Improved dynamic ID-based authentication scheme for telecare medical information systems

J Med Syst. 2013 Apr;37(2):9912. doi: 10.1007/s10916-012-9912-5. Epub 2013 Jan 24.

Abstract

In order to protect users' identity privacy, Chen et al. proposed an efficient dynamic ID-based authentication scheme for telecare medical information systems. However, Chen et al.'s scheme has some weaknesses. In Chen et al.'s scheme, an attacker can track a user by a linkability attack or an off-line identity guessing attack. Chen et al.'s scheme is also vulnerable to an off-line password guessing attack and an undetectable on-line password guessing attack when user's smart card is stolen. In server side, Chen et al.'s scheme needs large computational load to authentication a legal user or reject an illegal user. To remedy the weaknesses in Chen et al.'s scheme, we propose an improved smart card based password authentication scheme. Our analysis shows that the improved scheme can overcome the weaknesses in Chen et al.'s scheme.

MeSH terms

  • Computer Security*
  • Confidentiality*
  • Electronic Health Records*
  • Patient Identification Systems*
  • Radio Frequency Identification Device
  • Telemedicine*
  • User-Computer Interface