Lightweight authentication protocol for connected medical IoT through privacy-preserving access

被引:6
|
作者
Tanveer, Muhammad [1 ]
Chelloug, Samia Allaoua [2 ]
Alabdulhafith, Maali [2 ]
Abd El-Latif, Ahmed A. [3 ,4 ,5 ]
机构
[1] Univ Management & Technol, Dept Comp Sci, Lahore 54770, Pakistan
[2] Princess Nourah bint Abdulrahman Univ, Coll Comp & Informat Sci, Dept Informat Technol, POB 84428, Riyadh 11671, Saudi Arabia
[3] Prince Sultan Univ, Coll Comp & Informat Sci, EIAS Data Sci Lab, Riyadh 11586, Saudi Arabia
[4] Prince Sultan Univ, Ctr Excellence Quantum & Intelligent Comp, Riyadh 11586, Saudi Arabia
[5] Menoufia Univ, Fac Sci, Dept Math & Comp Sci, Menoufia 32511, Egypt
关键词
Smart healthcare system; Security; Privacy; Authentication; Encryption; SCHEME;
D O I
10.1016/j.eij.2024.100474
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the rapid progress of communication technology, the Internet of Things (IoT) has emerged as an essential element in our daily lives. Given that the IoT encompasses diverse devices that often have limited resources in terms of communication, computation, and storage. Consequently, the National Institute of Standards and Technology (NIST) has standardized several lightweight cryptographic algorithms for encryption and decryption, specifically designed to meet the needs of resource -constrained IoT devices. These cryptographic algorithms, known as authenticated encryption with associated data (AEAD), offer more than just confidentiality-they also guarantee information integrity and authentication. Unlike conventional encryption algorithms like AES, which solely provide confidentiality, AEAD algorithms encompass additional functionality to achieve authenticity. This eliminates the need for separate algorithms like message authentication codes to ensure authenticity. Therefore, by leveraging the characteristics of an AEAD protocol, it is possible to develop a lightweight authentication framework to mitigate the security risks inherent in public communication channels. Therefore, in this work, we designed the lightweight authentication protocol for the smart healthcare system (BLAP-SHS) using an AEAD mechanism. In order to do this, a session key must first be created for encrypted communication. This is done via a method called mutual authentication, which verifies the legitimacy of both the user and the server. The random -or -real methodology ensures the security of the derived session key, and the Scyther tool is used to assess BLAP-SHS' resistance to man -in -the -middle and replay attacks. Through using the technique of informal security analysis, the resilience of BLAP-SHS against denial of service, and password -guessing threats are evaluated. By juxtaposing BLAP-SHS with other prominent authentication techniques, the usefulness of BLAP-SHS is also assessed in terms of computing and communication costs. We illustrate that the BLAP-SHS requires a reduction in computation cost ranging from [70.11% to 95.21%] and a reduction in communication resources ranging from [3.85% to 9.09%], as evidenced by our comparative study.
引用
收藏
页数:12
相关论文
共 50 条
  • [41] A Lightweight Privacy-Preserving Authentication Scheme for Vehicle-to-Grid
    Shao, Huishuang
    Ma, Yiwei
    Shao, Binhai
    2024 6TH ASIA ENERGY AND ELECTRICAL ENGINEERING SYMPOSIUM, AEEES 2024, 2024, : 278 - 282
  • [42] A Privacy-Preserving Authentication Model Based on Anonymous Certificates in IoT
    Hamouid, Khaled
    Omar, Mawloud
    Adi, Kamel
    12TH WIRELESS DAYS CONFERENCE (WD 2021), 2020,
  • [43] An IoT-Oriented Privacy-Preserving Fingerprint Authentication System
    Yin, Xuefei
    Wang, Song
    Shahzad, Muhammad
    Hu, Jiankun
    IEEE INTERNET OF THINGS JOURNAL, 2021, 9 (14) : 11760 - 11771
  • [44] PRIVACY-PRESERVING AUTHENTICATION IN WIRELESS IOT: APPLICATIONS, APPROACHES, AND CHALLENGES
    Wang, Shujuan
    Wang, Jian
    Yu, Zhengtao
    IEEE WIRELESS COMMUNICATIONS, 2018, 25 (06) : 60 - 67
  • [45] Dynamically scalable privacy-preserving authentication protocol for distributed IoT based healthcare service providers
    Trivedi, Hiral S.
    Patel, Sankita J.
    WIRELESS NETWORKS, 2023, 29 (03) : 1385 - 1409
  • [46] Privacy-preserving authentication for general directed graphs in industrial IoT
    Zhu, Fei
    Wu, Wei
    Zhang, Yuexin
    Chen, Xiaofeng
    INFORMATION SCIENCES, 2019, 502 : 218 - 228
  • [47] A Privacy-Preserving Authentication and Key Agreement Scheme with Deniability for IoT
    Zhou, Yousheng
    Liu, Tong
    Tang, Fei
    Wang, Feng
    Tinashe, Magara
    ELECTRONICS, 2019, 8 (04):
  • [48] PICO: Privacy-Preserving Access Control in IoT Scenarios through Incomplete Information
    Sciancalepore, Savio
    Zannone, Nicola
    37TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, 2022, : 147 - 156
  • [49] Dynamically scalable privacy-preserving authentication protocol for distributed IoT based healthcare service providers
    Hiral S. Trivedi
    Sankita J. Patel
    Wireless Networks, 2023, 29 : 1385 - 1409
  • [50] A Privacy-Preserving Federated Learning Framework With Lightweight and Fair in IoT
    Chen, Yange
    Liu, Lei
    Ping, Yuan
    Atiquzzaman, Mohammed
    Mumtaz, Shahid
    Zhang, Zhili
    Guizani, Mohsen
    Tian, Zhihong
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2024, 21 (05): : 5843 - 5858