Department of Information Management, Tainan University of Technology, 529 Zhongzheng Road, Tainan 71002, Taiwan.
Fujian Provincial Key Laboratory of Big Data Mining and Applications, Fujian University of Technology, Fuzhou 350118, China.
Sensors (Basel). 2017 Jun 23;17(7):1482. doi: 10.3390/s17071482.
In recent years, with the increase in degenerative diseases and the aging population in advanced countries, demands for medical care of older or solitary people have increased continually in hospitals and healthcare institutions. Applying wireless sensor networks for the IoT-based telemedicine system enables doctors, caregivers or families to monitor patients' physiological conditions at anytime and anyplace according to the acquired information. However, transmitting physiological data through the Internet concerns the personal privacy of patients. Therefore, before users can access medical care services in IoT-based medical care system, they must be authenticated. Typically, user authentication and data encryption are most critical for securing network communications over a public channel between two or more participants. In 2016, Liu and Chung proposed a bilinear pairing-based password authentication scheme for wireless healthcare sensor networks. They claimed their authentication scheme cannot only secure sensor data transmission, but also resist various well-known security attacks. In this paper, we demonstrate that Liu-Chung's scheme has some security weaknesses, and we further present an improved secure authentication and data encryption scheme for the IoT-based medical care system, which can provide user anonymity and prevent the security threats of replay and password/sensed data disclosure attacks. Moreover, we modify the authentication process to reduce redundancy in protocol design, and the proposed scheme is more efficient in performance compared with previous related schemes. Finally, the proposed scheme is provably secure in the random oracle model under ECDHP.
近年来,随着先进国家退行性疾病和人口老龄化的增加,医院和医疗机构对老年或独居人士的医疗需求不断增加。将无线传感器网络应用于基于物联网的远程医疗系统,使医生、护理人员或家庭成员能够根据所获得的信息随时随地监测患者的生理状况。然而,通过互联网传输生理数据涉及患者的个人隐私。因此,在用户能够访问基于物联网的医疗保健系统中的医疗服务之前,他们必须经过身份验证。通常,用户身份验证和数据加密对于保护两个或多个参与者之间通过公共通道进行的网络通信的安全性至关重要。2016 年,Liu 和 Chung 提出了一种基于双线性配对的无线医疗传感器网络密码身份验证方案。他们声称,他们的认证方案不仅可以确保传感器数据传输的安全性,还可以抵御各种已知的安全攻击。在本文中,我们证明了 Liu-Chung 的方案存在一些安全弱点,我们进一步提出了一种改进的基于物联网的医疗保健系统的安全认证和数据加密方案,该方案可以提供用户匿名性,并防止重播和密码/感测数据泄露攻击的安全威胁。此外,我们修改了认证过程以减少协议设计中的冗余,与以前的相关方案相比,所提出的方案在性能上更加高效。最后,所提出的方案在随机 oracle 模型下基于 ECDHP 是可证明安全的。