2019/06/20 by Mahdi Nikooghadam, Nikooghadam, Mahdi, Haleh Amintoosi +1
Computer Science · #Advanced Authentication Protocols Security #Cryptography and Data Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #User Authentication and Security Systems #cs.CR
paper · pdf · doi:10.48550/arxiv.1906.08424
5 pages, 1 table, 1 figure
arxiv created 2019/06/20 · openalex publication_date 2019/06/20 · arxiv updated 2019/06/21 · openalex created_date 2019/06/27 · openalex updated_date 2026/07/28
Telecare medical information systems are gaining rapid popularity in terms of providing the delivery of online health-related services such as online remote health profile access for patients and doctors. Due to being installed entirely on Internet, these systems are exposed to various security and privacy threats. Hence, establishing a secure key agreement and authentication process between the patients and the medical servers is an important challenge. Recently, Khatoon et.al proposed an ECC-based unlink-able authentication and key agreement method for healthcare related application in smart city. In this article, we provide a descriptive analysis on their proposed scheme and prove that Khatoon et al.'s scheme is vulnerable to known-session-specific temporary information attack and is not able to provide perfect forward secrecy.