Cryptanalysis and improvement of 'A privacy enhanced scheme for telecare medical information systems'

J Med Syst. 2013 Aug;37(4):9952. doi: 10.1007/s10916-013-9952-5. Epub 2013 May 22.

Abstract

To ensure reliable telecare services some user authentication schemes for telecare medical information system (TMIS) have been presented in literature. These schemes are proposed with intent to regulate only authorized access to medical services so that medical information can be protected from misuse. Very recently Jiang et al. proposed a user authentication scheme for TMIS which they claimed to provide enhanced privacy. They made use of symmetric encryption/decryption with cipher block chaining mode (CBC) to achieve the claimed user privacy. Their scheme provides features like user anonymity and user un-traceability unlike its preceding schemes on which it is built. Unluckily, authors overlook some important aspects in designing their scheme due to which it falls short to resist user impersonation attack, guessing attacks and denial of service attack. Besides, its password change phase is not secure; air message confidentiality is at risk and also has some other drawbacks. Therefore, we propose an improved scheme free from problems observed in Jiang et al.'s scheme and more suitable for TMIS.

Publication types

  • Comment

MeSH terms

  • Computer Security*
  • Confidentiality*
  • Humans
  • Information Systems / organization & administration*
  • Telemedicine / organization & administration*