首页> 外文会议>International Computer Conference, Computer Society of Iran >An Improved Secure Authentication and Key Agreement Scheme for Healthcare Applications
【24h】

An Improved Secure Authentication and Key Agreement Scheme for Healthcare Applications

机译:一种改进的安全认证和医疗保健应用的关键协议计划

获取原文

摘要

Telecare medical information systems are developed to establish an online convenient communication platform for patients and medical staff to exchange healthcare related services. Being installed on Internet, these systems are prone to different security and privacy threats, which may result in leakage of sensitive health-related data and privacy compromise of the patients. Hence, a major challenge is to establish a secure communication channel between the patients and medical servers, where parties are mutually authenticated and a session key is agreed upon and shared between them for further information exchange. Recently, Ostad-Sharif et al. presented an ECC- based anonymous authentication and key agreement method for healthcare applications. In this article, we first prove that Ostad- sharif et al.'s scheme is vulnerable to key compromise password guessing attacks and key compromise impersonation attacks. Then, we propose a secure and efficient authentication and key agreement scheme for telecare medical information systems which can provide mutual authentication and perfect forward secrecy, and resists against key compromise password guessing attacks, key compromise impersonation attacks, insider attacks, and replay attacks. The security of the proposed scheme is also proved formally with the Scyther tool.
机译:为了展开患者和医务人员,开发了Telecare医疗信息系统以建立在线方便的通信平台,以交换医疗保健相关服务。这些系统在互联网上安装,易于不同的安全和隐私威胁,这可能导致敏感的健康相关数据和隐私妥协泄漏。因此,主要挑战是在患者和医疗服务器之间建立安全的通信渠道,缔约方相互认证,并在他们之间商定和共享会话密钥以获取更多信息交流。最近,OSTAD-Sharif等人。介绍了基于ECC的匿名认证和医疗保健应用程序的关键协议方法。在这篇文章中,我们首先证明Ostad-谢里夫等人的方案很容易受到密钥泄露密码猜测攻击和密钥泄露伪装攻击。然后,我们为远程护理医疗信息系统提出了安全有效的认证和关键协议计划,可以提供相互认证和完善的前锋保密,并抵抗关键损害密码猜测攻击,关键损害模拟攻击,内幕攻击和重播攻击。拟议方案的安全性也与脱乳汁工具正式证明。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号