A privacy preserving secure and efficient authentication scheme for telecare medical information systems

J Med Syst. 2015 May;39(5):54. doi: 10.1007/s10916-015-0215-5. Epub 2015 Mar 8.

Abstract

The Telecare medical information system (TMIS) presents effective healthcare delivery services by employing information and communication technologies. The emerging privacy and security are always a matter of great concern in TMIS. Recently, Chen at al. presented a password based authentication schemes to address the privacy and security. Later on, it is proved insecure against various active and passive attacks. To erase the drawbacks of Chen et al.'s anonymous authentication scheme, several password based authentication schemes have been proposed using public key cryptosystem. However, most of them do not present pre-smart card authentication which leads to inefficient login and password change phases. To present an authentication scheme with pre-smart card authentication, we present an improved anonymous smart card based authentication scheme for TMIS. The proposed scheme protects user anonymity and satisfies all the desirable security attributes. Moreover, the proposed scheme presents efficient login and password change phases where incorrect input can be quickly detected and a user can freely change his password without server assistance. Moreover, we demonstrate the validity of the proposed scheme by utilizing the widely-accepted BAN (Burrows, Abadi, and Needham) logic. The proposed scheme is also comparable in terms of computational overheads with relevant schemes.

MeSH terms

  • Computer Security*
  • Confidentiality
  • Health Information Exchange
  • Humans
  • Medical Records Systems, Computerized / organization & administration*
  • Medical Records Systems, Computerized / standards
  • Telemedicine / organization & administration*
  • Telemedicine / standards