首页> 外文期刊>Future generation computer systems >LACO: Lightweight Three-Factor Authentication, Access Control and Ownership Transfer Scheme for E-Health Systems in IoT
【24h】

LACO: Lightweight Three-Factor Authentication, Access Control and Ownership Transfer Scheme for E-Health Systems in IoT

机译:LACO:物联网电子医疗系统的轻量级三要素认证,访问控制和所有权转移方案

获取原文
获取原文并翻译 | 示例

摘要

The use of the Internet of Things (loT) in the electronic health (e-health) management systems brings with it many challenges, including secure communications through insecure radio channels, authentication and key agreement schemes between the entities involved, access control protocols and also schemes for transferring ownership of vital patient information. Besides, the resource-limited sensors in the IoT have real difficulties in achieving this goal. Motivated by these considerations, in this work we propose a new lightweight authentication and ownership transfer protocol for e-health systems in the context of IoT (LACO in short). The goal is to propose a secure and energy-efficient protocol that not only provides authentication and key agreement but also satisfies access control and preserves the privacy of doctors and patients. Moreover, this is the first time that the ownership transfer of users is considered. In the ownership transfer phase of the proposed scheme, the medical server can change the ownership of patient information. In addition, the LACO protocol overcomes the security flaws of recent authentication protocols that were proposed for e-health systems, but are unfortunately vulnerable to traceability, de-synchronization, denial of service (DoS), and insider attacks. To avoid past mistakes, we present formal (i.e., conducted on ProVerif language) and informal security analysis for the LACO protocol. All this ensures that our proposed scheme is secure against the most common attacks in IoT systems. Compared to the predecessor schemes, the LACO protocol is both more efficient and more secure to use in e-health systems. (C) 2019 Elsevier B.V. All rights reserved.
机译:在电子医疗(e-health)管理系统中使用物联网(loT)带来了许多挑战,包括通过不安全的无线电信道进行安全通信,所涉及实体之间的身份验证和密钥协议方案,访问控制协议以及转移重要患者信息所有权的方案。此外,物联网中资源有限的传感器在实现这一目标方面确实存在困难。基于这些考虑,在这项工作中,我们为物联网(简称LACO)的电子医疗系统提出了一种新的轻量级身份验证和所有权转移协议。目标是提出一种安全且节能的协议,该协议不仅提供身份验证和密钥协议,而且还满足访问控制并保护医生和患者的隐私。此外,这是第一次考虑用户的所有权转移。在提出的方案的所有权转移阶段,医疗服务器可以更改患者信息的所有权。此外,LACO协议克服了针对电子医疗系统提出的最新身份验证协议的安全漏洞,但不幸的是,这些协议容易受到可追溯性,去同步,拒绝服务(DoS)和内部攻击的攻击。为避免过去的错误,我们提供了针对LACO协议的正式(即,以ProVerif语言进行)和非正式的安全性分析。所有这些确保了我们提出的方案是安全的,可以抵御物联网系统中最常见的攻击。与以前的方案相比,LACO协议在电子医疗系统中使用更加高效和安全。 (C)2019 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号