@article{ART002757963},
author={Mi-Og Park},
title={Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS},
journal={Journal of The Korea Society of Computer and Information},
issn={1598-849X},
year={2021},
volume={26},
number={9},
pages={89-96},
doi={10.9708/jksci.2021.26.09.089}
TY - JOUR
AU - Mi-Og Park
TI - Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS
JO - Journal of The Korea Society of Computer and Information
PY - 2021
VL - 26
IS - 9
PB - The Korean Society Of Computer And Information
SP - 89
EP - 96
SN - 1598-849X
AB - In this paper, we analyzed that the user authentication scheme for TMIS(Telecare Medicine Information System) proposed by Al-Saggaf et al. In 2019, Al-Saggaf et al. proposed authentication scheme using biometric information, Al-Saggaf et al. claimed that their authentication scheme provides high security against various attacks along with very low computational cost. However in this paper after analyzing Al-Saggaf et al’s authentication scheme, the Al-Saggaf et al’s one are missing random number s from the DB to calculate the identity of the user from the server, and there is a design error in the authentication scheme due to the lack of delivery method. Al-Saggaf et al also claimed that their authentication scheme were safe against a variety of attacks, but were vulnerable to password guessing attack using login request messages and smart cards, session key exposure and insider attack. An attacker could also use a password to decrypt the stored user's biometric information by encrypting the DB with a password. Exposure of biometric information is a very serious breach of the user's privacy, which could allow an attacker to succeed in the user impersonation. Furthermore, Al-Saggaf et al’s authentication schemes are vulnerable to identity guessing attack, which, unlike what they claimed, do not provide significant user anonymity in TMIS.
KW - User authentication;TMIS;Smart-card;Password guessing attack;Biometrics
DO - 10.9708/jksci.2021.26.09.089
ER -
Mi-Og Park. (2021). Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS. Journal of The Korea Society of Computer and Information, 26(9), 89-96.
Mi-Og Park. 2021, "Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS", Journal of The Korea Society of Computer and Information, vol.26, no.9 pp.89-96. Available from: doi:10.9708/jksci.2021.26.09.089
Mi-Og Park "Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS" Journal of The Korea Society of Computer and Information 26.9 pp.89-96 (2021) : 89.
Mi-Og Park. Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS. 2021; 26(9), 89-96. Available from: doi:10.9708/jksci.2021.26.09.089
Mi-Og Park. "Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS" Journal of The Korea Society of Computer and Information 26, no.9 (2021) : 89-96.doi: 10.9708/jksci.2021.26.09.089
Mi-Og Park. Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS. Journal of The Korea Society of Computer and Information, 26(9), 89-96. doi: 10.9708/jksci.2021.26.09.089
Mi-Og Park. Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS. Journal of The Korea Society of Computer and Information. 2021; 26(9) 89-96. doi: 10.9708/jksci.2021.26.09.089
Mi-Og Park. Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS. 2021; 26(9), 89-96. Available from: doi:10.9708/jksci.2021.26.09.089
Mi-Og Park. "Analysis of Al-Saggaf et al’s Three-factor User Authentication Scheme for TMIS" Journal of The Korea Society of Computer and Information 26, no.9 (2021) : 89-96.doi: 10.9708/jksci.2021.26.09.089