4.6 Article

A Multiserver Biometric Authentication Scheme for TMIS using Elliptic Curve Cryptography

期刊

JOURNAL OF MEDICAL SYSTEMS
卷 40, 期 11, 页码 -

出版社

SPRINGER
DOI: 10.1007/s10916-016-0592-4

关键词

Biometrics; Authentication; Multiserver; Impersonation attack; Smart card stolen; Stolen verifier; ProVerif

资金

  1. Deanship of Scientific Research at King Saud University [PRG-1436-16]
  2. Institute for Information & communications Technology Promotion(IITP) - Korea government(MSIP) [B0713-15-0007]
  3. Ministry of Public Safety & Security (MPSS), Republic of Korea [B0713-15-0007] Funding Source: Korea Institute of Science & Technology Information (KISTI), National Science & Technology Information Service (NTIS)

向作者/读者索取更多资源

Recently several authentication schemes are proposed for telecare medicine information system (TMIS). Many of such schemes are proved to have weaknesses against known attacks. Furthermore, numerous such schemes cannot be used in real time scenarios. Because they assume a single server for authentication across the globe. Very recently, Amin et al. (J. Med. Syst. 39(11): 180, 2015) designed an authentication scheme for secure communication between a patient and a medical practitioner using a trusted central medical server. They claimed their scheme to extend all security requirements and emphasized the efficiency of their scheme. However, the analysis in this article proves that the scheme designed by Amin et al. is vulnerable to stolen smart card and stolen verifier attacks. Furthermore, their scheme is having scalability issues along with inefficient password change and password recovery phases. Then we propose an improved scheme. The proposed scheme is more practical, secure and lightweight than Amin et al.'s scheme. The security of proposed scheme is proved using the popular automated tool ProVerif.

作者

我是这篇论文的作者
点击您的名字以认领此论文并将其添加到您的个人资料中。

评论

主要评分

4.6
评分不足

次要评分

新颖性
-
重要性
-
科学严谨性
-
评价这篇论文

推荐

暂无数据
暂无数据