首页> 外文期刊>Journal of medical systems >A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity
【24h】

A Secure Three-Factor User Authentication and Key Agreement Protocol for TMIS With User Anonymity

机译:具有用户匿名性的TMIS的安全三因素用户认证和密钥协商协议

获取原文
获取原文并翻译 | 示例
           

摘要

Telecare medical information system (TMIS) makes an efficient and convenient connection between patient(s)/user(s) and doctor(s) over the insecure internet. Therefore, data security, privacy and user authentication are enormously important for accessing important medical data over insecure communication. Recently, many user authentication protocols for TMIS have been proposed in the literature and it has been observed that most of the protocols cannot achieve complete security requirements. In this paper, we have scrutinized two (Mishra et al., Xu et al.) remote user authentication protocols using smart card and explained that both the protocols are suffering against several security weaknesses. We have then presented three-factor user authentication and key agreement protocol usable for TMIS, which fix the security pitfalls of the above mentioned schemes. The informal cryptanalysis makes certain that the proposed protocol provides well security protection on the relevant security attacks. Furthermore, the simulator AVISPA tool confirms that the protocol is secure against active and passive attacks including replay and man-in-the-middle attacks. The security functionalities and performance comparison analysis confirm that our protocol not only provide strong protection on security attacks, but it also achieves better complexities along with efficient login and password change phase as well as session key verification property.
机译:Telecare医疗信息系统(TMIS)通过不安全的Internet在患者/用户和医生之间建立了高效便捷的连接。因此,数据安全性,隐私性和用户身份验证对于通过不安全的通信访问重要的医学数据极为重要。近来,在文献中已经提出了许多用于TMIS的用户认证协议,并且已经观察到大多数协议不能达到完整的安全性要求。在本文中,我们详细研究了使用智能卡的两种(Mishra等人,Xu等人)远程用户身份验证协议,并解释说这两种协议都存在一些安全漏洞。然后,我们提出了可用于TMIS的三要素用户身份验证和密钥协商协议,该协议解决了上述方案的安全隐患。非正式的密码分析确保了所提出的协议对相关的安全攻击提供了良好的安全保护。此外,模拟器AVISPA工具可确认该协议对主动和被动攻击(包括重播和中间人攻击)是安全的。安全功能和性能比较分析证实,我们的协议不仅为安全攻击提供了强大的保护,而且在有效的登录和密码更改阶段以及会话密钥验证属性的同时,还实现了更好的复杂性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号