Building Secure Healthcare Services Using OAuth 2.0 and JSON']JSON Web Token in IOT Cloud Scenario

被引:0
|
作者
Solapurkar, Prajakta [1 ]
机构
[1] GS Lab, Baner Rd, Pune 411045, Maharashtra, India
关键词
OAuth; 2.0; !text type='Json']Json[!/text] Web Token; IOT; Authorization;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
OAuth 2.0 is a delegated authorization framework enabling secure authorization for applications running on various kinds of platforms. In healthcare services, OAuth allows the patient (resource owner) seeking real time clinical care to authorize automatic monthly payments from his bank account (resource server) without the patient being required to supply his credentials to the clinic (client app). OAuth 2.0 achieves this with the help of tokens issued by an authorization server which enables validated access to a protected resource. To ensure security, access tokens have an expiry time and are short-lived. So the clinical app may use a refresh token to obtain a new access token to cash monthly payments for rendering real time health care services. Refresh tokens need secure storage to ensure they are not leaked, since any malicious party can use them to obtain new access and refresh tokens. Since OAuth 2.0 has dropped signatures and relies completely on SSL/TLS, it is vulnerable to phishing attack when accessing interoperable APIs. In this paper, we develop an approach that combines JSON web token (JWT) with OAuth 2.0 to request an OAuth access token from authorization server when a client wishes to utilize a previous authentication and authorization. Experimental evaluation confirms that the proposed scheme is practically efficient, removes secure storage overhead by removing the need to have or store refresh token, uses signature and prevents different security attacks which is highly desired in health care services using an IOT cloud platform.
引用
收藏
页码:99 / 104
页数:6
相关论文
共 21 条
  • [1] An authentication based scheme for applications using JSON']JSON web token
    Ahmed, Salman
    Mahmood, Qamar
    2019 22ND IEEE INTERNATIONAL MULTI TOPIC CONFERENCE (INMIC), 2019, : 205 - 208
  • [2] Token-Based Authentication Using JSON']JSON Web Token on SIKASIR RESTful Web Service
    Haekal, Muhamad
    Eliyani
    2016 INTERNATIONAL CONFERENCE ON INFORMATICS AND COMPUTING (ICIC), 2016, : 175 - 179
  • [3] RESTful Web Service Implementation on Unklab Information System Using JSON']JSON Web Token (JWT)
    Adam, Stenly Ibrahim
    Moedjahedy, Jimmy H.
    Maramis, Jeremiah
    PROCEEDINGS OF ICORIS 2020: 2020 THE 2ND INTERNATIONAL CONFERENCE ON CYBERNETICS AND INTELLIGENT SYSTEM (ICORIS), 2020, : 202 - 207
  • [4] Efficient Semantic Web Services Development Approaches using REST and JSON']JSON
    John, Elizabeth
    Siddique, Mohammed
    2021 INTERNATIONAL CONFERENCE ON DECISION AID SCIENCES AND APPLICATION (DASA), 2021,
  • [5] Validating a Modified JSON']JSON Web Signature Format using the Scenario of Ammunition Issuance for Training Purposes
    Hofmeier, Michael
    Seidenfad, Karl
    Hommel, Wolfgang
    MILCOM 2023 - 2023 IEEE MILITARY COMMUNICATIONS CONFERENCE, 2023,
  • [6] Dynamic integration of distributed, Cloud-based HPC and HTC resources using JSON']JSON Web Tokens and the INDIGO IAM Service
    Spiga, Danele
    Dal Pra, Stefano
    Salomoni, Davide
    Ceccanti, Andrea
    Alfieri, Roberto
    24TH INTERNATIONAL CONFERENCE ON COMPUTING IN HIGH ENERGY AND NUCLEAR PHYSICS (CHEP 2019), 2020, 245
  • [7] Enabling Secure RESTful Web Services in IoT using OpenStack
    Benomar, Zakaria
    Longo, Francesco
    Merlino, Giovanni
    Puliafito, Antonio
    2020 IEEE 17TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SMART SYSTEMS (MASS 2020), 2020, : 410 - 417
  • [8] Remote Healthcare Monitoring using Wearable IoT Devices and Cloud Services
    Abdel-Gawad, Menatalla
    Usama, Manar
    Hesham, Haidy
    Ibrahim, Omar
    Abdellatif, Mohammad M.
    2022 5TH CONFERENCE ON CLOUD AND INTERNET OF THINGS, CIOT, 2022, : 108 - 113
  • [9] BUILDING COMPLEX SYSTEMS ON TOP OF WEB 2.0 Integration of Web 2.0 Services using Enterprise Service Bus
    Drasil, Pavel
    Pitner, Tomas
    ICSOFT 2009: PROCEEDINGS OF THE 4TH INTERNATIONAL CONFERENCE ON SOFTWARE AND DATA TECHNOLOGIES, VOL 2, 2009, : 179 - 182
  • [10] IoT-Based Big Data Secure Transmission and Management over Cloud System: A Healthcare Digital Twin Scenario
    Stergiou, Christos L.
    Koidou, Maria P.
    Psannis, Konstantinos E.
    APPLIED SCIENCES-BASEL, 2023, 13 (16):