An Improved Anonymous Authentication Scheme for Telecare Medical Information Systems

An Improved Anonymous Authentication Scheme for Telecare Medical Information Systems
复制标题

DOI:
10.1007/s10916-014-0026-0
复制
发表时间:
2014-05
影响因子:
5.3
通讯作者:
Fengtong Wen;Dianli Guo
Fengtong Wen;Dianli Guo
中科院分区:
医学3区
文献类型:
--
作者:
Fengtong Wen;Dianli Guo

文献摘要

被引文献

相似文献

远程医疗信息系统构建了患者与医疗服务器之间高效、便捷的连接。患者可以通过公共网络享受医疗服务,因此对患者隐私的保护非常重要。最近,Wu et al.指出了酱等人的S认证方案存在的安全缺陷,提出了一种适用于电信管理信息系统的增强认证方案。然而,我们分析了Wu等人的S方案,发现他们的方案遭受了服务器欺骗攻击、离线口令猜测攻击、冒充攻击。此外,吴等人的S方案未能保持所声称的患者匿名性,并且其密码更改阶段不友好且效率低下。因此,我们提出了一种新的用于远程医疗信息系统的匿名认证方案来消除上述缺陷。此外,我们还通过BAN逻辑证明了该方案的完备性。此外,通过Bellare和Rogaways模型证明了所提方案的安全性。与已有的相关方案相比,我们的方案更加安全。
Telecare medical information system (TMIS) constructs an efficient and convenient connection between patients and the medical server. The patients can enjoy medical services through public networks, and hence the protection of patients’ privacy is very significant. Very recently, Wu et al. identified Jiang et al.’s authentication scheme had some security drawbacks and proposed an enhanced authentication scheme for TMIS. However, we analyze Wu et al.’s scheme and show that their scheme suffers from server spoofing attack, off-line password guessing attack, impersonation attack. Moreover, Wu et al.’s scheme fails to preserve the claimed patient anonymity and its password change phase is unfriendly and inefficient. Thereby, we present a novel anonymous authentication scheme for telecare medical information systems to eliminate the aforementioned faults. Besides, We demonstrate the completeness of the proposed scheme through the BAN logic. Furthermore, the security of our proposed scheme is proven through Bellare and Rogaways model. Compared with the related existing schemes, our scheme is more secure.