  • 學位論文


A secure authentication scheme for telecare medicine information systems

指導教授 : 賴飛羆


本論文發表一個可以適用於遠距照護醫療資訊系統上遠端病患使用者與系統主機之間的安全認證機制,其主體是以密碼為基礎,再搭配智慧卡或使用者端本身的儲存設備去做認證,和一般密碼認證機制最大的不同,是多了一個「預先運算」的步驟,進而可以在較低的運算資源上,達到和其他密碼認證機制相同甚至更高的安全等級。 一般的安全認證機制若要達到較好的安全等級,多半會使用指數運算、雜湊函數去設計機制,而這篇論文也同樣是使用指數運算和雜湊函數,但是使用了「預先運算」的方法去避免掉指數運算對系統資源的高要求,因此可以在低系統資源上達到和其他高系統資源同樣的安全等級,對於遠距照護的設備而言,因為強調其設備的可攜性,因此多用PDA等行動裝置搭配使用,故本篇論文設計出的機制可以符合其運算資源限制上的需求。


We propose a secure authentication scheme between users and the server in telecare medicine information system. In mobile telecare medicine information system, because of lower computation mobile devices, user authentication has been addressed efficiently. The major difference between our scheme and other schemes is the pre-computing phase. Obviously, our scheme is based on the hash function and discrete logarithms problem, so it has the same security level as other schemes. But we use the pre-computing phase to avoid the high cost of exponential operation. Therefore, it is very suitable for low computation mobile devices in telecare medicine information system, such as PDA.


[7]J. L. Tsai, “Efficient Nonce-based Authentication Scheme for Session Initiation Protocol”, International Journal of Network Security, Vol.9(16), No.1, PP.12, 2009
[12]E. Liao, C. C. Lee, and M. S. Hwang, “A password authentication scheme over insecure networks,” Journal of Computer and System Sciences, vol. 72, no. 4, pp. 727-740, 2006.
[1]E.J. Yoon, W.H. Kim, K.Y. Yoo, “Robust and simple authentication protocol for secure communication on the web”, in: ICWE 2005, Lecture Notes in Computer Science, vol. 3579, Springer-Verlag, 2005, pp. 352–362.
[2]C.L. Lin, T. Hwang, “A password authentication scheme with secure password updating”, Computers and Security 22 (1) (2003) 68–72.
[4]C. C. Yang, R. C. Wang, and W. T. Liu, “Secure authentication scheme for session initiation protocol," Computers and Security, vol. 24, pp. 381-386, 2005.
