Security enhancement of a biometric based authentication scheme for telecare medicine information systems with nonce

J Med Syst. 2014 May;38(5):41. doi: 10.1007/s10916-014-0041-1. Epub 2014 Apr 26.

Abstract

Telecare medicine information systems (TMIS) present the platform to deliver clinical service door to door. The technological advances in mobile computing are enhancing the quality of healthcare and a user can access these services using its mobile device. However, user and Telecare system communicate via public channels in these online services which increase the security risk. Therefore, it is required to ensure that only authorized user is accessing the system and user is interacting with the correct system. The mutual authentication provides the way to achieve this. Although existing schemes are either vulnerable to attacks or they have higher computational cost while an scalable authentication scheme for mobile devices should be secure and efficient. Recently, Awasthi and Srivastava presented a biometric based authentication scheme for TMIS with nonce. Their scheme only requires the computation of the hash and XOR functions.pagebreak Thus, this scheme fits for TMIS. However, we observe that Awasthi and Srivastava's scheme does not achieve efficient password change phase. Moreover, their scheme does not resist off-line password guessing attack. Further, we propose an improvement of Awasthi and Srivastava's scheme with the aim to remove the drawbacks of their scheme.

MeSH terms

  • Computer Security*
  • Confidentiality
  • Electronic Health Records / organization & administration*
  • Humans
  • Patient Identification Systems / organization & administration*
  • Radio Frequency Identification Device
  • Telemedicine / organization & administration*