首页> 外文期刊>Journal of ambient intelligence and humanized computing >Security analysis and improvement of bio-hashing based three- factor authentication scheme for telecare medical information systems
【24h】

Security analysis and improvement of bio-hashing based three- factor authentication scheme for telecare medical information systems

机译:远程医疗信息系统基于生物哈希的三因素认证方案的安全性分析与改进

获取原文
获取原文并翻译 | 示例
           

摘要

The deployment of telecare medical information system (TMIS) over public networks gives rise to the threat of exposing sensitive medical information to illegal entities. Although a number of three-factor authentication (3FA) schemes have been developed to address this challenge, most of them are found to be flawed. Understanding security and privacy failures of authentication protocols is a prerequisite to both fixing existing protocols and designing future ones. In this paper, we investigate the 3FA protocol of Lu et al. for TMIS (J Med Syst 39:32, 2015) and reveal that it cannot achieve the claimed security and privacy goals. (1) It fails to provide anonymity and untraceability, and is susceptible to the following attacks targeting user privacy: identity revelation attack, identity guessing attack and tracking attack. (2) It is susceptible to offline password guessing attack, user impersonation attack, and server impersonation attack. Then we present an improved 3FA scheme and show that the new scheme fulfills session key secrecy and mutual authentication using the formal verification tool ProVerif. Moreover, detailed heuristic security analysis is also presented to demonstrate that our new scheme is capable of withstanding various attacks, and provides desired security features. Additionally, performance analysis shows that our proposed protocol is a practical solution for TMIS.
机译:在公共网络上部署远程医疗信息系统(TMIS)带来了将敏感的医疗信息暴露给非法实体的威胁。尽管已经开发了许多三因素身份验证(3FA)方案来应对这一挑战,但发现其中大多数存在缺陷。了解身份验证协议的安全性和隐私失败是修复现有协议和设计未来协议的前提。在本文中,我们研究了Lu等人的3FA协议。 TMIS(J Med Syst 39:32,2015),并表明它无法实现声称的安全和隐私目标。 (1)它不能提供匿名性和不可追溯性,并且容易受到以下针对用户隐私的攻击:身份泄露攻击,身份猜测攻击和跟踪攻击。 (2)容易受到离线密码猜测攻击,用户模拟攻击和服务器模拟攻击。然后,我们提出一种改进的3FA方案,并证明新方案使用形式验证工具ProVerif满足了会话密钥保密和相互认证的要求。此外,还提供了详细的启发式安全分析,以证明我们的新方案能够抵御各种攻击,并提供所需的安全功能。此外,性能分析表明,我们提出的协议是TMIS的实用解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号