A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things

Wireless body area networks play an indispensable role in the medical Internet of Things. It is a network of several wearables or implantable devices that use wireless technologies to communicate. These devices usually collect the wearer's physiological data and send it to the server. Some heal...

Full description

Bibliographic Details
Main Authors: Zisang Xu, Cheng Xu, Wei Liang, Jianbo Xu, Haixian Chen
Format: Article
Language:English
Published: IEEE 2019-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8695801/
_version_ 1818924309618360320
author Zisang Xu
Cheng Xu
Wei Liang
Jianbo Xu
Haixian Chen
author_facet Zisang Xu
Cheng Xu
Wei Liang
Jianbo Xu
Haixian Chen
author_sort Zisang Xu
collection DOAJ
description Wireless body area networks play an indispensable role in the medical Internet of Things. It is a network of several wearables or implantable devices that use wireless technologies to communicate. These devices usually collect the wearer's physiological data and send it to the server. Some health care providers can access the server over the network and provide medical care to the wearer. Due to the openness and mobility of the wireless network, the adversary can easily steal and forge information, which exchanged in the communication channel that leaks wearer's privacy. Therefore, a secure and reliable authentication scheme is essential. Most of the existing authentication schemes are based on asymmetric encryption. However, since the sensor devices in wireless body area networks are typically resource-constrained devices, their computing resources cannot afford to use asymmetric encryption. In addition, most of the existing lightweight authentication schemes have various security vulnerabilities, especially the lack of forwarding secrecy. Therefore, we propose a secure lightweight authentication scheme for the wireless body area networks. With this scheme, forward secrecy can be guaranteed without using asymmetric encryption. We use the automatic security verification tool ProVerif to verify the security of our scheme and analyze informal security. The experimental results and the theoretical analysis indicate that our scheme significantly reduces the computational cost compared with the schemes using asymmetric encryption and that it has a lower security risk compared with the lightweight schemes.
first_indexed 2024-12-20T02:23:17Z
format Article
id doaj.art-84375030d6d54120b8d3f4ef23133923
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-20T02:23:17Z
publishDate 2019-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-84375030d6d54120b8d3f4ef231339232022-12-21T19:56:46ZengIEEEIEEE Access2169-35362019-01-017539225393110.1109/ACCESS.2019.29128708695801A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of ThingsZisang Xu0https://orcid.org/0000-0002-6861-5277Cheng Xu1Wei Liang2Jianbo Xu3Haixian Chen4College of Computer Science and Electronic Engineering, Hunan University, Changsha, ChinaCollege of Computer Science and Electronic Engineering, Hunan University, Changsha, ChinaSchool of Opto-Electronic and Communication Engineering, Xiamen University of Technology, Xiamen, ChinaSchool of Computer science and Engineering, Hunan University of Science and Technology, Xiangtan, ChinaCollege of Computer Science and Electronic Engineering, Hunan University, Changsha, ChinaWireless body area networks play an indispensable role in the medical Internet of Things. It is a network of several wearables or implantable devices that use wireless technologies to communicate. These devices usually collect the wearer's physiological data and send it to the server. Some health care providers can access the server over the network and provide medical care to the wearer. Due to the openness and mobility of the wireless network, the adversary can easily steal and forge information, which exchanged in the communication channel that leaks wearer's privacy. Therefore, a secure and reliable authentication scheme is essential. Most of the existing authentication schemes are based on asymmetric encryption. However, since the sensor devices in wireless body area networks are typically resource-constrained devices, their computing resources cannot afford to use asymmetric encryption. In addition, most of the existing lightweight authentication schemes have various security vulnerabilities, especially the lack of forwarding secrecy. Therefore, we propose a secure lightweight authentication scheme for the wireless body area networks. With this scheme, forward secrecy can be guaranteed without using asymmetric encryption. We use the automatic security verification tool ProVerif to verify the security of our scheme and analyze informal security. The experimental results and the theoretical analysis indicate that our scheme significantly reduces the computational cost compared with the schemes using asymmetric encryption and that it has a lower security risk compared with the lightweight schemes.https://ieeexplore.ieee.org/document/8695801/AuthenticationIoTsecuritywireless body area network
spellingShingle Zisang Xu
Cheng Xu
Wei Liang
Jianbo Xu
Haixian Chen
A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
IEEE Access
Authentication
IoT
security
wireless body area network
title A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
title_full A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
title_fullStr A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
title_full_unstemmed A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
title_short A Lightweight Mutual Authentication and Key Agreement Scheme for Medical Internet of Things
title_sort lightweight mutual authentication and key agreement scheme for medical internet of things
topic Authentication
IoT
security
wireless body area network
url https://ieeexplore.ieee.org/document/8695801/
work_keys_str_mv AT zisangxu alightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT chengxu alightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT weiliang alightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT jianboxu alightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT haixianchen alightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT zisangxu lightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT chengxu lightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT weiliang lightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT jianboxu lightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings
AT haixianchen lightweightmutualauthenticationandkeyagreementschemeformedicalinternetofthings