Wireless medical sensor networks (WMSNs) are playing an increasingly important role in smart healthcare applications. Since the data transmitted in WMSNs is closely related to patient's life and health, and considering the resource-constrain feature of the sensor node, constructing an authentication scheme for WMSNs is a formidable task. Recently, Soni et al. presented an elliptic curve cryptosystem based three-factor authentication scheme for WMSNs. However, we discover that their scheme suffers from serious vulnerabilities, such as sensor node capture attack, no forward secrecy, and the violation of threefactor security. To enhance the security and efficiency, we present a novel scheme using Rabin cryptosystem and chaotic maps. We use several widely-accepted security analysis methods to verify the correctness and security of our scheme. The Burrows-Abadi-Needham logic proof confirms the completeness of our scheme. The heuristic analysis indicates that our scheme is resistant to potential attacks and provides various security attributes like forward secrecy and three-factor security. Furthermore, we demonstrate that our scheme is provably secure in the random oracle model. Finally, the performance comparisons indicate that our scheme is superior to the related schemes both in security and efficiency and is more applicable to WMSNs owing to low overhead of the sensor node.
Nowadays, remote user authentication protocol plays a great role in ensuring the security of data transmission and protecting the privacy of users for various network services. In this study, we discover two recently introduced anonymous authentication schemes are not as secure as they claimed, by demonstrating they suffer from offline password guessing attack, desynchronization attack, session key disclosure attack, failure to achieve user anonymity, or forward secrecy. Besides, we reveal two environment-specific authentication schemes have weaknesses like impersonation attack. To eliminate the security vulnerabilities of existing schemes, we propose an improved authentication scheme based on elliptic curve cryptosystem. We use BAN logic and heuristic analysis to prove our scheme provides perfect security attributes and is resistant to known attacks. In addition, the security and performance comparison show that our scheme is superior with better security and low computation and communication cost.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.