A lightweight authentication scheme for telecare medical information system

The rapid development of information technology promotes the development and application of Telecare Information System (TMIS). However, TMIS also has security problems such as information leakage, false authentication, and key loss. In order to solve the safety problems of TMIS, this paper combines...

Full description

Bibliographic Details
Main Authors: Lijun Xiao, Songyou Xie, Dezhi Han, Wei Liang, Jun Guo, Wen-Kuang Chou
Format: Article
Language:English
Published: Taylor & Francis Group 2021-07-01
Series:Connection Science
Subjects:
Online Access:http://dx.doi.org/10.1080/09540091.2021.1889976
_version_ 1797684104470200320
author Lijun Xiao
Songyou Xie
Dezhi Han
Wei Liang
Jun Guo
Wen-Kuang Chou
author_facet Lijun Xiao
Songyou Xie
Dezhi Han
Wei Liang
Jun Guo
Wen-Kuang Chou
author_sort Lijun Xiao
collection DOAJ
description The rapid development of information technology promotes the development and application of Telecare Information System (TMIS). However, TMIS also has security problems such as information leakage, false authentication, and key loss. In order to solve the safety problems of TMIS, this paper combines Physical Unclonable Function (PUF) and Elliptic Curve Cryptography (ECC) technology to propose an access control and authentication scheme suitable for TMIS. The proposed scheme uses PUF and compact PUF identity authentication models to implement secure mutual authentication between tag and server. The key information in the scheme is generated by PUF, which not only reduces the cost of algorithm design but also avoids the risk of information leakage and key loss. In addition, this article uses ECC technology to encrypt the PUF response information and random numbers, which can ensure that this data information will not be leaked to the attacker. Then through the ProVerif verification tool and security attribute analysis, it is proved that the scheme is safe in the face of major attacks. The comparative analysis results show that the proposed scheme has higher security and is more suitable for TMIS.
first_indexed 2024-03-12T00:24:45Z
format Article
id doaj.art-eeb9571c10b24053904f7ccc1d1fa42c
institution Directory Open Access Journal
issn 0954-0091
1360-0494
language English
last_indexed 2024-03-12T00:24:45Z
publishDate 2021-07-01
publisher Taylor & Francis Group
record_format Article
series Connection Science
spelling doaj.art-eeb9571c10b24053904f7ccc1d1fa42c2023-09-15T10:47:59ZengTaylor & Francis GroupConnection Science0954-00911360-04942021-07-0133376978510.1080/09540091.2021.18899761889976A lightweight authentication scheme for telecare medical information systemLijun Xiao0Songyou Xie1Dezhi Han2Wei Liang3Jun Guo4Wen-Kuang Chou5Guangzhou College of Technology and BusinessHunan UniversityShanghai Maritime UniversityHunan UniversityQuanZhou University of Information Engineering Software CollegeProvidence UniversityThe rapid development of information technology promotes the development and application of Telecare Information System (TMIS). However, TMIS also has security problems such as information leakage, false authentication, and key loss. In order to solve the safety problems of TMIS, this paper combines Physical Unclonable Function (PUF) and Elliptic Curve Cryptography (ECC) technology to propose an access control and authentication scheme suitable for TMIS. The proposed scheme uses PUF and compact PUF identity authentication models to implement secure mutual authentication between tag and server. The key information in the scheme is generated by PUF, which not only reduces the cost of algorithm design but also avoids the risk of information leakage and key loss. In addition, this article uses ECC technology to encrypt the PUF response information and random numbers, which can ensure that this data information will not be leaked to the attacker. Then through the ProVerif verification tool and security attribute analysis, it is proved that the scheme is safe in the face of major attacks. The comparative analysis results show that the proposed scheme has higher security and is more suitable for TMIS.http://dx.doi.org/10.1080/09540091.2021.1889976telecare medical information system (tmis)physical unclonable function (puf)elliptic curve cryptography (ecc)safety analysisprivacy protection
spellingShingle Lijun Xiao
Songyou Xie
Dezhi Han
Wei Liang
Jun Guo
Wen-Kuang Chou
A lightweight authentication scheme for telecare medical information system
Connection Science
telecare medical information system (tmis)
physical unclonable function (puf)
elliptic curve cryptography (ecc)
safety analysis
privacy protection
title A lightweight authentication scheme for telecare medical information system
title_full A lightweight authentication scheme for telecare medical information system
title_fullStr A lightweight authentication scheme for telecare medical information system
title_full_unstemmed A lightweight authentication scheme for telecare medical information system
title_short A lightweight authentication scheme for telecare medical information system
title_sort lightweight authentication scheme for telecare medical information system
topic telecare medical information system (tmis)
physical unclonable function (puf)
elliptic curve cryptography (ecc)
safety analysis
privacy protection
url http://dx.doi.org/10.1080/09540091.2021.1889976
work_keys_str_mv AT lijunxiao alightweightauthenticationschemefortelecaremedicalinformationsystem
AT songyouxie alightweightauthenticationschemefortelecaremedicalinformationsystem
AT dezhihan alightweightauthenticationschemefortelecaremedicalinformationsystem
AT weiliang alightweightauthenticationschemefortelecaremedicalinformationsystem
AT junguo alightweightauthenticationschemefortelecaremedicalinformationsystem
AT wenkuangchou alightweightauthenticationschemefortelecaremedicalinformationsystem
AT lijunxiao lightweightauthenticationschemefortelecaremedicalinformationsystem
AT songyouxie lightweightauthenticationschemefortelecaremedicalinformationsystem
AT dezhihan lightweightauthenticationschemefortelecaremedicalinformationsystem
AT weiliang lightweightauthenticationschemefortelecaremedicalinformationsystem
AT junguo lightweightauthenticationschemefortelecaremedicalinformationsystem
AT wenkuangchou lightweightauthenticationschemefortelecaremedicalinformationsystem