본문 바로가기
  • Home

Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS

  • Journal of The Korea Society of Computer and Information
  • Abbr : JKSCI
  • 2021, 26(9), pp.89~96
  • DOI : 10.9708/jksci.2021.26.09.089
  • Publisher : The Korean Society Of Computer And Information
  • Research Area : Engineering > Computer Science
  • Received : August 10, 2021
  • Accepted : August 31, 2021
  • Published : September 30, 2021

Mi Og Park 1

1성결대학교

Accredited

ABSTRACT

In this paper, we analyzed that the user authentication scheme for TMIS(Telecare Medicine Information System) proposed by Al-Saggaf et al. In 2019, Al-Saggaf et al. proposed authentication scheme using biometric information, Al-Saggaf et al. claimed that their authentication scheme provides high security against various attacks along with very low computational cost. However in this paper after analyzing Al-Saggaf et al’s authentication scheme, the Al-Saggaf et al’s one are missing random number s from the DB to calculate the identity of the user from the server, and there is a design error in the authentication scheme due to the lack of delivery method. Al-Saggaf et al also claimed that their authentication scheme were safe against a variety of attacks, but were vulnerable to password guessing attack using login request messages and smart cards, session key exposure and insider attack. An attacker could also use a password to decrypt the stored user's biometric information by encrypting the DB with a password. Exposure of biometric information is a very serious breach of the user's privacy, which could allow an attacker to succeed in the user impersonation. Furthermore, Al-Saggaf et al’s authentication schemes are vulnerable to identity guessing attack, which, unlike what they claimed, do not provide significant user anonymity in TMIS.

Journal Copyright Policy

No CCL information provided

Citation status

* References for papers published after 2025 are currently being built.