Privacy-Preserving Fast Three-Factor Authentication and Key Agreement for IoT-Based E-Health Systems

被引:32
作者
Zhang, Liping [1 ]
Zhu, Yue [1 ]
Ren, Wei [1 ,2 ,3 ]
Zhang, Yixin [1 ]
Choo, Kim-Kwang Raymond [4 ]
机构
[1] China Univ Geosci, Sch Comp Sci, Wuhan 430074, Peoples R China
[2] Yunnan Key Lab Blockchain Applicat Technol, Kunming 650500, Peoples R China
[3] Henan Key Lab Network Cryptog Technol, Zhengzhou 450001, Peoples R China
[4] Univ Texas San Antonio, Dept Informat Syst & Cyber Secur, San Antonio, TX 78249 USA
基金
中国国家自然科学基金;
关键词
Authentication; Biometrics (access control); Security; Passwords; Medical services; Cryptography; Smart cards; Electronic healthcare system; authenticated key agreement; biometric template; privacy protection; LIGHTWEIGHT; NETWORKS; PROTOCOL; SCHEME; EXCHANGE; SECURE;
D O I
10.1109/TSC.2022.3149940
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Electronic healthcare (e-health) systems have received renewed interest, particularly in the current COVID-19 pandemic (e.g., lockdowns and changes in hospital policies due to the pandemic). However, ensuring security of both data-at-rest and data-in-transit remains challenging to achieve, particularly since data is collected and sent from less insecure devices (e.g., patients' wearable or home devices). While there have been a number of authentication schemes, such as those based on three-factor authentication, to provide authentication and privacy protection, a number of limitations associated with these schemes remain (e.g., (in)security or computationally expensive). In this study, we present a privacy-preserving three-factor authenticated key agreement scheme that is sufficiently lightweight for resource-constrained e-health systems. The proposed scheme enables both mutual authentication and session key negotiation in addition to privacy protection, with minimal computational cost. The security of the proposed scheme is demonstrated in the Real-or-Random model. Experiments using Raspberry Pi show that the proposed scheme achieves reduced computational cost (of up to 89.9% in comparison to three other related schemes).
引用
收藏
页码:1324 / 1333
页数:10
相关论文
共 27 条
[1]  
Abdalla M, 2005, LECT NOTES COMPUT SC, V3386, P65
[2]   Walsh-Hadamard-Based 3-D Steganography for Protecting Sensitive Information in Point-of-Care [J].
Abuadbba, Alsharif ;
Khalil, Ibrahim .
IEEE TRANSACTIONS ON BIOMEDICAL ENGINEERING, 2017, 64 (09) :2186-2195
[3]   LACO: Lightweight Three-Factor Authentication, Access Control and Ownership Transfer Scheme for E-Health Systems in IoT [J].
Aghili, Seyed Farhad ;
Mala, Hamid ;
Shojafar, Mohammad ;
Peris-Lopez, Pedro .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 96 :410-424
[4]   A Lightweight and Secure Anonymity Preserving Protocol for WBAN [J].
Almuhaideb, Abdullah M. ;
Alqudaihi, Kawther S. .
IEEE ACCESS, 2020, 8 :178183-178194
[5]   A robust and anonymous patient monitoring system using wireless medical sensor networks [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Kumar, Neeraj .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2018, 80 :483-495
[6]   Design of an anonymity-preserving three-factor authenticated key exchange protocol for wireless sensor networks [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Leng, Lu ;
Kumar, Neeraj .
COMPUTER NETWORKS, 2016, 101 :42-62
[7]  
Bellare M, 2000, LECT NOTES COMPUT SC, V1807, P139
[8]   An Improved Authentication Protocol for Wireless Body Sensor Networks Applied in Healthcare Applications [J].
Chatterjee, Kakali .
WIRELESS PERSONAL COMMUNICATIONS, 2020, 111 (04) :2605-2623
[10]   A provably secure and efficient anonymous mutual authentication and key agreement protocol for wearable devices in WBAN [J].
Gupta, Ankur ;
Tripathi, Meenakshi ;
Sharma, Aakar .
COMPUTER COMMUNICATIONS, 2020, 160 :311-325