Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps
Electronically protected health information is held in computerized healthcare records that contain complete healthcare information and are easily shareable or retrieved by various health care providers via the Internet. The two most important concerns regarding their use involve the security of the...
Main Authors: | , , |
---|---|
Format: | Article |
Language: | English |
Published: |
MDPI AG
2023-02-01
|
Series: | Electronics |
Subjects: | |
Online Access: | https://www.mdpi.com/2079-9292/12/5/1108 |
_version_ | 1797615548472754176 |
---|---|
author | Tian-Fu Lee I-Pin Chang Guo-Jun Su |
author_facet | Tian-Fu Lee I-Pin Chang Guo-Jun Su |
author_sort | Tian-Fu Lee |
collection | DOAJ |
description | Electronically protected health information is held in computerized healthcare records that contain complete healthcare information and are easily shareable or retrieved by various health care providers via the Internet. The two most important concerns regarding their use involve the security of the Internet and the privacy of patients. To protect the privacy of patients, various regions of the world maintain privacy standards. These are set, for example, by the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in Europe. Most recently developed authenticated key agreement schemes for HIPAA and GDPR privacy/security involve modular exponential computations or scalar multiplications on elliptic curves to provide higher security, but they are computationally heavy and therefore costly to implement. Recent studies have shown that cryptosystems that use modular exponential computation and scalar multiplication on elliptic curves are less efficient than those based on Chebyshev chaotic maps. Therefore, this investigation develops a secure and efficient non-certificate-based authenticated key agreement scheme that uses lightweight operations, including Chebyshev chaotic maps and hash operations. The proposed scheme overcomes the limitations of alternative schemes, is computationally more efficient, and provides more functionality. The proposed scheme complies with the privacy principles of HIPAA and GDPR. |
first_indexed | 2024-03-11T07:28:07Z |
format | Article |
id | doaj.art-e02afa5b98084b6c958528e0cf4c52e8 |
institution | Directory Open Access Journal |
issn | 2079-9292 |
language | English |
last_indexed | 2024-03-11T07:28:07Z |
publishDate | 2023-02-01 |
publisher | MDPI AG |
record_format | Article |
series | Electronics |
spelling | doaj.art-e02afa5b98084b6c958528e0cf4c52e82023-11-17T07:31:46ZengMDPI AGElectronics2079-92922023-02-01125110810.3390/electronics12051108Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic MapsTian-Fu Lee0I-Pin Chang1Guo-Jun Su2Department of Medical Informatics, Tzu Chi University, Hualien 97004, TaiwanDepartment of Industrial Management, National Taiwan University of Science and Technology, Taipei 106335, TaiwanInstitute for Information Industry, Taipei 10622, TaiwanElectronically protected health information is held in computerized healthcare records that contain complete healthcare information and are easily shareable or retrieved by various health care providers via the Internet. The two most important concerns regarding their use involve the security of the Internet and the privacy of patients. To protect the privacy of patients, various regions of the world maintain privacy standards. These are set, for example, by the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in Europe. Most recently developed authenticated key agreement schemes for HIPAA and GDPR privacy/security involve modular exponential computations or scalar multiplications on elliptic curves to provide higher security, but they are computationally heavy and therefore costly to implement. Recent studies have shown that cryptosystems that use modular exponential computation and scalar multiplication on elliptic curves are less efficient than those based on Chebyshev chaotic maps. Therefore, this investigation develops a secure and efficient non-certificate-based authenticated key agreement scheme that uses lightweight operations, including Chebyshev chaotic maps and hash operations. The proposed scheme overcomes the limitations of alternative schemes, is computationally more efficient, and provides more functionality. The proposed scheme complies with the privacy principles of HIPAA and GDPR.https://www.mdpi.com/2079-9292/12/5/1108HIPAAGDPRauthenticationkey agreementinformation security |
spellingShingle | Tian-Fu Lee I-Pin Chang Guo-Jun Su Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps Electronics HIPAA GDPR authentication key agreement information security |
title | Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps |
title_full | Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps |
title_fullStr | Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps |
title_full_unstemmed | Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps |
title_short | Compliance with HIPAA and GDPR in Certificateless-Based Authenticated Key Agreement Using Extended Chaotic Maps |
title_sort | compliance with hipaa and gdpr in certificateless based authenticated key agreement using extended chaotic maps |
topic | HIPAA GDPR authentication key agreement information security |
url | https://www.mdpi.com/2079-9292/12/5/1108 |
work_keys_str_mv | AT tianfulee compliancewithhipaaandgdprincertificatelessbasedauthenticatedkeyagreementusingextendedchaoticmaps AT ipinchang compliancewithhipaaandgdprincertificatelessbasedauthenticatedkeyagreementusingextendedchaoticmaps AT guojunsu compliancewithhipaaandgdprincertificatelessbasedauthenticatedkeyagreementusingextendedchaoticmaps |