Cryptanalysis and improvement of an improved two factor authentication protocol for telecare medical information systems

J Med Syst. 2015 Jun;39(6):66. doi: 10.1007/s10916-015-0244-0. Epub 2015 Apr 26.

Abstract

Telecare medical information systems (TMIS) provides rapid and convenient health care services remotely. Efficient authentication is a prerequisite to guarantee the security and privacy of patients in TMIS. Authentication is used to verify the legality of the patients and TMIS server during remote access. Very recently Islam et al. (J. Med. Syst. 38(10):135, 2014) proposed a two factor authentication protocol for TMIS using elliptic curve cryptography (ECC) to improve Xu et al.'s (J. Med. Syst. 38(1):9994, 2014) protocol. They claimed their improved protocol to be efficient and provides all security requirements. However our analysis reveals that Islam et al.'s protocol suffers from user impersonation and server impersonation attacks. Furthermore we proposed an enhanced protocol. The proposed protocol while delivering all the virtues of Islam et al.'s protocol resists all known attacks.

MeSH terms

  • Communication
  • Computer Security / standards*
  • Confidentiality / standards*
  • Health Information Systems / organization & administration
  • Health Information Systems / standards*
  • Humans
  • Patient Access to Records / standards*
  • Professional-Patient Relations
  • Telemedicine / methods
  • Telemedicine / organization & administration
  • Telemedicine / standards*
  • User-Computer Interface