首页> 美国卫生研究院文献>other >An Improved and Secure Anonymous Biometric-Based User Authentication with Key Agreement Scheme for the Integrated EPR Information System
【2h】

An Improved and Secure Anonymous Biometric-Based User Authentication with Key Agreement Scheme for the Integrated EPR Information System

机译:集成的EPR信息系统的改进和安全的基于密钥的匿名生物识别的用户身份验证方案

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Nowadays, many hospitals and medical institutes employ an authentication protocol within electronic patient records (EPR) services in order to provide protected electronic transactions in e-medicine systems. In order to establish efficient and robust health care services, numerous studies have been carried out on authentication protocols. Recently, Li et al. proposed a user authenticated key agreement scheme according to EPR information systems, arguing that their scheme is able to resist various types of attacks and preserve diverse security properties. However, this scheme possesses critical vulnerabilities. First, the scheme cannot prevent off-line password guessing attacks and server spoofing attack, and cannot preserve user identity. Second, there is no password verification process with the failure to identify the correct password at the beginning of the login phase. Third, the mechanism of password change is incompetent, in that it induces inefficient communication in communicating with the server to change a user password. Therefore, we suggest an upgraded version of the user authenticated key agreement scheme that provides enhanced security. Our security and performance analysis shows that compared to other related schemes, our scheme not only improves the security level, but also ensures efficiency.
机译:如今,许多医院和医疗机构都在电子病历(EPR)服务中采用了认证协议,以便在电子医疗系统中提供受保护的电子交易。为了建立有效和健壮的保健服务,已经对认证协议进行了许多研究。最近,李等人。提出了一种根据EPR信息系统的用户认证密钥协商方案,认为他们的方案能够抵抗各种类型的攻击并保留各种安全性。但是,此方案具有严重漏洞。首先,该方案无法防止离线密码猜测攻击和服务器欺骗攻击,并且无法保留用户身份。其次,没有密码验证过程,因为在登录阶段开始时无法识别正确的密码。第三,密码更改机制是不称职的,因为它导致与服务器进行通信以更改用户密码时通信效率低下。因此,我们建议用户认证密钥协商方案的升级版本,以提供增强的安全性。我们的安全性和性能分析表明,与其他相关方案相比,我们的方案不仅提高了安全级别,而且确保了效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号