Cryptanalysis and improvement of authentication and key agreement protocols for telecare medicine information systems

J Med Syst. 2014 Oct;38(10):135. doi: 10.1007/s10916-014-0135-9. Epub 2014 Sep 5.

Abstract

Recently, many authentication protocols have been presented using smartcard for the telecare medicine information system (TMIS). In 2014, Xu et al. put forward a two-factor mutual authentication with key agreement protocol using elliptic curve cryptography (ECC). However, the authors have proved that the protocol is not appropriate for practical use as it has many problems (1) it fails to achieve strong authentication in login and authentication phases; (2) it fails to update the password correctly in the password change phase; (3) it fails to provide the revocation of lost/stolen smartcard; and (4) it fails to protect the strong replay attack. We then devised an anonymous and provably secure two-factor authentication protocol based on ECC. Our protocol is analyzed with the random oracle model and demonstrated to be formally secured against the hardness assumption of computational Diffie-Hellman problem. The performance evaluation demonstrated that our protocol outperforms from the perspective of security, functionality and computation costs over other existing designs.

Publication types

  • Research Support, Non-U.S. Gov't

MeSH terms

  • Access to Information*
  • Computer Security*
  • Computer Simulation
  • Game Theory
  • Information Systems / standards*
  • Mathematical Concepts
  • Medical Informatics*
  • Telemedicine*