Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps

Electronically protected health information is held in computerized healthcare records that contain complete healthcare information and are easily shareable or retrieved by various health care providers via the Internet. The two most important concerns regarding their use involve the security of the...

Full description

Bibliographic Details
Main Authors: Tian-Fu Lee, I-Pin Chang, Guo-Jun Su
Format: Article
Language:English
Published: MDPI AG 2023-02-01
Series:Electronics
Subjects:
Online Access:https://www.mdpi.com/2079-9292/12/5/1108
_version_ 1797615548472754176
author Tian-Fu Lee
I-Pin Chang
Guo-Jun Su
author_facet Tian-Fu Lee
I-Pin Chang
Guo-Jun Su
author_sort Tian-Fu Lee
collection DOAJ
description Electronically protected health information is held in computerized healthcare records that contain complete healthcare information and are easily shareable or retrieved by various health care providers via the Internet. The two most important concerns regarding their use involve the security of the Internet and the privacy of patients. To protect the privacy of patients, various regions of the world maintain privacy standards. These are set, for example, by the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in Europe. Most recently developed authenticated key agreement schemes for HIPAA and GDPR privacy/security involve modular exponential computations or scalar multiplications on elliptic curves to provide higher security, but they are computationally heavy and therefore costly to implement. Recent studies have shown that cryptosystems that use modular exponential computation and scalar multiplication on elliptic curves are less efficient than those based on Chebyshev chaotic maps. Therefore, this investigation develops a secure and efficient non-certificate-based authenticated key agreement scheme that uses lightweight operations, including Chebyshev chaotic maps and hash operations. The proposed scheme overcomes the limitations of alternative schemes, is computationally more efficient, and provides more functionality. The proposed scheme complies with the privacy principles of HIPAA and GDPR.
first_indexed 2024-03-11T07:28:07Z
format Article
id doaj.art-e02afa5b98084b6c958528e0cf4c52e8
institution Directory Open Access Journal
issn 2079-9292
language English
last_indexed 2024-03-11T07:28:07Z
publishDate 2023-02-01
publisher MDPI AG
record_format Article
series Electronics
spelling doaj.art-e02afa5b98084b6c958528e0cf4c52e82023-11-17T07:31:46ZengMDPI AGElectronics2079-92922023-02-01125110810.3390/electronics12051108Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic MapsTian-Fu Lee0I-Pin Chang1Guo-Jun Su2Department of Medical Informatics, Tzu Chi University, Hualien 97004, TaiwanDepartment of Industrial Management, National Taiwan University of Science and Technology, Taipei 106335, TaiwanInstitute for Information Industry, Taipei 10622, TaiwanElectronically protected health information is held in computerized healthcare records that contain complete healthcare information and are easily shareable or retrieved by various health care providers via the Internet. The two most important concerns regarding their use involve the security of the Internet and the privacy of patients. To protect the privacy of patients, various regions of the world maintain privacy standards. These are set, for example, by the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in Europe. Most recently developed authenticated key agreement schemes for HIPAA and GDPR privacy/security involve modular exponential computations or scalar multiplications on elliptic curves to provide higher security, but they are computationally heavy and therefore costly to implement. Recent studies have shown that cryptosystems that use modular exponential computation and scalar multiplication on elliptic curves are less efficient than those based on Chebyshev chaotic maps. Therefore, this investigation develops a secure and efficient non-certificate-based authenticated key agreement scheme that uses lightweight operations, including Chebyshev chaotic maps and hash operations. The proposed scheme overcomes the limitations of alternative schemes, is computationally more efficient, and provides more functionality. The proposed scheme complies with the privacy principles of HIPAA and GDPR.https://www.mdpi.com/2079-9292/12/5/1108HIPAAGDPRauthenticationkey agreementinformation security
spellingShingle Tian-Fu Lee
I-Pin Chang
Guo-Jun Su
Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
Electronics
HIPAA
GDPR
authentication
key agreement
information security
title Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
title_full Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
title_fullStr Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
title_full_unstemmed Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
title_short Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
title_sort compliance with hipaa and gdpr in certificateless based authenticated key agreement using extended chaotic maps
topic HIPAA
GDPR
authentication
key agreement
information security
url https://www.mdpi.com/2079-9292/12/5/1108
work_keys_str_mv AT tianfulee compliancewithhipaaandgdprincertificatelessbasedauthenticatedkeyagreementusingextendedchaoticmaps
AT ipinchang compliancewithhipaaandgdprincertificatelessbasedauthenticatedkeyagreementusingextendedchaoticmaps
AT guojunsu compliancewithhipaaandgdprincertificatelessbasedauthenticatedkeyagreementusingextendedchaoticmaps