Related Experiment Video
Updated: May 10, 2026

TBase - an Integrated Electronic Health Record and Research Database for Kidney Transplant Recipients
Published on: April 13, 2021
An authentication scheme for secure access to healthcare services
Muhammad Khurram Khan1, Saru Kumari
1King Saud University, PO Box 92144, Riyadh, 11653, Kingdom of Saudi Arabia, khurram.khan@scientist.com.
Existing telecare medical information system (TMIS) authentication schemes by Wei et al. and Zhu have security flaws. We propose a new, more secure TMIS authentication scheme with forward secrecy.
Area of Science:
- Health Informatics
- Cybersecurity
- Computer Science
Background:
- Information and communication technologies have advanced significantly, benefiting the healthcare sector.
- User authentication is crucial for secure access to healthcare services, particularly in telecare medical information systems (TMIS).
- Previous authentication schemes for TMIS, such as Wei et al.'s (2012) and Zhu's improvement, have been proposed but contain vulnerabilities.
Purpose of the Study:
- To analyze the security effectiveness of existing user authentication schemes for TMIS.
- To identify and highlight the specific security weaknesses in Wei et al.'s and Zhu's schemes.
- To propose a novel, enhanced authentication scheme for TMIS that addresses identified vulnerabilities and offers improved security features.
Main Methods:
- Critical analysis of Wei et al.'s and Zhu's proposed user authentication schemes for TMIS.
- Identification of security flaws including undetectable online password guessing attacks, password change phase inefficacy, smart card traceability, denial-of-service threats, lack of forward secrecy, and absence of session keys.
- Development and proposal of a new authentication scheme incorporating forward secrecy and enhanced security measures.
Main Results:
- Both Wei et al.'s and Zhu's schemes were found to be ineffective for secure user authentication in TMIS.
- Identified persistent security issues across both schemes, including susceptibility to various attacks and functional deficiencies.
- The proposed scheme demonstrates enhanced security, including forward secrecy, preserving data confidentiality even if the server's master secret key is compromised.
Conclusions:
- Wei et al.'s and Zhu's authentication schemes for TMIS are inadequate due to significant security vulnerabilities.
- The newly proposed authentication scheme offers superior security and retains the advantages of previous schemes.
- The enhanced scheme is better suited for TMIS, ensuring robust user authentication and data protection.
Related Concept Videos
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Legal Guidelines for Documentation
Integrated Healthcare System
Health Information Technology and Healthcare Information System
Health Information Technology, commonly called HIT, integrates advanced information systems and technology in healthcare settings. Its primary functions include:
Standards of Care II
Secondary Healthcare System
