• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

用于集成电子病历信息系统的基于简单群组密码的认证密钥协商协议

Simple group password-based authenticated key agreements for the integrated EPR information system.

作者信息

Lee Tian-Fu, Chang I-Pin, Wang Ching-Cheng

机构信息

Department of Medical Informatics, Tzu Chi University, No. 701, Zhongyang Road, Sec. 3, Hualien, 97004, Taiwan, Republic of China,

出版信息

J Med Syst. 2013 Apr;37(2):9916. doi: 10.1007/s10916-012-9916-1. Epub 2013 Jan 19.

DOI:10.1007/s10916-012-9916-1
PMID:23328913
Abstract

The security and privacy are important issues for electronic patient records (EPRs). The goal of EPRs is sharing the patients' medical histories such as the diagnosis records, reports and diagnosis image files among hospitals by the Internet. So the security issue for the integrated EPR information system is essential. That is, to ensure the information during transmission through by the Internet is secure and private. The group password-based authenticated key agreement (GPAKE) allows a group of users like doctors, nurses and patients to establish a common session key by using password authentication. Then the group of users can securely communicate by using this session key. Many approaches about GAPKE employ the public key infrastructure (PKI) in order to have higher security. However, it not only increases users' overheads and requires keeping an extra equipment for storing long-term secret keys, but also requires maintaining the public key system. This investigation presents a simple group password-based authenticated key agreement (SGPAKE) protocol for the integrated EPR information system. The proposed SGPAKE protocol does not require using the server or users' public keys. Each user only remembers his weak password shared with a trusted server, and then can obtain a common session key. Then all users can securely communicate by using this session key. The proposed SGPAKE protocol not only provides users with convince, but also has higher security.

摘要

安全和隐私是电子病历(EPR)的重要问题。电子病历的目标是通过互联网在医院之间共享患者的病史,如诊断记录、报告和诊断图像文件。因此,集成电子病历信息系统的安全问题至关重要。也就是说,要确保通过互联网传输期间的信息是安全和私密的。基于群组密码的认证密钥协商(GPAKE)允许一组用户(如医生、护士和患者)通过使用密码认证来建立一个公共会话密钥。然后,该组用户可以使用此会话密钥进行安全通信。许多关于GPAKE的方法采用公钥基础设施(PKI)以获得更高的安全性。然而,它不仅增加了用户的开销,需要保留额外的设备来存储长期秘密密钥,而且还需要维护公钥系统。本研究提出了一种用于集成电子病历信息系统的简单的基于群组密码的认证密钥协商(SGPAKE)协议。所提出的SGPAKE协议不需要使用服务器或用户的公钥。每个用户只需记住与可信服务器共享的弱密码,然后就可以获得一个公共会话密钥。然后,所有用户都可以使用此会话密钥进行安全通信。所提出的SGPAKE协议不仅为用户提供了便利,而且具有更高的安全性。

