Cargando…

An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System

In recent years, with the increase in degenerative diseases and the aging population in advanced countries, demands for medical care of older or solitary people have increased continually in hospitals and healthcare institutions. Applying wireless sensor networks for the IoT-based telemedicine syste...

Descripción completa

Detalles Bibliográficos
Autores principales: Li, Chun-Ta, Wu, Tsu-Yang, Chen, Chin-Ling, Lee, Cheng-Chi, Chen, Chien-Ming
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2017
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5551096/
https://www.ncbi.nlm.nih.gov/pubmed/28644381
http://dx.doi.org/10.3390/s17071482
_version_ 1783256240658317312
author Li, Chun-Ta
Wu, Tsu-Yang
Chen, Chin-Ling
Lee, Cheng-Chi
Chen, Chien-Ming
author_facet Li, Chun-Ta
Wu, Tsu-Yang
Chen, Chin-Ling
Lee, Cheng-Chi
Chen, Chien-Ming
author_sort Li, Chun-Ta
collection PubMed
description In recent years, with the increase in degenerative diseases and the aging population in advanced countries, demands for medical care of older or solitary people have increased continually in hospitals and healthcare institutions. Applying wireless sensor networks for the IoT-based telemedicine system enables doctors, caregivers or families to monitor patients’ physiological conditions at anytime and anyplace according to the acquired information. However, transmitting physiological data through the Internet concerns the personal privacy of patients. Therefore, before users can access medical care services in IoT-based medical care system, they must be authenticated. Typically, user authentication and data encryption are most critical for securing network communications over a public channel between two or more participants. In 2016, Liu and Chung proposed a bilinear pairing-based password authentication scheme for wireless healthcare sensor networks. They claimed their authentication scheme cannot only secure sensor data transmission, but also resist various well-known security attacks. In this paper, we demonstrate that Liu–Chung’s scheme has some security weaknesses, and we further present an improved secure authentication and data encryption scheme for the IoT-based medical care system, which can provide user anonymity and prevent the security threats of replay and password/sensed data disclosure attacks. Moreover, we modify the authentication process to reduce redundancy in protocol design, and the proposed scheme is more efficient in performance compared with previous related schemes. Finally, the proposed scheme is provably secure in the random oracle model under ECDHP.
format Online
Article
Text
id pubmed-5551096
institution National Center for Biotechnology Information
language English
publishDate 2017
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-55510962017-08-11 An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System Li, Chun-Ta Wu, Tsu-Yang Chen, Chin-Ling Lee, Cheng-Chi Chen, Chien-Ming Sensors (Basel) Article In recent years, with the increase in degenerative diseases and the aging population in advanced countries, demands for medical care of older or solitary people have increased continually in hospitals and healthcare institutions. Applying wireless sensor networks for the IoT-based telemedicine system enables doctors, caregivers or families to monitor patients’ physiological conditions at anytime and anyplace according to the acquired information. However, transmitting physiological data through the Internet concerns the personal privacy of patients. Therefore, before users can access medical care services in IoT-based medical care system, they must be authenticated. Typically, user authentication and data encryption are most critical for securing network communications over a public channel between two or more participants. In 2016, Liu and Chung proposed a bilinear pairing-based password authentication scheme for wireless healthcare sensor networks. They claimed their authentication scheme cannot only secure sensor data transmission, but also resist various well-known security attacks. In this paper, we demonstrate that Liu–Chung’s scheme has some security weaknesses, and we further present an improved secure authentication and data encryption scheme for the IoT-based medical care system, which can provide user anonymity and prevent the security threats of replay and password/sensed data disclosure attacks. Moreover, we modify the authentication process to reduce redundancy in protocol design, and the proposed scheme is more efficient in performance compared with previous related schemes. Finally, the proposed scheme is provably secure in the random oracle model under ECDHP. MDPI 2017-06-23 /pmc/articles/PMC5551096/ /pubmed/28644381 http://dx.doi.org/10.3390/s17071482 Text en © 2017 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Li, Chun-Ta
Wu, Tsu-Yang
Chen, Chin-Ling
Lee, Cheng-Chi
Chen, Chien-Ming
An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System
title An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System
title_full An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System
title_fullStr An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System
title_full_unstemmed An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System
title_short An Efficient User Authentication and User Anonymity Scheme with Provably Security for IoT-Based Medical Care System
title_sort efficient user authentication and user anonymity scheme with provably security for iot-based medical care system
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC5551096/
https://www.ncbi.nlm.nih.gov/pubmed/28644381
http://dx.doi.org/10.3390/s17071482
work_keys_str_mv AT lichunta anefficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT wutsuyang anefficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT chenchinling anefficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT leechengchi anefficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT chenchienming anefficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT lichunta efficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT wutsuyang efficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT chenchinling efficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT leechengchi efficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem
AT chenchienming efficientuserauthenticationanduseranonymityschemewithprovablysecurityforiotbasedmedicalcaresystem