A Provably Secure RFID Authentication Protocol Based on Elliptic Curve for Healthcare Environments

J Med Syst. 2016 Jul;40(7):165. doi: 10.1007/s10916-016-0521-6. Epub 2016 May 24.

Abstract

To enhance the quality of healthcare in the management of chronic disease, telecare medical information systems have increasingly been used. Very recently, Zhang and Qi (J. Med. Syst. 38(5):47, 32), and Zhao (J. Med. Syst. 38(5):46, 33) separately proposed two authentication schemes for telecare medical information systems using radio frequency identification (RFID) technology. They claimed that their protocols achieve all security requirements including forward secrecy. However, this paper demonstrates that both Zhang and Qi's scheme, and Zhao's scheme could not provide forward secrecy. To augment the security, we propose an efficient RFID authentication scheme using elliptic curves for healthcare environments. The proposed RFID scheme is secure under common random oracle model.

Keywords: Authentication; Elliptic curve; RFID; Random oracle model; Telecare medical information systems; Untraceable privacy.

MeSH terms

  • Algorithms
  • Computer Security
  • Confidentiality
  • Humans
  • Radio Frequency Identification Device / methods*
  • Radio Frequency Identification Device / standards
  • Telemedicine / methods*
  • Telemedicine / standards