Lee Hyang Jin, Kook Sangjin, Kim Keunok, Ryu Jihyeon, Lee Hakjun, Lee Youngsook, Won Dongho
Department of Electrical and Computer Engineering, Sungkyunkwan University, Suwon-si 16419, Republic of Korea.
School of Computer and Information Engineering, Kwangwoon University, Seoul-si 01897, Republic of Korea.
Sensors (Basel). 2025 May 3;25(9):2894. doi: 10.3390/s25092894.
Medical Internet of Things (IoT) systems are crucial in monitoring the health status of patients. Recently, telemedicine services that manage patients remotely by receiving real-time health information from IoT devices attached to or carried by them have experienced significant growth. A primary concern in medical IoT services is ensuring the security of transmitted information and protecting patient privacy. To address these challenges, various authentication schemes have been proposed. We analyze the authentication scheme by Wang et al. and identified several limitations. Specifically, an attacker can exploit information stored in an IoT device to generate an illegitimate session key. Additionally, despite using a cloud center, the scheme lacks efficiency. To overcome these limitations, we propose an authentication and key distribution scheme that incorporates a physically unclonable function (PUF) and public-key computation. To enhance efficiency, computationally intensive public-key operations are performed exclusively in the cloud center. Furthermore, our scheme addresses privacy concerns by employing a temporary ID for IoT devices used to identify patients. We validate the security of our approach using the formal security analysis tool ProVerif.
医疗物联网(IoT)系统在监测患者健康状况方面至关重要。最近,通过从患者身上附着或携带的物联网设备接收实时健康信息来远程管理患者的远程医疗服务有了显著增长。医疗物联网服务中的一个主要问题是确保传输信息的安全性并保护患者隐私。为应对这些挑战,已经提出了各种认证方案。我们分析了Wang等人的认证方案并发现了几个局限性。具体而言,攻击者可以利用存储在物联网设备中的信息生成非法会话密钥。此外,尽管使用了云中心,但该方案缺乏效率。为克服这些局限性,我们提出了一种结合物理不可克隆功能(PUF)和公钥计算的认证和密钥分发方案。为提高效率,计算密集型的公钥操作仅在云中心执行。此外,我们的方案通过为用于识别患者的物联网设备使用临时ID来解决隐私问题。我们使用形式化安全分析工具ProVerif验证了我们方法的安全性。