[论文解读] Cryptanalysis of Cryptanalysis and Improvement of Yan et al Biometric-Based Authentication Scheme for TMIS
本文对Dheerendra等人提出的用于远程医疗信息系统的(TMIS)改进生物识别认证方案进行了密码分析,揭示其易受离线身份猜测攻击。作者证明攻击者可在无交互情况下破解用户身份并实施多种密码学攻击,因此提出了一个更安全的增强方案,以提供更强的防护能力应对此类威胁。
Remote user authentication is critical requirement in Telecare Medicine Information System (TMIS) to protect the patient personal details, security and integrity of the critical medical records of the patient as the patient data is transmitted over insecure public communication channel called Internet. In 2013, Yan proposed a biometric based remote user authentication scheme and claimed that his scheme is secure. Recently, Dheerendra et al. demonstrated some drawbacks in Yan et al scheme and proposed an improved scheme to erase the drawbacks of Yan et al scheme. We analyze Dheerendra et al scheme and identify that their scheme is vulnerable to off-line identity guessing attack, and on successfully mounting it, the attacker can perfom all major cryptographic attacks.
研究动机与目标
- 分析Dheerendra等人提出的TMIS改进生物识别认证方案的安全性。
- 识别该方案中损害用户身份机密性的漏洞。
- 证明该方案易受离线身份猜测攻击。
- 提出一种可抵抗此类攻击并提升整体安全性的修订方案。
提出的方法
- 使用标准密码分析技术对Dheerendra等人的方案进行形式化分析。
- 识别出允许攻击者在无交互情况下猜测用户身份的缺陷。
- 构建一种攻击模型,其中攻击者可利用截获的消息离线测试猜测的身份。
- 设计一种修订后的认证协议,以增强对身份猜测及相关密码学威胁的防护能力。
- 使用单向哈希函数和对称密钥操作等密码学原_primitive_,确保相互认证和机密性。
- 进行形式化安全分析,验证其对已知攻击向量(包括离线身份猜测)的抵抗能力。
实验结果
研究问题
- RQ1Dheerendra等人提出的方案是否真正抵御离线身份猜测攻击?
- RQ2攻击者是否仅通过截获的消息和计算资源即可成功恢复用户身份?
- RQ3该方案中哪些具体设计缺陷导致此类攻击成功?
- RQ4如何改进该方案以防止离线身份猜测,同时保持效率?
- RQ5所提出的改进方案是否能抵抗其他标准密码学攻击(如重放或伪装)?
主要发现
- Dheerendra等人提出的方案易受离线身份猜测攻击,攻击者可在无主动交互情况下破坏用户身份。
- 攻击者仅通过截获的消息和计算资源即可成功猜测用户身份。
- 一旦身份被猜中,攻击者可实施多种密码学攻击,包括伪装和会话密钥恢复。
- Yan等人原始方案及其由Dheerendra等人改进的版本均未能充分保护用户身份的机密性。
- 所提出的改进方案通过更强的密码学机制和消息认证,有效抵抗离线身份猜测攻击。
- 分析揭示该工作与先前研究存在显著文本重叠,表明改进方案的创新性有限。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。