Security analysis and improvement of bio-hashing based three-factor authentication scheme for telecare medical information systems

Security analysis and improvement of bio-hashing based three-factor authentication scheme for telecare medical information systems
复制标题

DOI:
10.1007/s12652-017-0516-2
复制
发表时间:
2018-08-01
影响因子:
--
通讯作者:
Ma, Jianfeng
Ma, Jianfeng
中科院分区:
计算机科学3区
文献类型:
--
作者:
Jiang, Qi;Chen, Zhiren;Ma, Jianfeng

文献摘要

被引文献

相似文献

远程医疗信息系统(TMIS)在公共网络上的部署引起了将敏感医疗信息暴露给非法实体的威胁。虽然已经开发了许多三因素身份验证(3FA)方案来解决这一挑战,但大多数方案都存在缺陷。了解认证协议的安全性和隐私性故障是修复现有协议和设计未来协议的先决条件。在本文中,我们研究了Lu等人的TMIS 3FA协议(J Med Syst 39:32,2015),并发现它无法实现所声称的安全和隐私目标。(1)它不能提供匿名性和不可追踪性,容易受到以下针对用户隐私的攻击:身份泄露攻击,身份猜测攻击和跟踪攻击。(2)它容易受到离线密码猜测攻击、用户模拟攻击和服务器模拟攻击。然后提出了一种改进的3FA方案,并使用形式化验证工具ProVerif证明了新方案能够实现会话密钥保密和相互认证。此外,详细的启发式安全分析也被提出来证明我们的新方案是能够抵御各种攻击,并提供了所需的安全特性。此外,性能分析表明,我们提出的协议是一个实用的解决方案TMIS。
The deployment of telecare medical information system (TMIS) over public networks gives rise to the threat of exposing sensitive medical information to illegal entities. Although a number of three-factor authentication (3FA) schemes have been developed to address this challenge, most of them are found to be flawed. Understanding security and privacy failures of authentication protocols is a prerequisite to both fixing existing protocols and designing future ones. In this paper, we investigate the 3FA protocol of Lu et al. for TMIS (J Med Syst 39:32, 2015) and reveal that it cannot achieve the claimed security and privacy goals. (1) It fails to provide anonymity and untraceability, and is susceptible to the following attacks targeting user privacy: identity revelation attack, identity guessing attack and tracking attack. (2) It is susceptible to offline password guessing attack, user impersonation attack, and server impersonation attack. Then we present an improved 3FA scheme and show that the new scheme fulfills session key secrecy and mutual authentication using the formal verification tool ProVerif. Moreover, detailed heuristic security analysis is also presented to demonstrate that our new scheme is capable of withstanding various attacks, and provides desired security features. Additionally, performance analysis shows that our proposed protocol is a practical solution for TMIS.