Back to Search Start Over

An Improved RSA Based User Authentication and Session Key Agreement Protocol Usable in TMIS.

Authors :
Amin, Ruhul
Biswas, G.
Source :
Journal of Medical Systems. Aug2015, Vol. 39 Issue 8, p1-14. 14p.
Publication Year :
2015

Abstract

Recently, Giri et al.'s proposed a RSA cryptosystem based remote user authentication scheme for telecare medical information system and claimed that the protocol is secure against all the relevant security attacks. However, we have scrutinized the Giri et al.'s protocol and pointed out that the protocol is not secure against off-line password guessing attack, privileged insider attack and also suffers from anonymity problem. Moreover, the extension of password guessing attack leads to more security weaknesses. Therefore, this protocol needs improvement in terms of security before implementing in real-life application. To fix the mentioned security pitfalls, this paper proposes an improved scheme over Giri et al.'s scheme, which preserves user anonymity property. We have then simulated the proposed protocol using widely-accepted AVISPA tool which ensures that the protocol is SAFE under OFMC and CL-AtSe models, that means the same protocol is secure against active and passive attacks including replay and man-in-the-middle attacks. The informal cryptanalysis has been also presented, which confirmed that the proposed protocol provides well security protection on the relevant security attacks. The performance analysis section compares the proposed protocol with other existing protocols in terms of security and it has been observed that the protocol provides more security and achieves additional functionalities such as user anonymity and session key verification. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
01485598
Volume :
39
Issue :
8
Database :
Academic Search Index
Journal :
Journal of Medical Systems
Publication Type :
Academic Journal
Accession number :
115925517
Full Text :
https://doi.org/10.1007/s10916-015-0262-y