An Improved and Untraceable Lightweight Authentication and Key Agreement Scheme for Wireless Body Area Networks

IF 1.5 4区 计算机科学 Q3 COMPUTER SCIENCE, SOFTWARE ENGINEERING
Zhongqing Wu, Ying Wang, Bo Gong, Lei Cheng, Jianbo Xu, Yulong Wang
{"title":"An Improved and Untraceable Lightweight Authentication and Key Agreement Scheme for Wireless Body Area Networks","authors":"Zhongqing Wu,&nbsp;Ying Wang,&nbsp;Bo Gong,&nbsp;Lei Cheng,&nbsp;Jianbo Xu,&nbsp;Yulong Wang","doi":"10.1002/cpe.70104","DOIUrl":null,"url":null,"abstract":"<div>\n \n <p>Wireless body area networks (WBANs) are an important component of Medical 4.0, as they can use sensors to collect real-time data on a patient's vital signs and transmit this information over the internet to healthcare providers, greatly improving the quality and efficiency of medical care. However, Since WBANs typically collect human physiological information, which involves personal privacy, and the collected data are usually used by medical professionals for medical diagnosis. If the transmitted data are tampered with by attackers, it may lead to errors in medical diagnosis. Therefore, we must ensure the privacy, integrity, and reliability of the data during the transmission process. As a result, identity authentication and session key negotiation become crucial for secure communication in this context. Moreover, due to the constraints of sensors in terms of memory, computation, and battery life, a lightweight and efficient authentication scheme is required. Previously, Narwal et al. proposed a scheme called SAMAKA, which allows for anonymous authentication and session key establishment between sensor nodes and a control node. However, in-depth analysis has revealed that their scheme is vulnerable to sensor node capture attacks and does not provide session unlinkability or forward secrecy. To address the security flaws in Narwal et al.'s protocol, we have proposed an improved and untraceable mutual authentication and key negotiation scheme. We have also formally verified the security of our scheme using BAN logic and the AVISPA tool. Performance analysis shows that our scheme has significant advantages over other related schemes in terms of computational and communication costs, making it more suitable for the resource-constrained WBAN environment.</p>\n </div>","PeriodicalId":55214,"journal":{"name":"Concurrency and Computation-Practice & Experience","volume":"37 9-11","pages":""},"PeriodicalIF":1.5000,"publicationDate":"2025-04-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Concurrency and Computation-Practice & Experience","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1002/cpe.70104","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, SOFTWARE ENGINEERING","Score":null,"Total":0}
引用次数: 0

Abstract

Wireless body area networks (WBANs) are an important component of Medical 4.0, as they can use sensors to collect real-time data on a patient's vital signs and transmit this information over the internet to healthcare providers, greatly improving the quality and efficiency of medical care. However, Since WBANs typically collect human physiological information, which involves personal privacy, and the collected data are usually used by medical professionals for medical diagnosis. If the transmitted data are tampered with by attackers, it may lead to errors in medical diagnosis. Therefore, we must ensure the privacy, integrity, and reliability of the data during the transmission process. As a result, identity authentication and session key negotiation become crucial for secure communication in this context. Moreover, due to the constraints of sensors in terms of memory, computation, and battery life, a lightweight and efficient authentication scheme is required. Previously, Narwal et al. proposed a scheme called SAMAKA, which allows for anonymous authentication and session key establishment between sensor nodes and a control node. However, in-depth analysis has revealed that their scheme is vulnerable to sensor node capture attacks and does not provide session unlinkability or forward secrecy. To address the security flaws in Narwal et al.'s protocol, we have proposed an improved and untraceable mutual authentication and key negotiation scheme. We have also formally verified the security of our scheme using BAN logic and the AVISPA tool. Performance analysis shows that our scheme has significant advantages over other related schemes in terms of computational and communication costs, making it more suitable for the resource-constrained WBAN environment.

一种改进的、不可追踪的无线体域网络轻量级认证与密钥协议方案
无线体域网络(wban)是医疗4.0的重要组成部分,因为它们可以使用传感器收集患者生命体征的实时数据,并通过互联网将这些信息传输给医疗保健提供商,从而大大提高医疗保健的质量和效率。然而,由于wban通常收集人体生理信息,涉及个人隐私,并且所收集的数据通常被医疗专业人员用于医疗诊断。如果传输的数据被攻击者篡改,可能会导致医疗诊断错误。因此,在传输过程中必须保证数据的保密性、完整性和可靠性。因此,身份验证和会话密钥协商对于这种情况下的安全通信至关重要。此外,由于传感器在内存、计算和电池寿命方面的限制,需要一种轻量级、高效的认证方案。此前,Narwal等人提出了一种名为SAMAKA的方案,该方案允许在传感器节点和控制节点之间匿名认证和建立会话密钥。然而,深入分析表明,他们的方案容易受到传感器节点捕获攻击,并且不提供会话不可链接性或前向保密。为了解决Narwal等人协议中的安全漏洞,我们提出了一种改进的、不可追踪的相互认证和密钥协商方案。我们还使用BAN逻辑和AVISPA工具正式验证了我们方案的安全性。性能分析表明,该方案在计算和通信成本方面比其他相关方案具有显著优势,更适合资源受限的WBAN环境。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
Concurrency and Computation-Practice & Experience
Concurrency and Computation-Practice & Experience 工程技术-计算机:理论方法
CiteScore
5.00
自引率
10.00%
发文量
664
审稿时长
9.6 months
期刊介绍: Concurrency and Computation: Practice and Experience (CCPE) publishes high-quality, original research papers, and authoritative research review papers, in the overlapping fields of: Parallel and distributed computing; High-performance computing; Computational and data science; Artificial intelligence and machine learning; Big data applications, algorithms, and systems; Network science; Ontologies and semantics; Security and privacy; Cloud/edge/fog computing; Green computing; and Quantum computing.
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信