Mosarrat Jahan, Fatema Tuz Zohra, Md. Kamal Parvez, Upama Kabir, Abdul Mohaimen Al Radi, Shaily Kabir
{"title":"无线体域网络的端到端认证机制","authors":"Mosarrat Jahan, Fatema Tuz Zohra, Md. Kamal Parvez, Upama Kabir, Abdul Mohaimen Al Radi, Shaily Kabir","doi":"10.1016/j.smhl.2023.100413","DOIUrl":null,"url":null,"abstract":"<div><p>Wireless Body Area Network (WBAN) ensures a high-quality healthcare service to patients by providing remote and relentless monitoring of their health conditions. Nevertheless, the patients’ health-related data are very sensitive and require security and privacy while transmitting through WBAN to maximize its benefit. User authentication is one of the primary mechanisms to protect critical data, which verifies the identities of entities involved in data transmission. Hence, in the case of health data, every entity engaged in the data transfer process over WBAN needs to be authenticated. In the literature, an end-to-end user authentication mechanism covering each communicating party must be included. Besides, most of the existing user authentication mechanisms are designed assuming that the patient’s mobile phone is trusted. However, a patient’s mobile phone can be stolen or compromised by various malware, therefore, can behave maliciously. To address these limitations, this paper proposes an end-to-end user authentication and session key agreement scheme between sensors and medical experts where the patient’s mobile phone is semi-trusted. We present a formal security analysis using BAN logic and an informal security analysis of the proposed scheme. Both studies reveal that the proposed methodology is robust against well-known security attacks. We analyze the performance of the proposed scheme by collecting real data in practical deployments and find that our scheme achieves comparable efficiency in computation, communication, and energy usage overheads concerning state-of-the-art methods. Besides, the NS-3 simulation exhibits that our proposed scheme also preserves a satisfactory network performance.</p></div>","PeriodicalId":37151,"journal":{"name":"Smart Health","volume":"29 ","pages":"Article 100413"},"PeriodicalIF":0.0000,"publicationDate":"2023-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"An end-to-end authentication mechanism for Wireless Body Area Networks\",\"authors\":\"Mosarrat Jahan, Fatema Tuz Zohra, Md. Kamal Parvez, Upama Kabir, Abdul Mohaimen Al Radi, Shaily Kabir\",\"doi\":\"10.1016/j.smhl.2023.100413\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Wireless Body Area Network (WBAN) ensures a high-quality healthcare service to patients by providing remote and relentless monitoring of their health conditions. Nevertheless, the patients’ health-related data are very sensitive and require security and privacy while transmitting through WBAN to maximize its benefit. User authentication is one of the primary mechanisms to protect critical data, which verifies the identities of entities involved in data transmission. Hence, in the case of health data, every entity engaged in the data transfer process over WBAN needs to be authenticated. In the literature, an end-to-end user authentication mechanism covering each communicating party must be included. Besides, most of the existing user authentication mechanisms are designed assuming that the patient’s mobile phone is trusted. However, a patient’s mobile phone can be stolen or compromised by various malware, therefore, can behave maliciously. To address these limitations, this paper proposes an end-to-end user authentication and session key agreement scheme between sensors and medical experts where the patient’s mobile phone is semi-trusted. We present a formal security analysis using BAN logic and an informal security analysis of the proposed scheme. Both studies reveal that the proposed methodology is robust against well-known security attacks. We analyze the performance of the proposed scheme by collecting real data in practical deployments and find that our scheme achieves comparable efficiency in computation, communication, and energy usage overheads concerning state-of-the-art methods. Besides, the NS-3 simulation exhibits that our proposed scheme also preserves a satisfactory network performance.</p></div>\",\"PeriodicalId\":37151,\"journal\":{\"name\":\"Smart Health\",\"volume\":\"29 \",\"pages\":\"Article 100413\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-09-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Smart Health\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2352648323000417\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q2\",\"JCRName\":\"Health Professions\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Smart Health","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2352648323000417","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q2","JCRName":"Health Professions","Score":null,"Total":0}
An end-to-end authentication mechanism for Wireless Body Area Networks
Wireless Body Area Network (WBAN) ensures a high-quality healthcare service to patients by providing remote and relentless monitoring of their health conditions. Nevertheless, the patients’ health-related data are very sensitive and require security and privacy while transmitting through WBAN to maximize its benefit. User authentication is one of the primary mechanisms to protect critical data, which verifies the identities of entities involved in data transmission. Hence, in the case of health data, every entity engaged in the data transfer process over WBAN needs to be authenticated. In the literature, an end-to-end user authentication mechanism covering each communicating party must be included. Besides, most of the existing user authentication mechanisms are designed assuming that the patient’s mobile phone is trusted. However, a patient’s mobile phone can be stolen or compromised by various malware, therefore, can behave maliciously. To address these limitations, this paper proposes an end-to-end user authentication and session key agreement scheme between sensors and medical experts where the patient’s mobile phone is semi-trusted. We present a formal security analysis using BAN logic and an informal security analysis of the proposed scheme. Both studies reveal that the proposed methodology is robust against well-known security attacks. We analyze the performance of the proposed scheme by collecting real data in practical deployments and find that our scheme achieves comparable efficiency in computation, communication, and energy usage overheads concerning state-of-the-art methods. Besides, the NS-3 simulation exhibits that our proposed scheme also preserves a satisfactory network performance.