首页> 外文期刊>Computer networks >SHAPARAK: Scalable healthcare authentication protocol with attack-resilience and anonymous key-agreement
【24h】

SHAPARAK: Scalable healthcare authentication protocol with attack-resilience and anonymous key-agreement

机译:Shaparak:可扩展的医疗保健身份验证协议,具有攻击 - 弹性和匿名键协议

获取原文
获取原文并翻译 | 示例

摘要

Security in wearable sensor networks and telecare medical information systems (TMIS) has turned to an issue of scholarly interest in recent years. Adequate security to agree on a temporary session key is essential for establishing a secure connection on various layers of the protocol stack in the Internet of Things (IoT) environments. Recently, Gupta et al. proposed a lightweight authentication and key agreement scheme for wearable sensing devices. Our analysis of Gupta et al.'s scheme revealed that it is insecure against privileged-insider attack, compromise sensing device, and desynchronization attacks in wearable sensor registration and login and authentication phases. In this paper, a Scalable Healthcare Authentication Protocol with Attack-Resilience and Anonymous Key-agreement, SHAPARAK, is proposed to overcome security flaws of existing schemes. The proposed protocol offers more scalability as it uses a public channel in the process of registration of each wearable sensing device. It also contains the password and biometrics changing phase without involvement of the trusted server. The security analysis of the proposed scheme is evaluated using the GNY logic, AVISPA tool, random oracle model, and informal security analysis. It is also shown that the proposed protocol is cost-efficient in terms of computation and communication overheads, compared to the existing schemes.
机译:可穿戴传感器网络和远程护理医疗信息系统(TMIS)的安全性近年来转向了学术兴趣的问题。足够的安全性以达到临时会话密钥的达成一致对于在“内容”(IOT)环境中在协议栈的各个层上建立安全连接至关重要。最近,Gupta等人。提出了一种可穿戴式传感设备的轻量级认证和关键协议方案。我们对Gupta等人的分析。的计划显示,它不安全地防止穿着传感器注册和登录和认证阶段的特权 - 内幕攻击,妥协感测装置和去同步攻击。本文提出了一种具有攻击 - 弹性和匿名密钥协议的可扩展医疗保健认证协议,Shaparak,以克服现有方案的安全漏洞。所提出的协议提供了更多可扩展性,因为它在每个可穿戴传感设备的登记过程中使用公共信道。它还包含未经可信服务器参与的密码和生物识别阶段。使用GNY逻辑,AVISPA工具,随机oracle模型和非正式安全分析评估所提出的方案的安全分析。还示出了与现有方案相比,所提出的协议在计算和通信开销方面具有成本效益。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号