Back to Search Start Over

An authentication scheme for secure access to healthcare services.

Authors :
Khan MK
Kumari S
Source :
Journal of medical systems [J Med Syst] 2013 Aug; Vol. 37 (4), pp. 9954. Date of Electronic Publication: 2013 Jul 05.
Publication Year :
2013

Abstract

Last few decades have witnessed boom in the development of information and communication technologies. Health-sector has also been benefitted with this advancement. To ensure secure access to healthcare services some user authentication mechanisms have been proposed. In 2012, Wei et al. proposed a user authentication scheme for telecare medical information system (TMIS). Recently, Zhu pointed out offline password guessing attack on Wei et al.'s scheme and proposed an improved scheme. In this article, we analyze both of these schemes for their effectiveness in TMIS. We show that Wei et al.'s scheme and its improvement proposed by Zhu fail to achieve some important characteristics necessary for secure user authentication. We find that security problems of Wei et al.'s scheme stick with Zhu's scheme; like undetectable online password guessing attack, inefficacy of password change phase, traceability of user's stolen/lost smart card and denial-of-service threat. We also identify that Wei et al.'s scheme lacks forward secrecy and Zhu's scheme lacks session key between user and healthcare server. We therefore propose an authentication scheme for TMIS with forward secrecy which preserves the confidentiality of air messages even if master secret key of healthcare server is compromised. Our scheme retains advantages of Wei et al.'s scheme and Zhu's scheme, and offers additional security. The security analysis and comparison results show the enhanced suitability of our scheme for TMIS.

Details

Language :
English
ISSN :
1573-689X
Volume :
37
Issue :
4
Database :
MEDLINE
Journal :
Journal of medical systems
Publication Type :
Academic Journal
Accession number :
23828650
Full Text :
https://doi.org/10.1007/s10916-013-9954-3