摘要

Telecare medicine information system (TMIS) is widely used for providing a convenient and efficient communicating platform between patients at home and physicians at medical centers or home health care (HHC) organizations. To ensure patient privacy, in 2013, Hao et al. proposed a chaotic map based authentication scheme with user anonymity for TMIS. Later, Lee showed that Hao et al.%26apos;s scheme is in no provision for providing fairness in session key establishment and gave an efficient user authentication and key agreement scheme using smart cards, in which only few hashing and Chebyshev chaotic map operations are required. In addition, Jiang et al. discussed that Hao et al.%26apos;s scheme can not resist stolen smart card attack and they further presented an improved scheme which attempts to repair the security pitfalls found in Hao et al.%26apos;s scheme. In this paper, we found that both Lee%26apos;s and Jiang et al.%26apos;s authentication schemes have a serious security problem in that a registered user%26apos;s secret parameters may be intentionally exposed to many non-registered users and this problem causing the service misuse attack. Therefore, we propose a slight modification on Lee%26apos;s scheme to prevent the shortcomings. Compared with previous schemes, our improved scheme not only inherits the advantages of Lee%26apos;s and Jiang et al.%26apos;s authentication schemes for TMIS but also remedies the serious security weakness of not being able to withstand service misuse attack.