首页> 外文期刊>Journal of medical systems >A Secure and Robust User Authenticated Key Agreement Scheme for Hierarchical Multi-medical Server Environment in TMIS
【24h】

A Secure and Robust User Authenticated Key Agreement Scheme for Hierarchical Multi-medical Server Environment in TMIS

机译:TMIS中的多层多媒体服务器环境的安全可靠的用户认证密钥协商方案

获取原文
获取原文并翻译 | 示例
           

摘要

The telecare medicine information system (TMIS) helps the patients to gain the health monitoring facility at home and access medical services over the Internet of mobile networks. Recently, Amin and Biswas presented a smart card based user authentication and key agreement security protocol usable for TMIS system using the cryptographic one-way hash function and biohashing function, and claimed that their scheme is secure against all possible attacks. Though their scheme is efficient due to usage of one-way hash function, we show that their scheme has several security pitfalls and design flaws, such as (1) it fails to protect privileged-insider attack, (2) it fails to protect strong replay attack, (3) it fails to protect strong man-in-the-middle attack, (4) it has design flaw in user registration phase, (5) it has design flaw in login phase, (6) it has design flaw in password change phase, (7) it lacks of supporting biometric update phase, and (8) it has flaws in formal security analysis. In order to withstand these security pitfalls and design flaws, we aim to propose a secure and robust user authenticated key agreement scheme for the hierarchical multi-server environment suitable in TMIS using the cryptographic one-way hash function and fuzzy extractor. Through the rigorous security analysis including the formal security analysis using the widely-accepted Burrows-Abadi-Needham (BAN) logic, the formal security analysis under the random oracle model and the informal security analysis, we show that our scheme is secure against possible known attacks. Furthermore, we simulate our scheme using the most-widely accepted and used Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The simulation results show that our scheme is also secure. Our scheme is more efficient in computation and communication as compared to Amin-Biswas's scheme and other related schemes. In addition, our scheme supports extra functionality features as compared to other related schemes. As a result, our scheme is very appropriate for practical applications in TMIS.
机译:远程医疗医学信息系统(TMIS)帮助患者在家中获得健康监控设施,并通过移动网络的互联网访问医疗服务。最近,Amin和Biswas提出了一种基于智能卡的用户身份验证和密钥协商安全协议,该协议可用于使用加密单向哈希函数和生物哈希函数的TMIS系统,并声称其方案可抵抗所有可能的攻击。尽管他们的方案由于使用了单向哈希函数而效率很高,但我们证明了他们的方案存在一些安全隐患和设计缺陷,例如(1)无法保护特权内部攻击,(2)无法保护强大的攻击。重播攻击,(3)无法保护强大的中间人攻击,(4)在用户注册阶段存在设计缺陷,(5)在登录阶段存在设计缺陷,(6)具有设计缺陷在密码更改阶段,(7)缺乏支持生物特征更新的阶段,(8)在正式的安全分析中存在缺陷。为了承受这些安全隐患和设计缺陷,我们旨在使用加密单向哈希函数和模糊提取器为适用于TMIS的分层多服务器环境提出一种安全,可靠的用户认证密钥协商方案。通过严格的安全性分析,包括使用广为接受的Burrows-Abadi-Needham(BAN)逻辑的形式安全性分析,随机oracle模型下的形式性安全分析和非正式形式的安全性分析,我们证明了我们的方案可以防范可能的已知攻击。此外,我们使用最广泛接受和使用的Internet安全协议和应用程序自动验证(AVISPA)工具来模拟我们的方案。仿真结果表明我们的方案也是安全的。与Amin-Biswas的方案和其他相关方案相比,我们的方案在计算和通信方面效率更高。此外,与其他相关方案相比,我们的方案还支持其他功能。因此,我们的方案非常适合TMIS中的实际应用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号