首页> 外文会议>International Conference on Information Technology in Medicine and Education >FAP_HIS: A Simple Fuzzy-Vault Based Authentication Protocol for RFID-Enabled Healthcare Information System against Unauthorised Tracking
【24h】

FAP_HIS: A Simple Fuzzy-Vault Based Authentication Protocol for RFID-Enabled Healthcare Information System against Unauthorised Tracking

机译:FAP_HIS:基于模糊保险库的简单身份验证协议,用于启用RFID的医疗信息系统,防止未经授权的跟踪

获取原文
获取外文期刊封面目录资料

摘要

With the merits of the radio frequency identification (RFID) technology such as automatic wireless identification without direct eye-sight contact, RFID-enabled healthcare information system can automatically acquire information related to the movement of specific patient or some important medical objects (e.g. blood bag) which is critical to be used for either a possible auxiliary treatment of some disease or an effective measure against improper operations of medical objects out of the eye-sight of the authenticated people. However, since the data within the RFID tags can be easily dumped using a reader of high power, malicious attackers can also track the patients or the objects, acquire the related information, and further infer the sensitive data with data mining techniques, causing the privacy breach of the patients and/or critical medical event if some urgent blood bag were replaced with an invalid one. In this paper we propose a simple fuzzy-vault based authentication protocol which separates the RFID tag ID into two parts using a fuzzy vault technique so that the unauthorized party is unable to infer the true ID simply by tracking the RFID tag. We explored the implementation of the conventional cryptographic construct, fuzzy vault, with the RFID tag data, and the authentication protocol is presented and its effectiveness is proven theoretically.
机译:借助射频识别(RFID)技术的优点,例如无需直接目视接触即可自动进行无线识别,支持RFID的医疗保健信息系统可以自动获取与特定患者或某些重要医疗对象(例如血袋)的运动有关的信息),这对于用于可能的某些疾病的辅助治疗或在经过身份验证的人的视线范围内有效防止医疗对象不当操作的有效措施至关重要。但是,由于可以使用高功率读取器轻松丢弃RFID标签中的数据,恶意攻击者还可以跟踪患者或物体,获取相关信息,并使用数据挖掘技术进一步推断敏感数据,从而导致隐私如果用无效的血液袋代替了一些紧急的血液袋,则违反了患者的要求和/或严重的医疗事件。在本文中,我们提出了一种基于模糊库的简单身份验证协议,该协议使用模糊库技术将RFID标签ID分为两部分,从而使未授权方无法仅通过跟踪RFID标签来推断真实ID。我们用RFID标签数据探索了常规密码结构,模糊保险库的实现,并提出了身份验证协议,并从理论上证明了其有效性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号