首页> 外文期刊>Journal of medical systems >A Secure Chaotic Maps and Smart Cards Based Password Authentication and Key Agreement Scheme with User Anonymity for Telecare Medicine Information Systems
【24h】

A Secure Chaotic Maps and Smart Cards Based Password Authentication and Key Agreement Scheme with User Anonymity for Telecare Medicine Information Systems

机译:Telecare Medicine信息系统的基于安全混沌图和智能卡的用户匿名密码认证和密钥协商方案

获取原文
获取原文并翻译 | 示例
           

摘要

Telecare medicine information system (TMIS) is widely used for providing a convenient and efficient communicating platform between patients at home and physicians at medical centers or home health care (HHC) organizations. To ensure patient privacy, in 2013, Hao et al. proposed a chaotic map based authentication scheme with user anonymity for TMIS. Later, Lee showed that Hao et al.'s scheme is in no provision for providing fairness in session key establishment and gave an efficient user authentication and key agreement scheme using smart cards, in which only few hashing and Chebyshev chaotic map operations are required. In addition, Jiang et al. discussed that Hao et al.'s scheme can not resist stolen smart card attack and they further presented an improved scheme which attempts to repair the security pitfalls found in Hao et al.'s scheme. In this paper, we found that both Lee's and Jiang et al.'s authentication schemes have a serious security problem in that a registered user's secret parameters may be intentionally exposed to many non-registered users and this problem causing the service misuse attack. Therefore, we propose a slight modification on Lee's scheme to prevent the shortcomings. Compared with previous schemes, our improved scheme not only inherits the advantages of Lee's and Jiang et al.'s authentication schemes for TMIS but also remedies the serious security weakness of not being able to withstand service misuse attack.
机译:远程护理医学信息系统(TMIS)被广泛用于在家庭患者与医疗中心或家庭保健(HHC)组织的医生之间提供便捷高效的通信平台。为了确保患者的隐私,2013年,Hao等人。提出了一种基于用户匿名的TMIS混沌地图认证方案。后来,Lee证明了Hao等人的方案没有提供会话密钥建立的公平性,并提供了使用智能卡的高效用户身份验证和密钥协议方案,其中仅需要很少的哈希和Chebyshev混沌映射操作。此外,江等。讨论了Hao等人的方案无法抵抗被盗的智能卡攻击,他们进一步提出了一种改进的方案,该方案试图修复Hao等人的方案中发现的安全隐患。在本文中,我们发现Lee和Jiang等人的身份验证方案都存在严重的安全问题,因为注册用户的秘密参数可能会故意暴露给许多非注册用户,并且此问题会导致服务滥用攻击。因此,我们建议对Lee的方案进行一些修改,以防止该缺点。与以前的方案相比,我们改进的方案不仅继承了Lee和Jiang等人的TMIS身份验证方案的优点,而且还弥补了无法抵御服务滥用攻击的严重安全漏洞。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号