• Title of article

    Cryptanalysis and improvement of a passwordbased user authentication scheme for the integrated EPR information system

  • Author/Authors

    Islam, SK Hafizul Birla Institute of Technology and Science, Pilani Campus - Department of Computer Science and Information Systems, India , Islam, SK Hafizul Indian School of Mines - Department of Computer Science and Engineering, India , Biswas, G.P. Indian School of Mines - Department of Computer Science and Engineering, India

  • From page
    211
  • To page
    221
  • Abstract
    Recently, Wu et al. proposed a password-based remote user authentication scheme for the integrated Electronic Patient Record (EPR) information system to achieve mutual authentication and session key agreement over the Internet. They claimed that the scheme resists various attacks and offers lower computation cost, data integrity, confidentiality and authenticity. However, we observed that the scheme cannot withstand lost smartcard/off-line password guessing, privileged-insider and known session-specific temporary information attacks, and lacks the requirements of lost smartcard revocation and users’ anonymity. Besides, the password change phase is inconvenient to use because a user cannot change his password independently. Thus, we proposed a new password-based user authentication scheme for the integrated EPR information system that would be able to resist detected security flaws of Wu et al.’s scheme
  • Keywords
    EPR information system , Two , factor user authentication , Password , Healthcare , Smartcard , Anonymity
  • Journal title
    Journal Of King Saud University - Computer an‎d Information Sciences
  • Journal title
    Journal Of King Saud University - Computer an‎d Information Sciences
  • Record number

    2713627