Lightweight Multi-party Authentication and Key Agreement Protocol in IoT-based E-Healthcare Service

被引:17
作者
Sahu, Amiya Kumar [1 ]
Sharma, Suraj [1 ]
Puthal, Deepak [2 ,3 ]
机构
[1] Int Inst Informat Technol Bhubaneswar, Bhubaneswar 751003, Odisha, India
[2] Newcastle Univ, Newcastle Upon Tyne, Tyne & Wear, England
[3] Urban Sci Bldg,Sci Sq, Newcastle Upon Tyne NE4 5TG, Tyne & Wear, England
关键词
Internet of Things; authentication; healthcare; lightweight; key establishment; security protocol; lattice-based cryptography; identity-based encryption; ESTABLISHMENT; NETWORKS; INTERNET; SCHEME; ROBUST;
D O I
10.1145/3398039
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet of Things (IoT) is playing a promising role in e-healthcare applications in the recent decades; nevertheless, security is one of the crucial challenges in the current field of study. Many healthcare devices (for instance, a sensor-augmented insulin pump and heart-rate sensor) collect a user's real-time data (such as glucose level and heart rate) and send them to the cloud for proper analysis and diagnosis of the user. However, the real-time user's data are vulnerable to various authentication attacks while sending through an insecure channel. Besides that, the attacks may further open scope for many other subsequent attacks. Existing security mechanisms concentrate on two-party mutual authentication. However, an IoT-enabled healthcare application involves multiple parties such as a patient, e-healthcare test-equipment, doctors, and cloud servers that requires multi-party authentication for secure communication. Moreover, the design and implementation of a lightweight security mechanism that fits into the resource constraint IoT-enabled healthcare devices are challenging. Therefore, this article proposes a lightweight, multi-party authentication and key-establishment protocol in IoT-based e-healthcare service access network to counter the attacks in resource constraint devices. The proposed multi-party protocol has used a lattice-based cryptographic construct such as Identity-Based Encryption (IBE) to acquire security, privacy, and efficiency. The study provided all-round analysis of the scheme, such as security, power consumption, and practical usage, in the following ways. The proposed scheme is tested by a formal security tool, Scyther, to testify the security properties of the protocol. In addition, security analysis for various attacks and comparison with other existing works are provided to show the robust security characteristics. Further, an experimental evaluation of the proposed scheme using IBE cryptographic construct is provided to validate the practical usage. The power consumption of the scheme is also computed and compared with existing works to evaluate its efficiency.
引用
收藏
页数:20
相关论文
共 34 条
  • [1] Abdalla M, 2005, LECT NOTES COMPUT SC, V3386, P65
  • [2] Context-aware anonymous authentication protocols in the internet of things dedicated to e-health applications
    Arfaoui, Amel
    Kribeche, Ali
    Senouci, Sidi-Mohammed
    [J]. COMPUTER NETWORKS, 2019, 159 : 23 - 36
  • [3] ON LOVASZ LATTICE REDUCTION AND THE NEAREST LATTICE POINT PROBLEM
    BABAI, L
    [J]. COMBINATORICA, 1986, 6 (01) : 1 - 13
  • [4] Identity-based encryption from the Weil pairing
    Boneh, D
    Franklin, M
    [J]. SIAM JOURNAL ON COMPUTING, 2003, 32 (03) : 586 - 615
  • [5] Canetti R, 2001, LECT NOTES COMPUT SC, V2045, P453
  • [6] Cohen Henri, 1993, ALGORITHMS LINEAR AL, P45, DOI [10.1007/978-3-662-02945-9_2, DOI 10.1007/978-3-662-02945-9_2]
  • [7] Cremers C., 2012, Operational Semantics and Verification of Security Protocols
  • [8] Cremers CJF, 2008, LECT NOTES COMPUT SC, V5123, P414
  • [9] Cremers Sjouke Mauw Cas, 2012, OPERATIONAL SEMANTIC, V1st, DOI [10.1007/978-3-540-78636-8, DOI 10.1007/978-3-540-78636-8]
  • [10] A Hybrid BlockChain-Based Identity Authentication Scheme for Multi-WSN
    Cui, Zhihua
    Xue, Fei
    Zhang, Shiqiang
    Cai, Xingjuan
    Cao, Yang
    Zhang, Wensheng
    Chen, Jinjun
    [J]. IEEE TRANSACTIONS ON SERVICES COMPUTING, 2020, 13 (02) : 241 - 251