Security vulnerability analysis for an improved anonymous authentication protocol for wearable health monitoring system in an aging society

G. Eom, H. Byeon, Y. Choi · Gerontechnology · 2022

Purpose The wearable health monitoring system (WHMS) plays a significant role in medical experts collecting and using patient medical data. The WHMS is becoming more popular than in the past through mobile devices due to meaningful progress in wireless sensor networks. However, because the data about health used by the WHMS is related to privacy, it has to be protected from malicious access when wirelessly transmitted. Jiang et al. proposed a two-factor suitable for WHMSs using a fuzzy verifier. However, Jiaqing Mo et al. revealed that the protocol proposed by Jiang et al. had various security vulnerabilities and proposed an authentication protocol with improved security and guaranteed anonymity for WHMSs. In this paper, we analyse the authentication protocol proposed by Jiaqing Mo et al. and determine problems with the offline identification, password guessing attacks, operation process bit mismatch, no perfect forward secrecy, no mutual authentication and insider attacks. Method This paper analyzed the operation process of Jiang et al.'s protocol and found various vulnerability as off-line ID, PW guessing attack, operation process bit mismatch, no perfect forward secrecy, no mutual authentication and insider attack. According to Jiaqing Mo et al.'s proposed protocol, when an adversary acquires a MD, the adversary can extract information stored in the MD and then find out the user's ID and PW. The information of {Reg_i, A_i, C_i, m, n, h()} is sent to the MD through the GWN security channel. Thereafter, the MD calculates and updates A_i^*=A_ih(ID_ir_i) and D_i=r_ih(h(ID_iPW_i) mod m). Finally, information of {Reg_i, A_i^*, C_i, D_i, m, n, h()} is stored in the MD.

Read the paper · More papers on PaperTik