line password guessing attacks and server spoofing attack, and cannot preserve user identity. Second, there is no password verification process with the failure to identify the correct password at the beginning of the login phase. Third, the mechanism of password change is incompetent, in that it induces inefficient communication in communicating with the server to change a user password. Therefore, we suggest an upgraded version of the user authenticated key agreement scheme that provides enhanced security. Our security and performance analysis shows that compared to other related schemes, our scheme not only improves the security level, but also ensures efficiency.
如今,许多医院和医疗机构在电子病历(EPR)服务中采用认证协议,以便在电子医疗系统中提供受保护的电子交易。为了建立高效且稳健的医疗服务,已针对认证协议开展了大量研究。最近,李等人根据EPR信息系统提出了一种用户认证密钥协商方案,称他们的方案能够抵御各种类型的攻击并保留多种安全属性。然而,该方案存在严重漏洞。首先,该方案无法防止离线密码猜测攻击和服务器欺骗攻击,并且无法保护用户身份。其次,在登录阶段开始时没有密码验证过程,无法识别正确密码。第三,密码更改机制不完善,因为在与服务器通信以更改用户密码时会导致低效通信。因此,我们提出了一种增强安全性的用户认证密钥协商方案升级版。我们的安全性和性能分析表明,与其他相关方案相比,我们的方案不仅提高了安全级别,还确保了效率。