Cryptanalysis and security enhancement of Zhu's authentication scheme for Telecare medicine information system

Authors

  • Fahad T. Bin Muhaya

    Corresponding author
    1. Prince Muqrin Chair for IT Security, Department of Management Information Systems, College of Business Administration, King Saud University, Saudi Arabia
    • Correspondence: Fahad T. Bin Muhaya, Prince Muqrin Chair for IT Security, Department of Management Information Systems, College of Business Administration, King Saud University, Saudi Arabia.

      E-mail: gmuva@hotmail.com

    Search for more papers by this author

ABSTRACT

The concept of Telecare medicine information systems (TMISs) has evolved to provide better health care to the masses. So the control of access to privileged services provided by TMIS is a crucial concern. Recently, Zhu proposed an authentication scheme for TMIS, which he claimed to be more suitable for TMIS environments than the scheme of Wei et al. especially regarding resistance to offline password guessing attack. However, this paper shows that Zhu's scheme still suffers from offline password guessing attack. We also show how an attacker can impersonate a legal user merely by intercepting a login request and how a legal user (patient) may often become victim of denial-of-service in crucial TMIS applications. We further show its vulnerability to online password guessing attack and smart card loss attack. To sort out these discrepancies from Zhu's scheme, we propose an improved scheme with session key establishment and user anonymity. Moreover, this improvement is achieved without adding any complex operation; even the communication cost of the proposed scheme is lesser than that in Zhu's scheme. Analysis shows the robustness as well as the simplicity of the proposed scheme. Copyright © 2014 John Wiley & Sons, Ltd.

Ancillary