摘要
RFID技术在物联网医疗领域得到了广泛的应用,由此而产生的患者隐私泄漏以及医疗记录伪造等问题成为研究热点.已有方案要求阅读器(Reader)与后台服务器保持实时连接,对网络环境要求较高,也会给系统带来一定安全隐患;提出了一种智能医疗环境下基于椭圆曲线加密的RFID离线互认证方案(EMAH),并进行了安全性证明,该方案采用HIS授权Reader进行离线互认证的方式来确保协议参与方的合法性,并将椭圆曲线加密以及数字签名算法应用到数据加密中,确保了医疗数据的安全性以及完整性,同时保护了患者的隐私;通过安全与性能分析,相对于其它方案,EMAH在离线身份认证、位置隐私以及医疗数据信息保护等方面具有较强的安全性,而性能开销与其它方案相当.
The RFID Technology has been widely applied in the lOT-based healthcare environment. The disclosure of the inpatient's privacy information and the forgery of medical records are research focus in recent literatures. The real-time connection between the Reader and the Server are needed in many schemes, which give rise to the higher requirement about the network condition, will also bring some potential risks to the system security. In this paper, an ECC-based RFID mutual authentication scheme in the IOT-based Healthcare environment /EMAH ) is proposed, and the security proof is provided. In this scheme,the HIS authorizes the Reader to a- dopt the off-line mutual authentication way to ensure the legality of protocol participants. EMAH applies the ECC and the digital signature to the data encryption, so as to guarantee the security and integrity of the medical records. Moreover, EMAH can preserve the privacy information for the patients. According the security and performance analyses, the EMAH is more secure in terms of off-line authentication, location privacy and medical information protection and has the similar performance compared with existing work.
出处
《小型微型计算机系统》
CSCD
北大核心
2017年第12期2714-2718,共5页
Journal of Chinese Computer Systems
基金
国家自然科学基金项目(61073037
61272496
61272151)资助
关键词
RFID
椭圆曲线加密
身份认证
隐私保护
RFID
elliptic curve cryptography
authentication
privacy protection