Smart Mutual Authentication Protocol for Cloud Based Medical Healthcare Systems Using Internet of Medical Things

被引:92
作者
Deebak, B. D. [1 ]
Al-Turjman, Fadi [2 ]
机构
[1] Vellore Inst Technol, Sch Comp Sci & Engn, Vellore 632014, Tamil Nadu, India
[2] Near East Univ, Res Ctr AI & IoT, Artificial Intelligence Dept, TR-99138 Nicosia, Turkey
关键词
Security protection; telecare medical information system; patient anonymity; mutual authenticity; ACCESS-CONTROL; SCHEME; SECURITY; DESIGN;
D O I
10.1109/JSAC.2020.3020599
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Technological development expands the computation process of smart devices that adopt the telecare medical information system (TMIS) to fulfill the demands of the healthcare organization. It provides better medical identification to claim the features namely trustworthy, efficient, and resourceful. Moreover, the telecare services automate the remote healthcare monitoring process to ease professional workloads. Importantly, it is conceived to be more timesaving, economical, and easy healthcare access. Cloud-Based Medical Healthcare (CBMH) system is a standard platform that gives its support to the patients for emergency treatment from the medical experts over Internet communication. Since the medical records are very sensitive, security protection is much necessitated. In addition, patient anonymity should be well preserved. In 2016, Chiou et al. proposed a mutual authentication protocol for the Telecare Medical Information System (TMIS) using Cloud Environment (CE). They claim that their protocol satisfies patient anonymity. However, this paper proves that the Chiou et al. scheme is not only completely insecure against the patient anonymity, health-report revelation, health-report forgery, report confidentiality, and non-repudiation but also fails to validate the service access against verifiability, undeniability and unforgeability. In order to provide better mutual authenticity, this paper suggests the framework of smart service authentication to cross-examine the common secret session key among the communication entities. In order to examine the security properties, formal and informal verification was carried out. Lastly, to prove the security and performance efficiency of a system, the proposed SSA framework was implemented using FPGA and Moteiv TMote Sky-Mote. A proposed smart service authentication (SSA) framework is presented to ensure better data security between the patients and the physicians. The formal and informal security analysis proves the significance of the SSA framework model to withstand the security attacks such as health-report forgery, health-report revelation, server-spoofing etc. As a result, it is claimed that it can be well suited for TMIS.
引用
收藏
页码:346 / 360
页数:15
相关论文
共 49 条
[1]   LACO: Lightweight Three-Factor Authentication, Access Control and Ownership Transfer Scheme for E-Health Systems in IoT [J].
Aghili, Seyed Farhad ;
Mala, Hamid ;
Shojafar, Mohammad ;
Peris-Lopez, Pedro .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 96 :410-424
[2]   mHealthMon: Toward Energy-Efficient and Distributed Mobile Health Monitoring Using Parallel Offloading [J].
Ahnn, Jong Hoon ;
Potkonjak, Miodrag .
JOURNAL OF MEDICAL SYSTEMS, 2013, 37 (05)
[3]   Seamless Key Agreement Framework for Mobile-Sink in IoT Based Cloud-Centric Secured Public Safety Sensor Networks [J].
Al-Turjman, Fadi ;
Ever, Yoney Kirsal ;
Ever, Enver ;
Nguyen, Huan X. ;
David, Deebak Bakkiam .
IEEE ACCESS, 2017, 5 :24617-24631
[4]   An efficient three factor-based authentication scheme in multiserver environment using ECC [J].
Ali, Rifaqat ;
Pal, Arup Kumar .
INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2018, 31 (04)
[5]  
Altera Inc, FPGA SOC CPLD ALTERA
[6]   Cryptanalysis and Enhancement of Anonymity Preserving Remote User Mutual Authentication and Session Key Agreement Scheme for E-Health Care Systems [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Li, Xiong .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (11)
[7]   Design and Analysis of an Enhanced Patient-Server Mutual Authentication Protocol for Telecare Medical Information System [J].
Amin, Ruhul ;
Islam, S. K. Hafizul ;
Biswas, G. P. ;
Khan, Muhammad Khurram ;
Obaidat, Mohammad S. .
JOURNAL OF MEDICAL SYSTEMS, 2015, 39 (11)
[8]   Design and Analysis of Bilinear Pairing Based Mutual Authentication and Key Agreement Protocol Usable in Multi-server Environment [J].
Amin, Ruhul ;
Biswas, G. P. .
WIRELESS PERSONAL COMMUNICATIONS, 2015, 84 (01) :439-462
[9]  
[Anonymous], CYCLONE 2 ARCHITECTU
[10]   Logic of authentication [J].
Burrows, Michael ;
Abadi, Martin ;
Needham, Roger .
Operating Systems Review (ACM), 1989, 23 (05) :1-13