Suppr超能文献

用于集成电子病历信息系统的基于简单群组密码的认证密钥协商协议

Simple group password-based authenticated key agreements for the integrated EPR information system.

作者信息

Lee Tian-Fu, Chang I-Pin, Wang Ching-Cheng

机构信息

Department of Medical Informatics, Tzu Chi University, No. 701, Zhongyang Road, Sec. 3, Hualien, 97004, Taiwan, Republic of China,

出版信息

J Med Syst. 2013 Apr;37(2):9916. doi: 10.1007/s10916-012-9916-1. Epub 2013 Jan 19.

Abstract

The security and privacy are important issues for electronic patient records (EPRs). The goal of EPRs is sharing the patients' medical histories such as the diagnosis records, reports and diagnosis image files among hospitals by the Internet. So the security issue for the integrated EPR information system is essential. That is, to ensure the information during transmission through by the Internet is secure and private. The group password-based authenticated key agreement (GPAKE) allows a group of users like doctors, nurses and patients to establish a common session key by using password authentication. Then the group of users can securely communicate by using this session key. Many approaches about GAPKE employ the public key infrastructure (PKI) in order to have higher security. However, it not only increases users' overheads and requires keeping an extra equipment for storing long-term secret keys, but also requires maintaining the public key system. This investigation presents a simple group password-based authenticated key agreement (SGPAKE) protocol for the integrated EPR information system. The proposed SGPAKE protocol does not require using the server or users' public keys. Each user only remembers his weak password shared with a trusted server, and then can obtain a common session key. Then all users can securely communicate by using this session key. The proposed SGPAKE protocol not only provides users with convince, but also has higher security.

摘要

安全和隐私是电子病历(EPR)的重要问题。电子病历的目标是通过互联网在医院之间共享患者的病史,如诊断记录、报告和诊断图像文件。因此,集成电子病历信息系统的安全问题至关重要。也就是说,要确保通过互联网传输期间的信息是安全和私密的。基于群组密码的认证密钥协商(GPAKE)允许一组用户(如医生、护士和患者)通过使用密码认证来建立一个公共会话密钥。然后,该组用户可以使用此会话密钥进行安全通信。许多关于GPAKE的方法采用公钥基础设施(PKI)以获得更高的安全性。然而,它不仅增加了用户的开销,需要保留额外的设备来存储长期秘密密钥,而且还需要维护公钥系统。本研究提出了一种用于集成电子病历信息系统的简单的基于群组密码的认证密钥协商(SGPAKE)协议。所提出的SGPAKE协议不需要使用服务器或用户的公钥。每个用户只需记住与可信服务器共享的弱密码,然后就可以获得一个公共会话密钥。然后,所有用户都可以使用此会话密钥进行安全通信。所提出的SGPAKE协议不仅为用户提供了便利,而且具有更高的安全性。

文献AI研究员

20分钟写一篇综述,助力文献阅读效率提升50倍。

立即体验

用中文搜PubMed

大模型驱动的PubMed中文搜索引擎

马上搜索

文档翻译

学术文献翻译模型,支持多种主流文档格式。

立即体验