The Experts below are selected from a list of 312 Experts worldwide ranked by ideXlab platform
Debasis Giri - One of the best experts on this subject based on the ideXlab platform.
-
an efficient and robust rsa based remote user authentication for telecare Medical Information Systems
Journal of Medical Systems, 2015Co-Authors: Debasis Giri, Tanmoy Maitra, Ruhul Amin, P D SrivastavaAbstract:It is not always possible for a patient to go to a doctor in critical or urgent period. Telecare Medical Information Systems (TMIS) provides a facility by which a patient can communicate to a doctor through a Medical server via internet from home. To hide the secret Information of both parties (a server and a patient), an authentication mechanism is needed in TMIS. In 2013, Khan and Kumari proposed the authentication schemes for TMIS. In this paper, we have shown that Khan and Kumari's scheme is insecure against off-line password guessing attack. We have also shown that Khan and Kumari's scheme does not provide any security if the password of a patient is compromised. To improve the security and efficiency, a new authentication scheme for TMIS has been proposed in this paper. Further, the proposed scheme can resist all possible attacks and has better performance than the related schemes published earlier.
-
an efficient biometric and password based remote user authentication using smart card for telecare Medical Information Systems in multi server environment
Journal of Medical Systems, 2014Co-Authors: Tanmoy Maitra, Debasis GiriAbstract:The Medical organizations have introduced Telecare Medical Information System (TMIS) to provide a reliable facility by which a patient who is unable to go to a doctor in critical or urgent period, can communicate to a doctor through a Medical server via internet from home. An authentication mechanism is needed in TMIS to hide the secret Information of both parties, namely a server and a patient. Recent research includes patient's biometric Information as well as password to design a remote user authentication scheme that enhances the security level. In a single server environment, one server is responsible for providing services to all the authorized remote patients. However, the problem arises if a patient wishes to access several branch servers, he/she needs to register to the branch servers individually. In 2014, Chuang and Chen proposed an remote user authentication scheme for multi-server environment. In this paper, we have shown that in their scheme, an non-register adversary can successfully logged-in into the system as a valid patient. To resist the weaknesses, we have proposed an authentication scheme for TMIS in multi-server environment where the patients can register to a root telecare server called registration center (RC) in one time to get services from all the telecare branch servers through their registered smart card. Security analysis and comparison shows that our proposed scheme provides better security with low computational and communication cost.
Muhammad Khurram Khan - One of the best experts on this subject based on the ideXlab platform.
-
A Provably Secure RFID Authentication Protocol Based on Elliptic Curve for Healthcare Environments
Journal of Medical Systems, 2016Co-Authors: Mohammad Sabzinejad Farash, Omer Nawaz, Shehzad Ashraf Chaudhry, Khalid Mahmood, Muhammad Khurram KhanAbstract:To enhance the quality of healthcare in the management of chronic disease, telecare Medical Information Systems have increasingly been used. Very recently, Zhang and Qi (J. Med. Syst. 38(5):47, 32), and Zhao (J. Med. Syst. 38(5):46, 33) separately proposed two authentication schemes for telecare Medical Information Systems using radio frequency identification (RFID) technology. They claimed that their protocols achieve all security requirements including forward secrecy. However, this paper demonstrates that both Zhang and Qi's scheme, and Zhao's scheme could not provide forward secrecy. To augment the security, we propose an efficient RFID authentication scheme using elliptic curves for healthcare environments. The proposed RFID scheme is secure under common random oracle model.
-
cryptanalysis and improvement of an efficient and secure dynamic id based authentication scheme for telecare Medical Information Systems
Security and Communication Networks, 2014Co-Authors: Muhammad Khurram Khan, Saru KumariAbstract:Recently, telecare medicine Information Systems TMIS have emerged as an effective mechanism to raise quality convenience and availability of healthcare services. User authentication schemes play an important role in solving security problems and grant access to healthcare services only to the authorized users. In 2010, a few authentication schemes were proposed for TMIS. These were based on the concept of static identity. In 2012, Chen et al. proposed a dynamic ID-based authentication scheme for TMIS, so that the user's identity is not revealed to anyone. However, Chen et al.'s scheme does not involve complex computations like the previous scheme for TMIS, yet it suffers from various security problems. We will show that attackers can not only impersonate the legal participants of the scheme but can also compute the shared session-key. In fact, it is an attack over the confidential communication between the participants. We will also show other drawbacks, such as password guessing attack, denial-of-service attack, immediate replay attack, and incomplete password change phase, present in the scheme. We also demonstrate user anonymity breach in Chen et al.'s scheme. To overcome these problems, we propose an improvement to Chen et al.'s scheme with a different approach. Our approach is aimed at providing an authentication mechanism for TMIS with strong security features. Copyright © 2013 John Wiley & Sons, Ltd.
-
Cryptanalysis and Improvement of ‘A Privacy Enhanced Scheme for Telecare Medical Information Systems’
Journal of Medical Systems, 2013Co-Authors: Saru Kumari, Muhammad Khurram Khan, Rahul KumarAbstract:To ensure reliable telecare services some user authentication schemes for telecare Medical Information system (TMIS) have been presented in literature. These schemes are proposed with intent to regulate only authorized access to Medical services so that Medical Information can be protected from misuse. Very recently Jiang et al. proposed a user authentication scheme for TMIS which they claimed to provide enhanced privacy. They made use of symmetric encryption/decryption with cipher block chaining mode (CBC) to achieve the claimed user privacy. Their scheme provides features like user anonymity and user un-traceability unlike its preceding schemes on which it is built. Unluckily, authors overlook some important aspects in designing their scheme due to which it falls short to resist user impersonation attack, guessing attacks and denial of service attack. Besides, its password change phase is not secure; air message confidentiality is at risk and also has some other drawbacks. Therefore, we propose an improved scheme free from problems observed in Jiang et al.’s scheme and more suitable for TMIS.
