Mutual authentication is one of the most efficient mechanisms to guarantee secure communication between the patient and the medical server in telecare medicine information system(TMIS). We remark that Sutrala et al’s scheme cannot resist offline password guessing attacks and man-in-the-middle attack and preserve forward secrecy. To overcome these limitations, we present a three factor user authentication protocol using extended chaotic maps for TMIS. Further, the proposed protocol is validated using BAN(Burrows-Abadi-Needham) logic. In addition, security analysis of our proposed protocol is to demonstrate its resilience against the well-known malicious attacks. Thus, it is more applicable to telecare medicine environments.
随着网络通信技术的快速发展,为患者和患者家庭提供医疗服务的远程医疗信息系统也得到了快速的发展,并成为现代医疗服务的一种新模式。远程医疗信息系统(telecare medicine information system,TMIS)[1,2,3,4,5,6]是一种提供医生、护士和患者等使用者相互认证[7,8,9]身份并进行安全通信的网络系统。使用远程医疗信息系统来检测患者的健康状况可以大大地减少医疗费用,节约人力和时间。
WEIJ, HUX, LIUW. An improved authentication scheme for telecare medicine information systems[J]. Journal of Medical Systems, 2012, 36(6): 3597-3604. DOI: 10.1007/s10916-012-9835-1 .
[2]
LUY R, LIX L, PENGH P, et al. Robust and efficient biometrics based password authentication scheme for telecare medicine information systems using extended chaotic maps[J]. Journal of Medical System, 2015, 39(6):65. DOI:10.1007/s10916- 015-0229-z .
[3]
SRIVASTRAVAK, AWASTHIA K, KAULS D. A Hash based mutual RFID tag authentication protocol in telecare medicine information system [J]. Journal of Medical Systems, 2015, 39(1):153. DOI:10.1007/s10916-014-0153-7 .
[4]
FAHADT, BIN M. Cryptanalysis and security enhancement of Zhu,s authentication scheme for telecare medicine information system[J]. Security and Communication Networks, 2015, 8(2): 149-158. DOI:10.1002/sec.967 .
[5]
JUNGJ W, MOONJ H, WON D H. Robust biomertic-based anonymous user authentication key agreement scheme for telecare medicine information systems[J]. KSII Transaction on Internet and Information System, 2017,11(7):3720-3745. DOI:10.3837 /tiis.2017.07.023 .
[6]
JIANGQ, CHENZ R, LIB Y. Security analysis and improvement of bio-hashing based three-factor authentication scheme for telecare medical information systems [J]. Journal of Ambient Intelligence and Humanized Computing, 2018,9(4):1061-1073. DOI:10.1007/s12652-017-0516-2 .
[7]
WANGD, MAC G, ZHANGQ M. On the security of an improved password authentication scheme based on ECC[C]// International Conference Information Computing and Applications(LNCS 7473). Berlin: Springer⁃Verlag,2012:181-188.DOI:10.1007/978-3-642-34062-8_24 .
[8]
WANGD, LIW T, WANGP. Measuring two-factor authentication schemes for real-time data access in industrial wireless sensor networks[J]. IEEE Transactions on Industrial Informatics, 2018, 14(9):4081-4092. DOI:10.1109/TII.2018.2834351
[9]
HED B, WANGD, WUS H. Cryptanalysis and improvement of a password-based remote user authentication scheme without smart cards[J]. Information Technology and Control, 2013, 42(2): 105-112.
[10]
LEE J K, RYU S R, YOO K Y. Fingerprint-based remote user authentication scheme using smart cards[J]. Electronics Letters, 2002, 38(12):554. DOI:10.1049/el:20020380 .
[11]
LINC H, LAIY Y. A flexible biometrics remote user authentication scheme [J]. Computer Standards and Interfaces, 2004,27(1):19-23. DOI:10.1016/j.csi.2004.03.003 .
[12]
WUF, XUL, KUMARIS, et al. A novel and provably secure biometrics-based three-factor remote user authentication scheme for mobile client-server networks [J]. Computer & Electrical Engineering, 2015, 45:274-285. DOI: 10.1016/j.compeleceng. 2015.02.015 .
MOONJ H, CHOUY, KIMI, et al. An improvement of robust and efficient biometrics based password authentication scheme for telecare medicine information systems using extended chaotic maps [J]. Journal of Medical System,2016,40(3):70. DOI:10.1007/s10916-015-0422-0 .
[15]
KHANI, CHAUDHRYS A. An anonymous and provably secure biomeric-based authentication scheme using chaotic maps for accessing medical drop data [J]. The Journal of Supercomputing, 2018, 74(8): 3685-3703. DOI: 10.1007/s11071-015 -2467-5 .
[16]
LIC T, LEE C C, WENGC Y, et al. A secure dynamic identify and chaotic maps based user authentication and key agreement scheme for e-healthcare systems [J]. Journal of Medical System, 2016, 40(11):233. DOI:10.1007/s10916-016-0586-2 .
[17]
MADHUSUDHANR, CHAITANYAS N. A robust authentication scheme for telecare medical information systems[J]. Multimedia Tools and Applications. 2018,78(11): 15255-15273. DOI: 10.1007/s11042-018-6884-6 .
[18]
SUTRALAA K, DAS A K, ODELUV, et al. Secure anonymity preserving password based user authentication and session key agreement scheme for telecare medicine information systems [J]. Computer Methods and Programs in Biomedicine, 2016, 135:167-185. DOI: 10.1016/j.cmpb.2016.07.028 .
[19]
RIVLINT J. The Chebyshev polynomials [J]. Mathematics of Computation, 1974, 30(134): 374. DOI:10.2307/2005983 .
[20]
ZHANGL. Cryptanalysis of the public key encryption based on multiple chaotic systems [J]. Chaotic Solitons & Fractals, 2008, 37(3): 669-674. DOI:10.1016/j.chaos.2006.09.047 .
[21]
KOCHERP C, JAFFEJ, JUN B. Differential power analysis[C]// Annual Inernational Cryptology Conference. Berlin:Springer, 1999:388-397.
[22]
CHATTERJEES R, DAS S, CHATTOPADHYAYA K, et al. Secure biometric-based authentication scheme using Chebyshev chaotic map for multi-server environment [J]. IEEE Tansaction Dependable Secure Computing, 2018, 15(5): 824-839. DOI:10. 1109/TDSC.2016.2616876 .