Secure privacy-preserving biometric authentication scheme for telecare medicine information systems

J Med Syst. 2014 Nov;38(11):139. doi: 10.1007/s10916-014-0139-5. Epub 2014 Oct 9.

Abstract

Healthcare delivery services via telecare medicine information systems (TMIS) can help patients to obtain their desired telemedicine services conveniently. However, information security and privacy protection are important issues and crucial challenges in healthcare information systems, where only authorized patients and doctors can employ telecare medicine facilities and access electronic medical records. Therefore, a secure authentication scheme is urgently required to achieve the goals of entity authentication, data confidentiality and privacy protection. This paper investigates a new biometric authentication with key agreement scheme, which focuses on patient privacy and medical data confidentiality in TMIS. The new scheme employs hash function, fuzzy extractor, nonce and authenticated Diffie-Hellman key agreement as primitives. It provides patient privacy protection, e.g., hiding identity from being theft and tracked by unauthorized participant, and preserving password and biometric template from being compromised by trustless servers. Moreover, key agreement supports secure transmission by symmetric encryption to protect patient's medical data from being leaked. Finally, the analysis shows that our proposal provides more security and privacy protection for TMIS.

Publication types

  • Research Support, Non-U.S. Gov't

MeSH terms

  • Biometric Identification / instrumentation*
  • Computer Security / instrumentation*
  • Confidentiality*
  • Electronic Health Records / instrumentation
  • Humans
  • Information Systems / instrumentation*
  • Telemedicine / instrumentation*