A Secure and Robust User Authenticated Key Agreement Scheme for Hierarchical Multi-medical Server Environment in TMIS

被引:0
|
作者
Ashok Kumar Das
Vanga Odelu
Adrijit Goswami
机构
[1] International Institute of Information Technology,Center for Security, Theory and Algorithmic Research
[2] Indian Institute of Technology,Department of Mathematics
来源
关键词
Telecare medicine information systems; Authentication; Key agreement; Multi-medical servers; Fuzzy extractor; Biometrics; User anonymity; AVISPA;
D O I
暂无
中图分类号
学科分类号
摘要
The telecare medicine information system (TMIS) helps the patients to gain the health monitoring facility at home and access medical services over the Internet of mobile networks. Recently, Amin and Biswas presented a smart card based user authentication and key agreement security protocol usable for TMIS system using the cryptographic one-way hash function and biohashing function, and claimed that their scheme is secure against all possible attacks. Though their scheme is efficient due to usage of one-way hash function, we show that their scheme has several security pitfalls and design flaws, such as (1) it fails to protect privileged-insider attack, (2) it fails to protect strong replay attack, (3) it fails to protect strong man-in-the-middle attack, (4) it has design flaw in user registration phase, (5) it has design flaw in login phase, (6) it has design flaw in password change phase, (7) it lacks of supporting biometric update phase, and (8) it has flaws in formal security analysis. In order to withstand these security pitfalls and design flaws, we aim to propose a secure and robust user authenticated key agreement scheme for the hierarchical multi-server environment suitable in TMIS using the cryptographic one-way hash function and fuzzy extractor. Through the rigorous security analysis including the formal security analysis using the widely-accepted Burrows-Abadi-Needham (BAN) logic, the formal security analysis under the random oracle model and the informal security analysis, we show that our scheme is secure against possible known attacks. Furthermore, we simulate our scheme using the most-widely accepted and used Automated Validation of Internet Security Protocols and Applications (AVISPA) tool. The simulation results show that our scheme is also secure. Our scheme is more efficient in computation and communication as compared to Amin-Biswas’s scheme and other related schemes. In addition, our scheme supports extra functionality features as compared to other related schemes. As a result, our scheme is very appropriate for practical applications in TMIS.
引用
收藏
相关论文
共 50 条
  • [1] A Secure and Robust User Authenticated Key Agreement Scheme for Hierarchical Multi-medical Server Environment in TMIS
    Das, Ashok Kumar
    Odelu, Vanga
    Goswami, Adrijit
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (09)
  • [2] An Improved User Authentication and Key Agreement Scheme for Multi-medical Server Usable in TMIS
    Lin, Hao
    Wen, Fengtong
    Du, Chunxia
    2016 INTERNATIONAL CONFERENCE ON INFORMATION ENGINEERING AND COMMUNICATIONS TECHNOLOGY (IECT 2016), 2016, : 90 - 95
  • [3] A Novel User Authentication and Key Agreement Protocol for Accessing Multi-Medical Server Usable in TMIS
    Ruhul Amin
    G. P. Biswas
    Journal of Medical Systems, 2015, 39
  • [4] Authenticated Key Agreement Scheme with Strong Anonymity for Multi-Server Environment in TMIS
    Hui Qiao
    Xuewen Dong
    Yulong Shen
    Journal of Medical Systems, 2019, 43
  • [5] A Novel User Authentication and Key Agreement Protocol for Accessing Multi-Medical Server Usable in TMIS
    Amin, Ruhul
    Biswas, G. P.
    JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (03)
  • [6] Authenticated Key Agreement Scheme with Strong Anonymity for Multi-Server Environment in TMIS
    Qiao, Hui
    Dong, Xuewen
    Shen, Yulong
    JOURNAL OF MEDICAL SYSTEMS, 2019, 43 (11)
  • [7] A Lightweight Pseudonym Authentication and Key Agreement Protocol for Multi-medical Server Architecture in TMIS
    Liu, Xiaoxue
    Li, Yanping
    Qu, Juan
    Ding, Yong
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2017, 11 (02): : 924 - 944
  • [8] A secure and provable multi-server authenticated key agreement for TMIS based on Amin et al. scheme
    Irshad, Azeem
    Sher, Muhammad
    Nawaz, Omer
    Chaudhry, Shehzad Ashraf
    Khan, Imran
    Kumari, Saru
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (15) : 16463 - 16489
  • [9] A secure and provable multi-server authenticated key agreement for TMIS based on Amin et al. scheme
    Azeem Irshad
    Muhammad Sher
    Omer Nawaz
    Shehzad Ashraf Chaudhry
    Imran Khan
    Saru Kumari
    Multimedia Tools and Applications, 2017, 76 : 16463 - 16489
  • [10] A Secure Three-Factor Authenticated Key Agreement Scheme for Multi-Server Environment
    Xia, Meichen
    Li, Shiliang
    Liu, Liu
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 64 (03): : 1673 - 1689