An improved and effective secure password-based authentication and key agreement scheme using smart cards for the telecare medicine information system

J Med Syst. 2013 Oct;37(5):9969. doi: 10.1007/s10916-013-9969-9. Epub 2013 Sep 6.

Abstract

Recently Lee and Liu proposed an efficient password based authentication and key agreement scheme using smart card for the telecare medicine information system [J. Med. Syst. (2013) 37:9933]. In this paper, we show that though their scheme is efficient, their scheme still has two security weaknesses such as (1) it has design flaws in authentication phase and (2) it has design flaws in password change phase. In order to withstand these flaws found in Lee-Liu's scheme, we propose an improvement of their scheme. Our improved scheme keeps also the original merits of Lee-Liu's scheme. We show that our scheme is efficient as compared to Lee-Liu's scheme. Further, through the security analysis, we show that our scheme is secure against possible known attacks. In addition, we simulate our scheme for the formal security verification using the widely-accepted AVISPA (Automated Validation of Internet Security Protocols and Applications) tool to show that our scheme is secure against passive and active attacks.

MeSH terms

  • Computer Security*
  • Confidentiality*
  • Health Smart Cards
  • Information Systems
  • Telemedicine