1. A Hash Based Remote User Authentication and Authenticated Key Agreement Scheme for the Integrated EPR Information System.
- Author
-
Li, Chun-Ta, Weng, Chi-Yao, Lee, Cheng-Chi, and Wang, Chun-Cheng
- Subjects
- *
DATA security failures , *INFORMATION storage & retrieval systems , *MEDICAL databases , *MEDICAL records , *RESEARCH funding , *DATA security , *PREVENTION - Abstract
To protect patient privacy and ensure authorized access to remote medical services, many remote user authentication schemes for the integrated electronic patient record (EPR) information system have been proposed in the literature. In a recent paper, Das proposed a hash based remote user authentication scheme using passwords and smart cards for the integrated EPR information system, and claimed that the proposed scheme could resist various passive and active attacks. However, in this paper, we found that Das's authentication scheme is still vulnerable to modification and user duplication attacks. Thereafter we propose a secure and efficient authentication scheme for the integrated EPR information system based on lightweight hash function and bitwise exclusive-or (XOR) operations. The security proof and performance analysis show our new scheme is well-suited to adoption in remote medical healthcare services. [ABSTRACT FROM AUTHOR]
- Published
- 2015
- Full Text
- View/download PDF