PAAF-SHS: PUF and authenticated encryption based authentication framework for the IoT-enabled smart healthcare system

被引:21
作者
Aldosary, Abdallah [1 ]
Tanveer, Muhammad [2 ]
机构
[1] Prince Sattam bin Abdulaziz Univ, Dept Comp Engn, Wadi Addwasir 11991, Ar Riyadh, Saudi Arabia
[2] Univ Management & Technol, Dept Comp Sci, Lahore 54770, Pakistan
关键词
Smart healthcare system; Secure communication; Security; Authentication; Data security; USER AUTHENTICATION; MUTUAL AUTHENTICATION; SCHEME; SECURE; LIGHTWEIGHT; EFFICIENT; PROTOCOL;
D O I
10.1016/j.iot.2024.101159
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Internet of Things (IoT) is increasingly becoming a fundamental component of our everyday existence with the swift advancement in communication technology. Critical infrastructures, smart city monitoring, and smart healthcare systems (SHS) all make significant use of IoT-enabled devices. Nevertheless, the computing power of IoT devices utilized in SHS is constrained. These IoT devices gather sensitive patient data and send it to a medical server. Doctors use IoT-enabled devices to retrieve patient data that has been stored on the medical server using a public communication channel that is susceptible to different types of security attacks. In order to provide information security for IoT-enabled devices with limited resources, the NIST has developed an array of authenticated encryption algorithms. When compared to conventional security techniques, these authenticated encryption algorithms offer computational efficiency. The existing authentication schemes are developed by computationally expensive symmetric and asymmetric encryption schemes and are vulnerable to privileged insider and medical server key compromise attacks. Therefore, this paper introduces a physical unclonable function (PUF) and authenticated encryption (GIFT-COFB)-based authentication framework for IoT-enabled SHS, called PAAF-SHS. PAAF-SHS ensures secure encrypted communication between users and medical servers following mutual authentication. The PUF is incorporated within the medical server and the IoT-enabled device to improve resistance against insider attackers and potential compromises to the medical server key attack. Even in the case of a potential medical server key compromise attack, PAAF-SHS ensures that user-medical server communication remains confidential. The implementation of BAN logic ensures the logical exactitude of PAAF-SHS. Informal security analysis is conducted to validate PAAF-SHS's resilience against impersonation, replay, and denial-of-service attacks. Security validation using Scyther is performed to illustrate the robustness of PAAF-SHS. Finally, performance evaluations demonstrate that the proposed PAAF-SHS achieves a significant reduction in computational and communication costs while enhancing security features.
引用
收藏
页数:19
相关论文
共 51 条
[21]   An efficient and reliable ultralightweight RFID authentication scheme for healthcare systems [J].
Kumar, Anand ;
Singh, Karan ;
Shariq, Mohd ;
Lal, Chhagan ;
Conti, Mauro ;
Amin, Ruhul ;
Chaudhry, Shehzad Ashraf .
COMPUTER COMMUNICATIONS, 2023, 205 :147-157
[22]   A secure authentication scheme based on elliptic curve cryptography for IoT and cloud servers [J].
Kumari, Saru ;
Karuppiah, Marimuthu ;
Das, Ashok Kumar ;
Li, Xiong ;
Wu, Fan ;
Kumar, Neeraj .
JOURNAL OF SUPERCOMPUTING, 2018, 74 (12) :6428-6453
[23]   Secure and Anonymous Authentication Scheme for Mobile Edge Computing Environments [J].
Lee, Hakjun ;
Ryu, Jihyeon ;
Won, Dongho .
IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (04) :5798-5815
[24]   Cryptanalysis and Security Enhancement of Three Authentication Schemes in Wireless Sensor Networks [J].
Li, Wenting ;
Li, Bin ;
Zhao, Yiming ;
Wang, Ping ;
Wei, Fushan .
WIRELESS COMMUNICATIONS & MOBILE COMPUTING, 2018,
[25]   Anonymous mutual authentication and key agreement scheme for wearable sensors in wireless body area networks [J].
Li, Xiong ;
Ibrahim, Maged Hamada ;
Kumari, Saru ;
Sangaiah, Arun Kumar ;
Gupta, Vidushi ;
Choo, Kim-Kwang Raymond .
COMPUTER NETWORKS, 2017, 129 :429-443
[26]   A Secure Anonymous Identity-Based Scheme in New Authentication Architecture for Mobile Edge Computing [J].
Li, Yuting ;
Cheng, Qingfeng ;
Liu, Ximeng ;
Li, Xinghua .
IEEE SYSTEMS JOURNAL, 2021, 15 (01) :935-946
[27]   Secure user authentication scheme for wireless healthcare sensor networks [J].
Liu, Chia-Hui ;
Chung, Yu-Fang .
COMPUTERS & ELECTRICAL ENGINEERING, 2017, 59 :250-261
[28]   An improved user authentication scheme for electronic medical record systems [J].
Madhusudhan, R. ;
Nayak, Chaitanya S. .
MULTIMEDIA TOOLS AND APPLICATIONS, 2020, 79 (29-30) :22007-22026
[29]   A robust authentication scheme for telecare medical information systems [J].
Madhusudhan, R. ;
Nayak, Chaitanya S. .
MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (11) :15255-15273
[30]   Lightweight and Anonymity-Preserving User Authentication Scheme for IoT-Based Healthcare [J].
Masud, Mehedi ;
Gaba, Gurjot Singh ;
Choudhary, Karanjeet ;
Hossain, M. Shamim ;
Alhamid, Mohammed F. ;
Muhammad, Ghulam .
IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (04) :2649-2656