Lightweight Collaborative Authentication With Key Protection for Smart Electronic Health Record System

Lightweight Collaborative Authentication With Key Protection for Smart Electronic Health Record System
复制标题

智能电子健康记录系统的轻量级协同认证与密钥保护

DOI:
10.1109/jsen.2019.2949717
复制
发表时间:
2020-02-15
影响因子:
4.3
通讯作者:
Choo, Kim-Kwang Raymond
Choo, Kim-Kwang Raymond
中科院分区:
综合性期刊2区
文献类型:
--
作者:
Feng, Qi;He, Debiao;Choo, Kim-Kwang Raymond

文献摘要

被引文献

相似文献

当无线体域网络(WBAN)在现代医疗系统中发挥越来越大的作用时,智能电子健康记录(SEHR)系统被认为是一种经济而有效的方式,可以优化通过互联的分层网络的个人信息或电子健康记录(EHR)。从个人智能医疗传感器收集的大规模、多样性和高灵敏度的电子病历数据具有很强的安全性和隐私保护能力。作为一种能够有效识别接入实体合法性的认证协议,已经提出了多种针对SEHR系统的认证方法。然而,它们很少适合需要双方生成认证消息的情况,例如医生在访问EHR时需要从患者那里获得认证。使用秘密共享方案的一个限制是要求可信第三方恢复原始私钥。因此,我们针对两个参与者(即没有可信多数)的具体情况,提出了一种适用于SEHR系统的协同认证协议。我们的协议在困难问题假设下是可证明安全的,满足所有的安全要求,尤其是私钥保护。此外,与现有的依赖于重同态加密和零知识证明的安全两方认证协议相比,我们提出的协议的性能分析表明,我们提出的协议比以前的协议快得多。
When wireless body area network (WBAN) is playing an increasing role in modern medical systems, smart electronic health record (SEHR) system is heralded primarily as an economical and efficient way to optimize personal information or electronic health records (EHR) flowing through the inter-connected hierarchical network. Large scale, diversity and high sensitivity on EHR data collected from the personal intelligent medical sensors intrigue strong security and privacy preservation. As an authentication protocol can effectively identify the legality of the access entities, many authentication approaches for SEHR system have been proposed. However, few of them are suitable for such situation where an authentication message need to be generated by two parties, for example, doctors need to gain authenticaion from patients when accessing to EHRs. A limitation of using secret sharing scheme is the requirement of a trusted third party to recover the original private key. Therefore, we focus on the specific case of two participants (i.e., no trusted majority) and present a collaborative authentication protocol for SEHR system. Our protocol is provable secure under the hard problem assumptions and meets all the security requirements, especially private key protection. Furthermore, contract to an existing secure two-party authentication protocol that relies on heavy homomorphic encryptions and zero-knowledge proofs, our proposed protocol is tremendously faster than the previous ones shown by the performance analysis.