• Title of article

    A secure effective dynamic group password-based authenticated key agreement scheme for the integrated EPR information system

  • Author/Authors

    Odelu, Vanga Indian Institute of Technology - Department of Mathematics, India , Odelu, Vanga Rajiv Gandhi University of Knowledge Technologies - Department of Mathematics, India , Das, Ashok Kumar International Institute of Information Technology - Center for Security, Theory and Algorithmic Research, India , Goswami, Adrijit Indian Institute of Technology - Department of Mathematics, India

  • From page
    68
  • To page
    81
  • Abstract
    With the rapid growth of the Internet, a lot of electronic patient records (EPRs) have been developed for e-medicine systems. The security and privacy issues of EPRs are important for the patients in order to understand how the hospitals control the use of their personal information, such as name, address, e-mail, medical records, etc. of a particular patient. Recently, Lee et al. proposed a simple group password-based authenticated key agreement protocol for the integrated EPR information system (SGPAKE). However, in this paper, we show that Lee et al.’s protocol is vulnerable to the off-line weak password guessing attack and as a result, their scheme does not provide users’ privacy. To withstand this security weakness found in Lee et al.’s scheme, we aim to propose an effective dynamic group password-based authenticated key exchange scheme for the integrated EPR information system, which retains the original merits of Lee et al.’s scheme. Through the informal and formal security analysis, we show that our scheme provides users’ privacy, perfect forward security and known-key security, and also protects online and offline password guessing attacks. Furthermore, our scheme efficiently supports the dynamic group password-based authenticated key agreement for the integrated EPR information system. In addition, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool and show that our scheme is secure against passive and active attacks
  • Keywords
    Cryptanalysis , Integrated EPR informationsystem , Dynamic group , Password , Authentication , Security
  • Journal title
    Journal Of King Saud University - Computer an‎d Information Sciences
  • Journal title
    Journal Of King Saud University - Computer an‎d Information Sciences
  • Record number

    2713689