A Multiserver Biometric Authentication Scheme for TMIS using Elliptic Curve Cryptography

J Med Syst. 2016 Nov;40(11):230. doi: 10.1007/s10916-016-0592-4. Epub 2016 Sep 19.

Abstract

Recently several authentication schemes are proposed for telecare medicine information system (TMIS). Many of such schemes are proved to have weaknesses against known attacks. Furthermore, numerous such schemes cannot be used in real time scenarios. Because they assume a single server for authentication across the globe. Very recently, Amin et al. (J. Med. Syst. 39(11):180, 2015) designed an authentication scheme for secure communication between a patient and a medical practitioner using a trusted central medical server. They claimed their scheme to extend all security requirements and emphasized the efficiency of their scheme. However, the analysis in this article proves that the scheme designed by Amin et al. is vulnerable to stolen smart card and stolen verifier attacks. Furthermore, their scheme is having scalability issues along with inefficient password change and password recovery phases. Then we propose an improved scheme. The proposed scheme is more practical, secure and lightweight than Amin et al.'s scheme. The security of proposed scheme is proved using the popular automated tool ProVerif.

Keywords: Authentication; Biometrics; Impersonation attack; Multiserver; ProVerif; Smart card stolen; Stolen verifier.

MeSH terms

  • Biometric Identification / instrumentation*
  • Computer Security / instrumentation*
  • Confidentiality
  • Health Information Exchange
  • Health Smart Cards
  • Humans
  • Telemedicine / instrumentation*