{"title":"一种改进的基于模糊提取的无线体域网络生物特征认证与密钥协议方案","authors":"Xiao Wang , Yong Xie , Dingyi Shui , Shaolong Ge","doi":"10.1016/j.jisa.2025.104047","DOIUrl":null,"url":null,"abstract":"<div><div>Wireless Body Area Networks (WBANs) support data communication between devices around the human body and are widely used in areas such as healthcare and health monitoring. Due to the sensitivity of transmitted data in WBANs, the restriction of device resources, and the requirement of communication efficiency in emergencies, it remains a great challenge to construct an efficient and secure authentication and key agreement scheme to meet the needs of WBANs. Recently, for the secure exchange of sensitive data in WBANs, Zhang et al. (2024) designed a biometric authentication and key agreement protocol using fuzzy extractor. However, an in-depth analysis reveals that the scheme cannot effectively withstand man-in-the-middle attacks and is insufficient in stability. To address the issues, we propose an improved biometric authentication and key agreement scheme. The solution mainly uses fuzzy extraction techniques, biometrics and elliptic curve cryptography. The user is not required to store any information and only requires to send the message once to complete the authentication, which protects the user’s privacy and is more appropriate for WBANs devices with limited resources. The security of our scheme is demonstrated by formal and informal security analysis. Additionally, we comprehensively evaluate the calculation complexity and security characteristics of this scheme. The evaluation shows our scheme provides both better security as well as reduced computational and communication overheads compared with Zhang et al. (2024)’s scheme.</div></div>","PeriodicalId":48638,"journal":{"name":"Journal of Information Security and Applications","volume":"91 ","pages":"Article 104047"},"PeriodicalIF":3.8000,"publicationDate":"2025-04-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"An improved biometric authentication and key agreement scheme based on fuzzy extractor for Wireless Body Area Networks\",\"authors\":\"Xiao Wang , Yong Xie , Dingyi Shui , Shaolong Ge\",\"doi\":\"10.1016/j.jisa.2025.104047\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><div>Wireless Body Area Networks (WBANs) support data communication between devices around the human body and are widely used in areas such as healthcare and health monitoring. Due to the sensitivity of transmitted data in WBANs, the restriction of device resources, and the requirement of communication efficiency in emergencies, it remains a great challenge to construct an efficient and secure authentication and key agreement scheme to meet the needs of WBANs. Recently, for the secure exchange of sensitive data in WBANs, Zhang et al. (2024) designed a biometric authentication and key agreement protocol using fuzzy extractor. However, an in-depth analysis reveals that the scheme cannot effectively withstand man-in-the-middle attacks and is insufficient in stability. To address the issues, we propose an improved biometric authentication and key agreement scheme. The solution mainly uses fuzzy extraction techniques, biometrics and elliptic curve cryptography. The user is not required to store any information and only requires to send the message once to complete the authentication, which protects the user’s privacy and is more appropriate for WBANs devices with limited resources. The security of our scheme is demonstrated by formal and informal security analysis. Additionally, we comprehensively evaluate the calculation complexity and security characteristics of this scheme. The evaluation shows our scheme provides both better security as well as reduced computational and communication overheads compared with Zhang et al. (2024)’s scheme.</div></div>\",\"PeriodicalId\":48638,\"journal\":{\"name\":\"Journal of Information Security and Applications\",\"volume\":\"91 \",\"pages\":\"Article 104047\"},\"PeriodicalIF\":3.8000,\"publicationDate\":\"2025-04-20\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Journal of Information Security and Applications\",\"FirstCategoryId\":\"94\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2214212625000845\",\"RegionNum\":2,\"RegionCategory\":\"计算机科学\",\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"COMPUTER SCIENCE, INFORMATION SYSTEMS\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Information Security and Applications","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2214212625000845","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
An improved biometric authentication and key agreement scheme based on fuzzy extractor for Wireless Body Area Networks
Wireless Body Area Networks (WBANs) support data communication between devices around the human body and are widely used in areas such as healthcare and health monitoring. Due to the sensitivity of transmitted data in WBANs, the restriction of device resources, and the requirement of communication efficiency in emergencies, it remains a great challenge to construct an efficient and secure authentication and key agreement scheme to meet the needs of WBANs. Recently, for the secure exchange of sensitive data in WBANs, Zhang et al. (2024) designed a biometric authentication and key agreement protocol using fuzzy extractor. However, an in-depth analysis reveals that the scheme cannot effectively withstand man-in-the-middle attacks and is insufficient in stability. To address the issues, we propose an improved biometric authentication and key agreement scheme. The solution mainly uses fuzzy extraction techniques, biometrics and elliptic curve cryptography. The user is not required to store any information and only requires to send the message once to complete the authentication, which protects the user’s privacy and is more appropriate for WBANs devices with limited resources. The security of our scheme is demonstrated by formal and informal security analysis. Additionally, we comprehensively evaluate the calculation complexity and security characteristics of this scheme. The evaluation shows our scheme provides both better security as well as reduced computational and communication overheads compared with Zhang et al. (2024)’s scheme.
期刊介绍:
Journal of Information Security and Applications (JISA) focuses on the original research and practice-driven applications with relevance to information security and applications. JISA provides a common linkage between a vibrant scientific and research community and industry professionals by offering a clear view on modern problems and challenges in information security, as well as identifying promising scientific and "best-practice" solutions. JISA issues offer a balance between original research work and innovative industrial approaches by internationally renowned information security experts and researchers.