Shi Qiu;Jinqing Li;Xiaoqiang Di;Xusheng Li;Yunlong Wu;Makram Ibrahim
{"title":"Lightweight Mutual Authentication Scheme Based on Blockchain for Internet of Medical Things","authors":"Shi Qiu;Jinqing Li;Xiaoqiang Di;Xusheng Li;Yunlong Wu;Makram Ibrahim","doi":"10.1109/JIOT.2024.3503065","DOIUrl":null,"url":null,"abstract":"To address the issues of poor user privacy protection and insecure communication in the Internet of Medical Things (IoMT) environment, we propose a blockchain-based lightweight mutual authentication scheme for the IoMT. First, our scheme is a two-factor authentication scheme that uses certificates and feature information for identity authentication. Second, we use elliptic curve cryptography and the Chinese remainder theorem to design a lightweight identity registration and authentication algorithm. This algorithm can aggregate multiple identity information of users for verification, while achieving efficient user identity authentication and ensuring the security of user identity information. Finally, we combined nonfungible tokens (NFTs) with user device information, and through a composable NFT solution, we ensured the uniqueness and immutability of user identity information on the blockchain, while facilitating user identity management. The formal security analysis based on AVISPA has proven the security of our scheme. Performance analysis shows that the proposed scheme has low communication and storage overhead. We simulated the proposed scheme on the Ethereum platform using the Solidity language and conducted latency and throughput analysis of our smart contracts using the stress testing tool, Hyperledger Caliper. The results illustrate the practicality of our scheme.","PeriodicalId":54347,"journal":{"name":"IEEE Internet of Things Journal","volume":"12 7","pages":"8848-8861"},"PeriodicalIF":8.9000,"publicationDate":"2024-11-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IEEE Internet of Things Journal","FirstCategoryId":"94","ListUrlMain":"https://ieeexplore.ieee.org/document/10758667/","RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
To address the issues of poor user privacy protection and insecure communication in the Internet of Medical Things (IoMT) environment, we propose a blockchain-based lightweight mutual authentication scheme for the IoMT. First, our scheme is a two-factor authentication scheme that uses certificates and feature information for identity authentication. Second, we use elliptic curve cryptography and the Chinese remainder theorem to design a lightweight identity registration and authentication algorithm. This algorithm can aggregate multiple identity information of users for verification, while achieving efficient user identity authentication and ensuring the security of user identity information. Finally, we combined nonfungible tokens (NFTs) with user device information, and through a composable NFT solution, we ensured the uniqueness and immutability of user identity information on the blockchain, while facilitating user identity management. The formal security analysis based on AVISPA has proven the security of our scheme. Performance analysis shows that the proposed scheme has low communication and storage overhead. We simulated the proposed scheme on the Ethereum platform using the Solidity language and conducted latency and throughput analysis of our smart contracts using the stress testing tool, Hyperledger Caliper. The results illustrate the practicality of our scheme.
期刊介绍:
The EEE Internet of Things (IoT) Journal publishes articles and review articles covering various aspects of IoT, including IoT system architecture, IoT enabling technologies, IoT communication and networking protocols such as network coding, and IoT services and applications. Topics encompass IoT's impacts on sensor technologies, big data management, and future internet design for applications like smart cities and smart homes. Fields of interest include IoT architecture such as things-centric, data-centric, service-oriented IoT architecture; IoT enabling technologies and systematic integration such as sensor technologies, big sensor data management, and future Internet design for IoT; IoT services, applications, and test-beds such as IoT service middleware, IoT application programming interface (API), IoT application design, and IoT trials/experiments; IoT standardization activities and technology development in different standard development organizations (SDO) such as IEEE, IETF, ITU, 3GPP, ETSI, etc.