相似文献

1
Simple group password-based authenticated key agreements for the integrated EPR information system.用于集成电子病历信息系统的基于简单群组密码的认证密钥协商协议
J Med Syst. 2013 Apr;37(2):9916. doi: 10.1007/s10916-012-9916-1. Epub 2013 Jan 19.
2
An Improved and Secure Anonymous Biometric-Based User Authentication with Key Agreement Scheme for the Integrated EPR Information System.一种用于集成电子病历信息系统的、具有密钥协商方案的改进型安全匿名生物特征用户认证方法。
PLoS One. 2017 Jan 3;12(1):e0169414. doi: 10.1371/journal.pone.0169414. eCollection 2017.
3
A secure and efficient password-based user authentication scheme using smart cards for the integrated EPR information system.一种用于集成电子病历信息系统的、基于智能卡的安全高效的基于密码的用户认证方案。
J Med Syst. 2013 Jun;37(3):9941. doi: 10.1007/s10916-013-9941-8. Epub 2013 Apr 4.
4
Secure verifier-based three-party authentication schemes without server public keys for data exchange in telecare medicine information systems.用于远程医疗信息系统中数据交换的、无需服务器公钥的基于安全验证器的三方认证方案。
J Med Syst. 2014 May;38(5):30. doi: 10.1007/s10916-014-0030-4. Epub 2014 Apr 8.
5
A secure and robust password-based remote user authentication scheme using smart cards for the integrated EPR information system.一种用于集成电子病历信息系统的、基于智能卡的安全且稳健的基于密码的远程用户认证方案。
J Med Syst. 2015 Mar;39(3):25. doi: 10.1007/s10916-015-0204-8. Epub 2015 Feb 10.
6
Anonymous three-party password-authenticated key exchange scheme for Telecare Medical Information Systems.用于远程医疗信息系统的匿名三方密码认证密钥交换方案。
PLoS One. 2014 Jul 21;9(7):e102747. doi: 10.1371/journal.pone.0102747. eCollection 2014.
7
Three-party authenticated key agreements for optimal communication.用于优化通信的三方认证密钥协商
PLoS One. 2017 Mar 29;12(3):e0174473. doi: 10.1371/journal.pone.0174473. eCollection 2017.
8
A privacy preserving secure and efficient authentication scheme for telecare medical information systems.一种用于远程医疗信息系统的隐私保护安全高效认证方案。
J Med Syst. 2015 May;39(5):54. doi: 10.1007/s10916-015-0215-5. Epub 2015 Mar 8.
9
Performance analysis: Securing SIP on multi-threaded/multi-core proxy server using public keys on Diffie-Hellman (DH) in single and multi-server queuing scenarios.性能分析:在单服务器和多服务器排队场景中,使用Diffie-Hellman(DH)公钥在多线程/多核代理服务器上保护SIP安全。
PLoS One. 2024 Jan 25;19(1):e0293626. doi: 10.1371/journal.pone.0293626. eCollection 2024.
10
A password-based user authentication scheme for the integrated EPR information system.基于密码的综合电子病历信息系统用户认证方案。
J Med Syst. 2012 Apr;36(2):631-8. doi: 10.1007/s10916-010-9527-7. Epub 2010 May 27.

引用本文的文献

1
A Round-Efficient Authenticated Key Agreement Scheme Based on Extended Chaotic Maps for Group Cloud Meeting.一种基于扩展混沌映射的用于群组云会议的高效轮次认证密钥协商方案。
Sensors (Basel). 2017 Dec 3;17(12):2793. doi: 10.3390/s17122793.

本文引用的文献

1
A more secure authentication scheme for telecare medicine information systems.远程医疗保健信息系统的更安全认证方案。
J Med Syst. 2012 Jun;36(3):1989-95. doi: 10.1007/s10916-011-9658-5. Epub 2011 Mar 1.
2
A secure authentication scheme for telecare medicine information systems.远程医疗保健信息系统的安全认证方案。
J Med Syst. 2012 Jun;36(3):1529-35. doi: 10.1007/s10916-010-9614-9. Epub 2010 Oct 27.
3
A study on agent-based secure scheme for electronic medical record system.基于代理的电子病历系统安全方案研究。
J Med Syst. 2012 Jun;36(3):1345-57. doi: 10.1007/s10916-010-9595-8. Epub 2010 Sep 21.
4
A password-based user authentication scheme for the integrated EPR information system.基于密码的综合电子病历信息系统用户认证方案。
J Med Syst. 2012 Apr;36(2):631-8. doi: 10.1007/s10916-010-9527-7. Epub 2010 May 27.
5
A cryptographic key management solution for HIPAA privacy/security regulations.一种符合《健康保险流通与责任法案》(HIPAA)隐私/安全法规的加密密钥管理解决方案。
IEEE Trans Inf Technol Biomed. 2008 Jan;12(1):34-41. doi: 10.1109/TITB.2007.906101.
6
Data security and protection in cross-institutional electronic patient records.跨机构电子病历中的数据安全与保护
Int J Med Inform. 2003 Jul;70(2-3):117-30. doi: 10.1016/s1386-5056(03)00033-9.