Cargando…

A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems

Heterogeneous mobile authentication is a crucial technique to securely retrieve the resource of e-healthcare cloud servers which are commonly implemented in a public key Infrastructure (PKI). Conventionally, a mobile data user can utilize a self-chosen password along with a portable device to reques...

Descripción completa

Detalles Bibliográficos
Autor principal: Lin, Han-Yu
Formato: Online Artículo Texto
Lenguaje:English
Publicado: Public Library of Science 2018
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6291128/
https://www.ncbi.nlm.nih.gov/pubmed/30540838
http://dx.doi.org/10.1371/journal.pone.0208397
_version_ 1783380209175625728
author Lin, Han-Yu
author_facet Lin, Han-Yu
author_sort Lin, Han-Yu
collection PubMed
description Heterogeneous mobile authentication is a crucial technique to securely retrieve the resource of e-healthcare cloud servers which are commonly implemented in a public key Infrastructure (PKI). Conventionally, a mobile data user can utilize a self-chosen password along with a portable device to request the access privilege of clouds. However, to validate the membership of users, a cloud server usually has to make use of a password table, which not only increases the burden of management, but also raises the possibility of information leakage. In this paper, we propose a secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems. In our system structure, an e-healthcare cloud server of traditional PKIs does not have to store a password table. A legitimate data user only possesses a security token hardware and keeps an offline updatable password without using any private key. Our scheme is classified into the category of dynamic ID authentication techniques, since a data user is able to preserve his/her anonymity during authentication processes. We formally prove that the proposed mechanism fulfills the essential authenticated key exchange (AKE) security and owns lower computational costs. To further ensure the practical application security, an automatic security validation tool called AVISPA is also adopted to analyze possible attacks and pitfalls of our designed protocol.
format Online
Article
Text
id pubmed-6291128
institution National Center for Biotechnology Information
language English
publishDate 2018
publisher Public Library of Science
record_format MEDLINE/PubMed
spelling pubmed-62911282018-12-28 A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems Lin, Han-Yu PLoS One Research Article Heterogeneous mobile authentication is a crucial technique to securely retrieve the resource of e-healthcare cloud servers which are commonly implemented in a public key Infrastructure (PKI). Conventionally, a mobile data user can utilize a self-chosen password along with a portable device to request the access privilege of clouds. However, to validate the membership of users, a cloud server usually has to make use of a password table, which not only increases the burden of management, but also raises the possibility of information leakage. In this paper, we propose a secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems. In our system structure, an e-healthcare cloud server of traditional PKIs does not have to store a password table. A legitimate data user only possesses a security token hardware and keeps an offline updatable password without using any private key. Our scheme is classified into the category of dynamic ID authentication techniques, since a data user is able to preserve his/her anonymity during authentication processes. We formally prove that the proposed mechanism fulfills the essential authenticated key exchange (AKE) security and owns lower computational costs. To further ensure the practical application security, an automatic security validation tool called AVISPA is also adopted to analyze possible attacks and pitfalls of our designed protocol. Public Library of Science 2018-12-12 /pmc/articles/PMC6291128/ /pubmed/30540838 http://dx.doi.org/10.1371/journal.pone.0208397 Text en © 2018 Han-Yu Lin http://creativecommons.org/licenses/by/4.0/ This is an open access article distributed under the terms of the Creative Commons Attribution License (http://creativecommons.org/licenses/by/4.0/) , which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.
spellingShingle Research Article
Lin, Han-Yu
A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
title A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
title_full A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
title_fullStr A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
title_full_unstemmed A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
title_short A secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
title_sort secure heterogeneous mobile authentication and key agreement scheme for e-healthcare cloud systems
topic Research Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6291128/
https://www.ncbi.nlm.nih.gov/pubmed/30540838
http://dx.doi.org/10.1371/journal.pone.0208397
work_keys_str_mv AT linhanyu asecureheterogeneousmobileauthenticationandkeyagreementschemeforehealthcarecloudsystems
AT linhanyu secureheterogeneousmobileauthenticationandkeyagreementschemeforehealthcarecloudsystems