A Secure and Robust Password-Based Remote User Authentication Scheme Using Smart Cards for the Integrated EPR Information System.
An integrated EPR (Electronic Patient Record) information system of all the patients provides the medical institutions and the academia with most of the patients' information in details for them to make corrective decisions and clinical decisions in order to maintain and analyze patients' health. In...
| Publicado en: | Journal of Medical Systems Vol. 39; no. 3; pp. 1 - 15 |
|---|---|
| Autor principal: | |
| Formato: | commentary equations & formulas tables/charts Journal Article |
| Publicado: |
Springer Nature
Mar2015
|
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=115925411&site=ehost-live header: @attributes: shortDbName: ccm uiTerm: 115925411 longDbName: CINAHL Complete uiTag: AN controlInfo: bkinfo: dissinfo: jinfo: jid: 01485598 4N0 jtl: Journal of Medical Systems issn: 01485598 maglogo: N pubinfo: dt: Mar2015 vid: 39 iid: 3 pid: 237 pub: Springer Nature place: New York, New York artinfo: ui: 115925411 115925411 115925411 10.1007/s10916-015-0204-8 115925411 ppf: 1 ppct: 14 formats: fmt: @attributes: type: P tig: atl: A Secure and Robust Password-Based Remote User Authentication Scheme Using Smart Cards for the Integrated EPR Information System. aug: au: Das, Ashok affil: Center for Security, Theory and Algorithmic Research International Institute of Information Technology, Hyderabad 500 032 India sug: subj: Electronic Health Records Smart Cards Data Security Internet Protocols ab: An integrated EPR (Electronic Patient Record) information system of all the patients provides the medical institutions and the academia with most of the patients' information in details for them to make corrective decisions and clinical decisions in order to maintain and analyze patients' health. In such system, the illegal access must be restricted and the information from theft during transmission over the insecure Internet must be prevented. Lee et al. proposed an efficient password-based remote user authentication scheme using smart card for the integrated EPR information system. Their scheme is very efficient due to usage of one-way hash function and bitwise exclusive-or (XOR) operations. However, in this paper, we show that though their scheme is very efficient, their scheme has three security weaknesses such as (1) it has design flaws in password change phase, (2) it fails to protect privileged insider attack and (3) it lacks the formal security verification. We also find that another recently proposed Wen's scheme has the same security drawbacks as in Lee at al.'s scheme. In order to remedy these security weaknesses found in Lee et al.'s scheme and Wen's scheme, we propose a secure and efficient password-based remote user authentication scheme using smart cards for the integrated EPR information system. We show that our scheme is also efficient as compared to Lee et al.'s scheme and Wen's scheme as our scheme only uses one-way hash function and bitwise exclusive-or (XOR) operations. Through the security analysis, we show that our scheme is secure against possible known attacks. Furthermore, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and show that our scheme is secure against passive and active attacks. pubtype: Academic Journal doctype: commentary equations & formulas tables/charts Journal Article ougenre: Article language: English refInfo: holdings: @attributes: islocal: N |
|---|