School of Mathematics and Statistics, Wuhan University, Wuhan 430072, China.
Wuhan Maritime Communication Research Institute, Hubei 430205, China.
Comput Methods Programs Biomed. 2018 Oct;164:101-109. doi: 10.1016/j.cmpb.2018.07.008. Epub 2018 Jul 18.
Telecare Medicine Information System (TMIS) enables physicians to efficiently and conveniently make certain diagnoses and medical treatment for patients over the insecure public Internet. To ensure patients securely access to medicinal services, many authentication schemes have been proposed. Although numerous cryptographic authentication schemes for TMIS have been proposed with the aim to ensure data security, user privacy and authentication, various forms of attacks make these schemes impractical.
To design a truly secure and practical authentication scheme for TMIS, a new biometrics-based authentication key exchange protocol for multi-server TMIS without sharing the system private key with distributed servers is presented in this work.
Our proposed protocol has perfect security features including mutual authentication, user anonymity, perfect forward secrecy and resisting various well-known attacks, and these security feathers are confirmed by the BAN logic and heuristic cryptanalysis, respectively.
A secure biometrics-based authentication key exchange protocol for multi-server TMIS is presented in this work, which has perfect security properties including perfect forward secrecy, supporting user anonymity, etc., and can withstand various attacks such as impersonation attack, off-line password guessing attack, etc.. Considering security is the most important factor for an authentication scheme, so our scheme is more suitable for multi-server TMIS.
远程医疗信息系统(TMIS)使医生能够通过不安全的公共互联网为患者进行高效、便捷的诊断和治疗。为确保患者安全地获得医疗服务,已经提出了许多身份验证方案。虽然已经提出了许多针对 TMIS 的加密身份验证方案,旨在确保数据安全、用户隐私和身份验证,但各种形式的攻击使得这些方案不切实际。
为了设计一个真正安全实用的 TMIS 认证方案,本文提出了一种新的基于生物特征的多服务器 TMIS 认证密钥交换协议,该协议无需与分布式服务器共享系统私钥。
我们提出的协议具有完美的安全特性,包括相互认证、用户匿名性、完美前向保密性和抵抗各种已知攻击,这些安全特性分别通过 BAN 逻辑和启发式密码分析得到确认。
本文提出了一种基于生物特征的多服务器 TMIS 认证密钥交换协议,该协议具有完美的安全特性,包括完美前向保密性、支持用户匿名性等,并能抵御各种攻击,如冒充攻击、离线密码猜测攻击等。考虑到安全性是认证方案最重要的因素,因此我们的方案更适合多服务器 TMIS。