Mohinder Singh B, Natarajan Jaisankar
School of Computer Science and Engineering, Vellore Institute of Technology, Vellore 632014, India.
J King Saud Univ Comput Inf Sci. 2023 Jun 23:101629. doi: 10.1016/j.jksuci.2023.101629.
In wake of covid19, many countries are shifting their paper-based health record management from manual processes to digital ones. The major benefit of digital health record is that data can be easily shared. As health data is sensitive, more security is to be provided to gain the trust of stakeholders. In this paper, a novel secure authentication protocol is planned for digitalizing personal health record that will be used by the user. While transacting data, a key is used to secure it. Many protocols used elliptic curve cryptography. In this proposed protocol, at an initial stage, an asymmetric and quantum-resistant crypto-algorithm, Kyber is used. In further stages, symmetric crypto-algorithm, Advanced Encryption Standard in Galois/Counter mode (AES-GCM) is used to secure transferred data. For every session, a new key is generated for secure transactions. The more interesting fact in this protocol is that transactions are secured without exchanging actual key and also minimized the key exchange. This protocol not only verified the authenticity of user but also checked rightful citizenship of user. This protocol is analyzed for various security traits using ProVerif tool and provided better results relating to security provisioning, cost of storage, and computation as opposed to related protocols.
在新冠疫情之后,许多国家正在将其基于纸张的健康记录管理从手动流程转变为数字流程。数字健康记录的主要好处是数据可以轻松共享。由于健康数据敏感,需要提供更多安全性以赢得利益相关者的信任。在本文中,计划为用户使用的个人健康记录数字化设计一种新颖的安全认证协议。在处理数据时,使用密钥对其进行保护。许多协议使用椭圆曲线密码学。在这个提议的协议中,在初始阶段,使用一种非对称且抗量子的加密算法Kyber。在后续阶段,使用对称加密算法,即伽罗瓦/计数器模式下的高级加密标准(AES-GCM)来保护传输的数据。对于每个会话,都会生成一个新的密钥用于安全交易。该协议中更有趣的一点是,交易在不交换实际密钥的情况下得到保护,并且还将密钥交换降至最低。该协议不仅验证了用户的真实性,还检查了用户的合法公民身份。使用ProVerif工具对该协议的各种安全特性进行了分析,与相关协议相比,在安全 provisioning、存储成本和计算方面提供了更好的结果。