首页> 外文会议>International Conference on Contemporary Computing and Informatics >Building secure healthcare services using OAuth 2.0 and JSON web token in IOT cloud scenario
【24h】

Building secure healthcare services using OAuth 2.0 and JSON web token in IOT cloud scenario

机译:在IOT云场景中使用OAuth 2.0和JSON Web令牌构建安全的医疗服务

获取原文

摘要

OAuth 2.0 is a delegated authorization framework enabling secure authorization for applications running on various kinds of platforms. In healthcare services, OAuth allows the patient (resource owner) seeking real time clinical care to authorize automatic monthly payments from his bank account (resource server) without the patient being required to supply his credentials to the clinic (client app). OAuth 2.0 achieves this with the help of tokens issued by an authorization server which enables validated access to a protected resource. To ensure security, access tokens have an expiry time and are short-lived. So the clinical app may use a refresh token to obtain a new access token to cash monthly payments for rendering real time health care services. Refresh tokens need secure storage to ensure they are not leaked, since any malicious party can use them to obtain new access and refresh tokens. Since OAuth 2.0 has dropped signatures and relies completely on SSL/TLS, it is vulnerable to phishing attack when accessing interoperable APIs. In this paper, we develop an approach that combines JSON web token (JWT) with OAuth 2.0 to request an OAuth access token from authorization server when a client wishes to utilize a previous authentication and authorization. Experimental evaluation confirms that the proposed scheme is practically efficient, removes secure storage overhead by removing the need to have or store refresh token, uses signature and prevents different security attacks which is highly desired in health care services using an IOT cloud platform.
机译:OAuth 2.0是一种委托授权框架,可为在各种平台上运行的应用程序提供安全授权。在医疗保健服务中,OAuth允许寻求实时临床护理的患者(资源所有者)从他的银行帐户(资源服务器)授权每月自动付款,而无需患者将其凭据提供给诊所(客户端应用)。 OAuth 2.0在授权服务器发出的令牌的帮助下实现了这一目标,该服务器启用了对受保护资源的验证访问。为了确保安全性,访问令牌有一个有效时间并且是短命的。因此,临床应用可以使用刷新令牌来获取新的访问令牌,以兑现每月付款以提供实时医疗保健服务。刷新令牌需要安全的存储以确保它们不会泄漏,因为任何恶意方都可以使用它们来获取新的访问权限和刷新令牌。由于OAuth 2.0删除了签名并完全依赖SSL / TLS,因此在访问可互操作的API时,它很容易遭受网络钓鱼攻击。在本文中,我们开发了一种方法,该方法将JSON Web令牌(JWT)与OAuth 2.0结合在一起,以在客户端希望使用以前的身份验证和授权时从授权服务器请求OAuth访问令牌。实验评估证实,该方案是切实有效的,通过消除拥有或存储刷新令牌的需要来消除安全的存储开销,使用签名并防止使用物联网云平台的医疗服务中迫切需要的不同安全攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号