A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification

Telecare Medical Information Systems (TMIS) is a highly focused and unique domain providing healthcare services remotely, the development and advancement in the realm of information and communication technologies boosted the development of TMIS. Smartphones, IoT devices, Mobile Healthcare Applicatio...

Full description

Bibliographic Details
Main Authors: Shaik Shakeel Ahamad, Mohammed Al-Shehri, Ismail Keshta
Format: Article
Language:English
Published: IEEE 2022-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/9950052/
_version_ 1811179615678365696
author Shaik Shakeel Ahamad
Mohammed Al-Shehri
Ismail Keshta
author_facet Shaik Shakeel Ahamad
Mohammed Al-Shehri
Ismail Keshta
author_sort Shaik Shakeel Ahamad
collection DOAJ
description Telecare Medical Information Systems (TMIS) is a highly focused and unique domain providing healthcare services remotely, the development and advancement in the realm of information and communication technologies boosted the development of TMIS. Smartphones, IoT devices, Mobile Healthcare Applications (MHA) and hospital servers are the building blocks of TMIS. Emergen Research predicts that IoT based healthcare security market will reach USD 5.52 Billion in 2028. Existing IoT based healthcare solutions are facing many security problems which includes information leakage, false authentication, key loss and are not in compliance with Health Insurance Portability and Accountability Act (HIPAA) regulations as IoT devices and sensors used are prone to Blue Borne, DoS (Denial of Service), DDoS (Distributed Denial of Service) and Reverse-engineering attacks. In addition to these healthcare applications in the IoT devices/sensors and mobile healthcare applications in the smart phone of the patient are vulnerable to repackaging attacks and lacked transport layer protection. This paper proposes a SRSTMIS (Secure and Resilient Scheme for Telecare Medical Information Systems) containing its architecture, a procedure to verify the safety and security of patients credentials and Mobile Healthcare Applications (MHA) and finally proposed a secure protocol. White-Box Cryptography (WBC) ensures the safety and security of the keys in the healthcare applications and in the SE, UICC and TPM. We have threat modeled our proposed healthcare framework using STRIDE approach and successfully verified using Microsoft Threat Modeling tool 2016. Our proposed secure and lightweight authentication scheme has been successfully verified with BAN (Burrows, Abadi, and Needham) logic and Scyther tool, and our proposed protocol overcome DoS (Denial of Service), multi-protocol attack, Blue Borne attack, DDoS (Distributed Denial of Service) attack, reverse engineering, insider, outsider and Phlashing attacks. SRSTMIS overcomes information leakage from sensors during rest and during transit, key loss from healthcare applications of the sensors and smart phone and false authentication and ensures HIPAA regulations. Proposed protocol was successfully implemented in Android Studio. We have compared our proposed work with the existing works and found to better in terms of security, resisting attacks, and in consumption of resources.
first_indexed 2024-04-11T06:38:12Z
format Article
id doaj.art-8e57ac72a1734d82861a1f388d354a02
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-04-11T06:38:12Z
publishDate 2022-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-8e57ac72a1734d82861a1f388d354a022022-12-22T04:39:37ZengIEEEIEEE Access2169-35362022-01-011012022712024410.1109/ACCESS.2022.32172309950052A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal VerificationShaik Shakeel Ahamad0https://orcid.org/0000-0002-9619-0907Mohammed Al-Shehri1https://orcid.org/0000-0003-1035-311XIsmail Keshta2Department of Information Technology, College of Computer and Information Sciences, Majmaah University, Al-Majmaah, Saudi ArabiaDepartment of Information Technology, College of Computer and Information Sciences, Majmaah University, Al-Majmaah, Saudi ArabiaComputer Science and Information Systems Department, College of Applied Sciences, AlMaarefa University, Riyadh, Saudi ArabiaTelecare Medical Information Systems (TMIS) is a highly focused and unique domain providing healthcare services remotely, the development and advancement in the realm of information and communication technologies boosted the development of TMIS. Smartphones, IoT devices, Mobile