首页> 外文会议>IEEE EMBS International Conference on Biomedical and Health Informatics >Conceptual Design and Analysis of a Mobile Digital Identity for eHealth Applications
【24h】

Conceptual Design and Analysis of a Mobile Digital Identity for eHealth Applications

机译:eHealth应用程序移动数字身份的概念设计与分析

获取原文

摘要

As mobile technology continues to improve, more and more professional services are being offered as mobile apps. This paradigm shift also affects eHealth applications. Digital identities in nation-wide eHealth infrastructures are often realized via smart cards, which however, do not support mobile applications well. In this paper we propose a concept of a mobile eID for eHealth based on smartphones with embedded secure hardware, an mobile authenticator app and an account manager as well as an Identity Provider (IdP) as backend services. The practical applicability of the concept is shown using the example of the German eHealth infrastructure. Our method generates a cryptographic key pair in secure hardware on the user’s smartphone, registers it on the IdP and uses it to authenticate on the IdP. The security of the private key and the integrity of the smartphone is also validated and attestated. The user’s established smartcard-based identity "Electronic Health Card" (EHC) forms the trust anchor. To authenticate against specialist eHealth apps the IdP issues standard-compliant OAuth2.0/OIDC tokens with a limited period of validity. Furthermore, in our security analysis we demonstrate that based on specific security requirements for smartphones and operating systems, at least the eIDAS security level "substantial" related to the technical security aspects of the system can be achieved. On the basis of this research German legislation was adjusted and "digital identities" supplementary to the smartcard-based EHC will be issued from 2023 in the German eHealth infrastructure.
机译:随着移动技术继续提高,越来越多的专业服务作为移动应用程序提供。此范例班次也会影响eHealth应用程序。全国范围内的数字身份经常通过智能卡实现,但是,不支持良好的移动应用程序。在本文中,我们提出了基于智能手机的智能手机,移动验证者应用程序和客户经理以及身份提供程序(IDP)作为后端服务的智能手机的概念。使用德国电子健康基础设施的示例显示了该概念的实际适用性。我们的方法在用户智能手机上的安全硬件中生成一个加密密钥对,将其注册到IDP上并将其使用它在IDP上进行身份验证。还验证并证明了私钥的安全性和智能手机的完整性。用户建立的基于智能卡的身份“电子保健卡”(EHC)形成了信任锚。验证专家电子医疗应用程序,IDP发出标准符合标准的OAuth2.0 / OIDC令牌,有限的有效期。此外,在我们的安全分析中,我们证明基于智能手机和操作系统的特定安全要求,至少可以实现与系统的技术安全方面相关的外销安全级别“实质性”。在本研究的基础上,调整了德国立法,并将在德国电子保健基础设施的2023年向基于智能卡的EHC补充的“数字身份”。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号