选定移动数据收集系统中的身份验证:现状、挑战、解决方案和差距

Marriette Katarahweire, Engineer Bainomugisha, K. Mughal
{"title":"选定移动数据收集系统中的身份验证:现状、挑战、解决方案和差距","authors":"Marriette Katarahweire, Engineer Bainomugisha, K. Mughal","doi":"10.1109/MOBILESoft.2017.9","DOIUrl":null,"url":null,"abstract":"Mobile data collection systems (MDCS) in the health sector are of great benefit to health care providers and community workers especially in low-resource settings. MDCS enable the extension and provision of health services closer to the community by enabling data collection and diagnosis without the patient being in a hospital setting. MDCS, however, face a number security challenges including authentication and authorization of users, secure communication between a mobile client and the server, and secure application deployment. This paper provides a criteria and guidelines for evaluating an authentication model for MDCS. The criteria encompass key authentication dimensions including proper local and remote authentication, password management and recovery especially with no Internet connectivity. We assess the authentication models using two reference systems that are widely used in low-resource settings, namely, District Health Information Software (DHIS 2) and mUzima. The findings reveal gaps in the authentication model of the reference systems including insecure authentication, insecure storage of user credentials on the mobile device and no proper automatic logouts, among others.","PeriodicalId":281934,"journal":{"name":"2017 IEEE/ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft)","volume":"94 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-05-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":"{\"title\":\"Authentication in Selected Mobile Data Collection Systems: Current State, Challenges, Solutions and Gaps\",\"authors\":\"Marriette Katarahweire, Engineer Bainomugisha, K. Mughal\",\"doi\":\"10.1109/MOBILESoft.2017.9\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Mobile data collection systems (MDCS) in the health sector are of great benefit to health care providers and community workers especially in low-resource settings. MDCS enable the extension and provision of health services closer to the community by enabling data collection and diagnosis without the patient being in a hospital setting. MDCS, however, face a number security challenges including authentication and authorization of users, secure communication between a mobile client and the server, and secure application deployment. This paper provides a criteria and guidelines for evaluating an authentication model for MDCS. The criteria encompass key authentication dimensions including proper local and remote authentication, password management and recovery especially with no Internet connectivity. We assess the authentication models using two reference systems that are widely used in low-resource settings, namely, District Health Information Software (DHIS 2) and mUzima. The findings reveal gaps in the authentication model of the reference systems including insecure authentication, insecure storage of user credentials on the mobile device and no proper automatic logouts, among others.\",\"PeriodicalId\":281934,\"journal\":{\"name\":\"2017 IEEE/ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft)\",\"volume\":\"94 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-05-20\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"4\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 IEEE/ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/MOBILESoft.2017.9\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 IEEE/ACM 4th International Conference on Mobile Software Engineering and Systems (MOBILESoft)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MOBILESoft.2017.9","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

摘要

卫生部门的移动数据收集系统(MDCS)对卫生保健提供者和社区工作者大有裨益,特别是在资源匮乏的环境中。MDCS能够在病人不住院的情况下进行数据收集和诊断,从而使卫生服务的扩展和提供更接近社区。然而,MDCS面临着许多安全挑战,包括用户的身份验证和授权、移动客户端和服务器之间的安全通信以及应用程序的安全部署。本文提供了评估MDCS认证模型的标准和指南。这些标准包括关键身份验证维度,包括适当的本地和远程身份验证、密码管理和恢复,尤其是在没有互联网连接的情况下。我们使用在低资源环境中广泛使用的两个参考系统,即区域卫生信息软件(DHIS 2)和mUzima来评估认证模型。调查结果揭示了参考系统的身份验证模型存在缺陷,包括不安全的身份验证、在移动设备上不安全的用户凭证存储以及没有适当的自动注销等。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Authentication in Selected Mobile Data Collection Systems: Current State, Challenges, Solutions and Gaps
Mobile data collection systems (MDCS) in the health sector are of great benefit to health care providers and community workers especially in low-resource settings. MDCS enable the extension and provision of health services closer to the community by enabling data collection and diagnosis without the patient being in a hospital setting. MDCS, however, face a number security challenges including authentication and authorization of users, secure communication between a mobile client and the server, and secure application deployment. This paper provides a criteria and guidelines for evaluating an authentication model for MDCS. The criteria encompass key authentication dimensions including proper local and remote authentication, password management and recovery especially with no Internet connectivity. We assess the authentication models using two reference systems that are widely used in low-resource settings, namely, District Health Information Software (DHIS 2) and mUzima. The findings reveal gaps in the authentication model of the reference systems including insecure authentication, insecure storage of user credentials on the mobile device and no proper automatic logouts, among others.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信