Healthcare Applications (MHA) and hospital servers are the building blocks of TMIS. Emergen Research predicts that IoT based healthcare security market will reach USD 5.52 Billion in 2028. Existing IoT based healthcare solutions are facing many security problems which includes information leakage, false authentication, key loss and are not in compliance with Health Insurance Portability and Accountability Act (HIPAA) regulations as IoT devices and sensors used are prone to Blue Borne, DoS (Denial of Service), DDoS (Distributed Denial of Service) and Reverse-engineering attacks. In addition to these healthcare applications in the IoT devices/sensors and mobile healthcare applications in the smart phone of the patient are vulnerable to repackaging attacks and lacked transport layer protection. This paper proposes a SRSTMIS (Secure and Resilient Scheme for Telecare Medical Information Systems) containing its architecture, a procedure to verify the safety and security of patients credentials and Mobile Healthcare Applications (MHA) and finally proposed a secure protocol. White-Box Cryptography (WBC) ensures the safety and security of the keys in the healthcare applications and in the SE, UICC and TPM. We have threat modeled our proposed healthcare framework using STRIDE approach and successfully verified using Microsoft Threat Modeling tool 2016. Our proposed secure and lightweight authentication scheme has been successfully verified with BAN (Burrows, Abadi, and Needham) logic and Scyther tool, and our proposed protocol overcome DoS (Denial of Service), multi-protocol attack, Blue Borne attack, DDoS (Distributed Denial of Service) attack, reverse engineering, insider, outsider and Phlashing attacks. SRSTMIS overcomes information leakage from sensors during rest and during transit, key loss from healthcare applications of the sensors and smart phone and false authentication and ensures HIPAA regulations. Proposed protocol was successfully implemented in Android Studio. We have compared our proposed work with the existing works and found to better in terms of security, resisting attacks, and in consumption of resources.https://ieeexplore.ieee.org/document/9950052/Telecare medical information systems (TMIS)SRSTMIS (secure and resilient scheme for telecare medical information systems)mobile healthcare applications (MHA)white-box cryptography (WBC)health insurance portability and accountability act (HIPAA)BAN logic
spellingShingle Shaik Shakeel Ahamad
Mohammed Al-Shehri
Ismail Keshta
A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification
IEEE Access
Telecare medical information systems (TMIS)
SRSTMIS (secure and resilient scheme for telecare medical information systems)
mobile healthcare applications (MHA)
white-box cryptography (WBC)
health insurance portability and accountability act (HIPAA)
BAN logic
title A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification
title_full A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification
title_fullStr A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification
title_full_unstemmed A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification
title_short A Secure and Resilient Scheme for Telecare Medical Information Systems With Threat Modeling and Formal Verification
title_sort secure and resilient scheme for telecare medical information systems with threat modeling and formal verification
topic Telecare medical information systems (TMIS)
SRSTMIS (secure and resilient scheme for telecare medical information systems)
mobile healthcare applications (MHA)
white-box cryptography (WBC)
health insurance portability and accountability act (HIPAA)
BAN logic
url https://ieeexplore.ieee.org/document/9950052/
work_keys_str_mv AT shaikshakeelahamad asecureandresilientschemefortelecaremedicalinformationsystemswiththreatmodelingandformalverification
AT mohammedalshehri asecureandresilientschemefortelecaremedicalinformationsystemswiththreatmodelingandformalverification
AT ismailkeshta asecureandresilientschemefortelecaremedicalinformationsystemswiththreatmodelingandformalverification
AT shaikshakeelahamad secureandresilientschemefortelecaremedicalinformationsystemswiththreatmodelingandformalverification
AT mohammedalshehri secureandresilientschemefortelecaremedicalinformationsystemswiththreatmodelingandformalverification
AT ismailkeshta secureandresilientschemefortelecaremedicalinformationsystemswiththreatmodelingandformalverification