
移动医疗系统隐私保护的数据传输协议设计 被引量:1

Security-aware Privacy-preserving Data Transmission for Mobile-Health System
摘要 随着老龄化社会的到来,基于无线体域网的移动医疗系统得到越来越多的关注。由于当前网络环境复杂且移动医疗系统防御脆弱,用户的医疗数据和身份信息很容易泄露。提出了一个基于无证书密码技术的数据安全传输协议,能够实现移动医疗系统中数据的完整性和机密性以及用户身份隐私等安全目标。该方案在医疗用户和医疗服务提供者两端保持记录表,记录用户和医疗服务提供者之间的对称密钥及用户的匿名身份,并在每次通信结束后更新记录表,实现了通信双方的相互认证以及前向安全和后向安全。此外,采用对称加密和数字签名等密码技术实现数据的安全性。性能分析表明所提出的数据安全传输协议计算开销小,简单高效。 With the arrival of aging society,mobile-health systems based on wireless body area network are gaining more and more attentions.However,the network environment is complex and mobile-health systems are vulnerable to attack,thus users'medical data and identity information is vulnerable to leak.In this paper,we propose a secure data transmission protocol based on certificateless cryptographic scheme to ensure the security of the system.It can achieve security objectives such as data integrity,data confidentiality and identity privacy preservation.Specifically,record tables are kept both in the clients and medical service providers to store the symmetric keys and the anonymous identities between.The table is refreshed at the end of each communication such that it can achieve mutual authentication,forward security and backward security.Additionally,symmetric encryption and digital signature are adopted to achieve data security.Performance analysis demonstrates that the scheme is simple and efficient with less computational overhead.
作者 黄兴 张爱清 叶新荣 谢小娟 HUANG Xing;ZHANG Aiqing;YE Xinrong;XIE Xiaojuan(Anhui Normal University,College of Physics and Electronic Information,Wuhu 241000,China)
出处 《无线电通信技术》 2018年第3期282-287,共6页 Radio Communications Technology
基金 国家自然科学基金项目(61601005) 安徽省自然科学基金项目(1608085QF138) 安徽省高校优秀青年人才计划支持重点项目(gxyq ZD2016027) 安徽师范大学博士科研启动基金项目(2014bsqdjj38)
关键词 移动医疗 隐私保护 无证书密码体制 传输协议 mobile-health privacy preservation certificateless public key scheme transmission protocol
  • 相关文献



  • 1Zheng YL. Digital signcryption or how to achieve cost(signature & encryption)<<cost(signature)+cost(encryption). In: Jr Kaliski BS, ed. Proc. of the CRYPTO'97. LNCS 1294, Heidelberg: Springer-Verlag, 1997. 165-179. [doi: 10.1007/BFb0052234].
  • 2Al-Riyami SS, Paterson KG. Certificateless public key cryptography. In: Laih CS, ed. Proc. of the Advances in Cryptology-- Asiacrypt 2003. LNCS 2894, Heidelberg: Springer-Verlag, 2003.452-473. [doi: 10.1007/978,3-540-40061-5_29].
  • 3Barbosa M, Farshim P. Certificateless signcryption. In: Proc. of the ACM Symp. on Information, Computer and Communications Security (ASIACCS 2008). ACM, 2008. 369-372. Idol: 10.1145/1368310.1368364].
  • 4Aranha D, Castro R, Lopez J, Dahab R. Efficient certificateless signcryption. 2008. http://sbseg2008.inf.ufrgs.br/proceedings/data/ pdf/st03 01 resumo.pdf.
  • 5Wu CH, Chen ZX. A new efficient certificateless signcryption scheme. In: Proc. of the ISISE 2008. 2008.661-664. [doi: 10.1109/ ISISE.2008.206].
  • 6Sharmila DS, Vivek SS, Pandu RC. On the security of certificateless signcryption schemes. Cryptology ePrint Archive: Report 2009/298.2009. http://eprint.iacr.org/2009/298.
  • 7da Silva RR. Toward efficient certificateless signcryption from (and without) bilinear pairings. 2008. http://sbseg2008.inf.ufrgs.br/ proceedings/data/pdf/st03_03_artigo.pdf.
  • 8Li FG, Shirase M, Takagi T. Certificateless hybrid signcryption. In: Proc. of the ISPEC 2009. LNCS 5451, Berlin, Heidelberg: Springer-Verlag, 2009. 112-123. [doi: 10.1007/978-3-642-00843-6_11].
  • 9MIRACL. Multiprecision integer and rational arithmetic C/C++ Library. 2004. http://indigo.ie/mscott/.
  • 10Chert L, Cheng Z, Smart NP. Identity-Based key agreement protocols from pairings. Int'l Journal of Information Security, 2007, 6(4):213-241. [doi: 10.1007/s10207-006-0011-9].











使用帮助 返回顶部