Changkuo Yeh - One of the best experts on this subject based on the ideXlab platform.
-
an efficient and secure dynamic id based authentication scheme for telecare Medical Information Systems
Journal of Medical Systems, 2012Co-Authors: Hungming Chen, Changkuo YehAbstract:The rapidly increased availability of always-on broadband telecommunication environments and lower-cost vital signs monitoring devices bring the advantages of telemedicine directly into the patient's home. Hence, the control of access to remote Medical servers' resources has become a crucial challenge. A secure authentication scheme between the Medical server and remote users is therefore needed to safeguard data integrity, confidentiality and to ensure availability. Recently, many authentication schemes that use low-cost mobile devices have been proposed to meet these requirements. In contrast to previous schemes, Khan et al. proposed a dynamic ID-based remote user authentication scheme that reduces computational complexity and includes features such as a provision for the revocation of lost or stolen smart cards and a time expiry check for the authentication process. However, Khan et al.'s scheme has some security drawbacks. To remedy theses, this study proposes an enhanced authentication scheme that overcomes the weaknesses inherent in Khan et al.'s scheme and demonstrated this scheme is more secure and robust for use in a telecare Medical Information system.
Tanmoy Maitra - One of the best experts on this subject based on the ideXlab platform.
-
an efficient and robust rsa based remote user authentication for telecare Medical Information Systems
Journal of Medical Systems, 2015Co-Authors: Debasis Giri, Tanmoy Maitra, Ruhul Amin, P D SrivastavaAbstract:It is not always possible for a patient to go to a doctor in critical or urgent period. Telecare Medical Information Systems (TMIS) provides a facility by which a patient can communicate to a doctor through a Medical server via internet from home. To hide the secret Information of both parties (a server and a patient), an authentication mechanism is needed in TMIS. In 2013, Khan and Kumari proposed the authentication schemes for TMIS. In this paper, we have shown that Khan and Kumari's scheme is insecure against off-line password guessing attack. We have also shown that Khan and Kumari's scheme does not provide any security if the password of a patient is compromised. To improve the security and efficiency, a new authentication scheme for TMIS has been proposed in this paper. Further, the proposed scheme can resist all possible attacks and has better performance than the related schemes published earlier.
-
an efficient biometric and password based remote user authentication using smart card for telecare Medical Information Systems in multi server environment
Journal of Medical Systems, 2014Co-Authors: Tanmoy Maitra, Debasis GiriAbstract:The Medical organizations have introduced Telecare Medical Information System (TMIS) to provide a reliable facility by which a patient who is unable to go to a doctor in critical or urgent period, can communicate to a doctor through a Medical server via internet from home. An authentication mechanism is needed in TMIS to hide the secret Information of both parties, namely a server and a patient. Recent research includes patient's biometric Information as well as password to design a remote user authentication scheme that enhances the security level. In a single server environment, one server is responsible for providing services to all the authorized remote patients. However, the problem arises if a patient wishes to access several branch servers, he/she needs to register to the branch servers individually. In 2014, Chuang and Chen proposed an remote user authentication scheme for multi-server environment. In this paper, we have shown that in their scheme, an non-register adversary can successfully logged-in into the system as a valid patient. To resist the weaknesses, we have proposed an authentication scheme for TMIS in multi-server environment where the patients can register to a root telecare server called registration center (RC) in one time to get services from all the telecare branch servers through their registered smart card. Security analysis and comparison shows that our proposed scheme provides better security with low computational and communication cost.
Na Dong - One of the best experts on this subject based on the ideXlab platform.
-
anonymous three party password authenticated key exchange scheme for telecare Medical Information Systems
PLOS ONE, 2014Co-Authors: Qi Xie, Na Dong, Duncan S WongAbstract:Telecare Medical Information Systems (TMIS) provide an effective way to enhance the Medical process between doctors, nurses and patients. For enhancing the security and privacy of TMIS, it is important while challenging to enhance the TMIS so that a patient and a doctor can perform mutual authentication and session key establishment using a third-party Medical server while the privacy of the patient can be ensured. In this paper, we propose an anonymous three-party password-authenticated key exchange (3PAKE) protocol for TMIS. The protocol is based on the efficient elliptic curve cryptosystem. For security, we apply the pi calculus based formal verification tool ProVerif to show that our 3PAKE protocol for TMIS can provide anonymity for patient and doctor while at the same time achieves mutual authentication and session key security. The proposed scheme is secure and efficient, and can be used in TMIS.
-
robust anonymous authentication scheme for telecare Medical Information Systems
Journal of Medical Systems, 2013Co-Authors: Qi Xie, Jun Zhang, Na DongAbstract:Patient can obtain sorts of health-care delivery services via Telecare Medical Information Systems (TMIS). Authentication, security, patient’s privacy protection and data confidentiality are important for patient or doctor accessing to Electronic Medical Records (EMR). In 2012, Chen et al. showed that Khan et al.’s dynamic ID-based authentication scheme has some weaknesses and proposed an improved scheme, and they claimed that their scheme is more suitable for TMIS. However, we show that Chen et al.’s scheme also has some weaknesses. In particular, Chen et al.’s scheme does not provide user’s privacy protection and perfect forward secrecy, is vulnerable to off-line password guessing attack and impersonation attack once user’s smart card is compromised. Further, we propose a secure anonymity authentication scheme to overcome their weaknesses even an adversary can know all Information stored in smart card.