Cryptanalysis and improvement of authentication and key agreement protocols for telecare medicine information systems

SH Islam, MK Khan�- Journal of medical systems, 2014 - Springer
Journal of medical systems, 2014Springer
Recently, many authentication protocols have been presented using smartcard for the
telecare medicine information system (TMIS). In 2014, Xu et al. put forward a two-factor
mutual authentication with key agreement protocol using elliptic curve cryptography (ECC).
However, the authors have proved that the protocol is not appropriate for practical use as it
has many problems (1) it fails to achieve strong authentication in login and authentication
phases;(2) it fails to update the password correctly in the password change phase;(3) it fails�…
Abstract
Recently, many authentication protocols have been presented using smartcard for the telecare medicine information system (TMIS). In 2014, Xu et al. put forward a two-factor mutual authentication with key agreement protocol using elliptic curve cryptography (ECC). However, the authors have proved that the protocol is not appropriate for practical use as it has many problems (1) it fails to achieve strong authentication in login and authentication phases; (2) it fails to update the password correctly in the password change phase; (3) it fails to provide the revocation of lost/stolen smartcard; and (4) it fails to protect the strong replay attack. We then devised an anonymous and provably secure two-factor authentication protocol based on ECC. Our protocol is analyzed with the random oracle model and demonstrated to be formally secured against the hardness assumption of computational Diffie-Hellman problem. The performance evaluation demonstrated that our protocol outperforms from the perspective of security, functionality and computation costs over other existing designs.
Springer
Showing the best result for this search. See all results