{"title":"A Privacy Preserving Mutual Authentication Scheme Suitable for IoT-Based Medical Systems","authors":"M. Ebrahimi, M. Bayat, Behnam Zahednejad","doi":"10.22042/ISECURE.2021.183936.463","DOIUrl":null,"url":null,"abstract":"The medical system remains among the fastest to adopt the Internet of Things. The reason for this trend is that integration Internet of Things(IoT) features into medical devices greatly improve the quality and effectiveness of service. However, there are many unsolved security problems. Due to medical information is critical and important, authentication between users and medical servers is an essential issue. Recently, Park et al. proposed an authentication scheme using Shamir's threshold technique for IoT-based medical information system and claimed that their scheme satisfies all security requirements and is immune to various types of attacks. However, in this paper, we show that Park et al.'s scheme does not achieve user anonymity, forward security, and mutual authentication and it is not resistant to the DoS attacks and then we introduce an improved mutual authentication scheme based on Elliptic Curve Cryptography (ECC) and Shamir 's secret sharing for IoT-based medical information system.In this paper, we formally analyze the security properties of our scheme via the ProVerif. Moreover, we compare our proposed scheme with other related schemes in terms of security and performance.","PeriodicalId":436674,"journal":{"name":"ISC Int. J. Inf. Secur.","volume":"12 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-08-28","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"ISC Int. J. Inf. Secur.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.22042/ISECURE.2021.183936.463","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
Abstract
The medical system remains among the fastest to adopt the Internet of Things. The reason for this trend is that integration Internet of Things(IoT) features into medical devices greatly improve the quality and effectiveness of service. However, there are many unsolved security problems. Due to medical information is critical and important, authentication between users and medical servers is an essential issue. Recently, Park et al. proposed an authentication scheme using Shamir's threshold technique for IoT-based medical information system and claimed that their scheme satisfies all security requirements and is immune to various types of attacks. However, in this paper, we show that Park et al.'s scheme does not achieve user anonymity, forward security, and mutual authentication and it is not resistant to the DoS attacks and then we introduce an improved mutual authentication scheme based on Elliptic Curve Cryptography (ECC) and Shamir 's secret sharing for IoT-based medical information system.In this paper, we formally analyze the security properties of our scheme via the ProVerif. Moreover, we compare our proposed scheme with other related schemes in terms of security and performance.
医疗系统仍然是采用物联网最快的领域之一。出现这种趋势的原因是,将物联网功能集成到医疗设备中可以大大提高服务质量和效率。然而,还有许多安全问题尚未解决。由于医疗信息非常关键和重要,用户和医疗服务器之间的身份验证是一个至关重要的问题。最近,Park 等人针对基于物联网的医疗信息系统提出了一种使用 Shamir 门限技术的身份验证方案,并声称他们的方案满足所有安全要求,并能抵御各种类型的攻击。然而,在本文中,我们发现 Park 等人的方案无法实现用户匿名性、前向安全性和相互认证,也无法抵御 DoS 攻击,因此我们为基于物联网的医疗信息系统引入了一种基于椭圆曲线加密(ECC)和 Shamir 秘密共享的改进型相互认证方案。此外,我们还将我们提出的方案与其他相关方案在安全性和性能方面进行了比较。