A lightweight authentication and authorization method in IoT-based medical care.

Saved in:
Bibliographic Details
Title: A lightweight authentication and authorization method in IoT-based medical care.
Authors: Khajehzadeh, Laleh1 (AUTHOR) laleh.khajehzadeh@iaud.ac.ir, Barati, Hamid1 (AUTHOR) hbarati@iaud.ac.ir, Barati, Ali1 (AUTHOR) abarati@iaud.ac.ir
Source: Multimedia Tools & Applications. Apr2025, Vol. 84 Issue 12, p11137-11176. 40p.
Subjects: Internet of medical things, Wireless sensor network security, Wireless sensor nodes, Data privacy, Internet privacy
Abstract: The Internet of Things has opened up new opportunities in healthcare systems. Wireless sensor nodes are used to collect and exchange health-related data in the Internet of Things. In this integration, data is transmitted to medical professionals through unsecured channels to enable them to monitor patients' conditions in real-time. However, due to the high sensitivity of e-health records, there are key challenges such as security considerations, privacy, and authentication in data transmission in heterogeneous Internet of Things networks. This article examines the solution proposed by Masud and colleagues and points out the existing threats and vulnerabilities, such as node clone/replication attacks. To overcome these drawbacks, we propose an improved lightweight authentication protocol for a smart healthcare system. In the proposed protocol, the mutual authentication process consists of two steps. The doctor sends their information for authentication and the desired sensor node ID to the gateway for communication. After successful confirmation of authentication, the gateway node, in turn, sends a message to the sensor node to complete the authentication process. After confirming the authentication process, the node sends a message to the gateway to complete the authentication process and key agreement. Once the authentication process of the sensor node is confirmed, the gateway sends a message to the medical user based on their authentication along with the session key. The security of the proposed protocol is demonstrated through automatic validation of protocols using tools like ProVerif and internet security programs. Additionally, security features and performance analysis are compared to other schemes. The results show that the improved proposed protocol provides a higher level of security while ensuring computational and communication efficiency. It is also resistant to attacks such as mutual authentication, identity anonymity and untraceability, ensures data privacy, and provides perfect forward secrecy, among others. [ABSTRACT FROM AUTHOR]
Copyright of Multimedia Tools & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
Full text is not displayed to guests.
FullText Links:
  – Type: pdflink
Text:
  Availability: 1
Header DbId: egs
DbLabel: Engineering Source
An: 184870648
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: A lightweight authentication and authorization method in IoT-based medical care.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Khajehzadeh%2C+Laleh%22">Khajehzadeh, Laleh</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> laleh.khajehzadeh@iaud.ac.ir</i><br /><searchLink fieldCode="AR" term="%22Barati%2C+Hamid%22">Barati, Hamid</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> hbarati@iaud.ac.ir</i><br /><searchLink fieldCode="AR" term="%22Barati%2C+Ali%22">Barati, Ali</searchLink><relatesTo>1</relatesTo> (AUTHOR)<i> abarati@iaud.ac.ir</i>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Multimedia+Tools+%26+Applications%22">Multimedia Tools & Applications</searchLink>. Apr2025, Vol. 84 Issue 12, p11137-11176. 40p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Internet+of+medical+things%22">Internet of medical things</searchLink><br /><searchLink fieldCode="DE" term="%22Wireless+sensor+network+security%22">Wireless sensor network security</searchLink><br /><searchLink fieldCode="DE" term="%22Wireless+sensor+nodes%22">Wireless sensor nodes</searchLink><br /><searchLink fieldCode="DE" term="%22Data+privacy%22">Data privacy</searchLink><br /><searchLink fieldCode="DE" term="%22Internet+privacy%22">Internet privacy</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: The Internet of Things has opened up new opportunities in healthcare systems. Wireless sensor nodes are used to collect and exchange health-related data in the Internet of Things. In this integration, data is transmitted to medical professionals through unsecured channels to enable them to monitor patients' conditions in real-time. However, due to the high sensitivity of e-health records, there are key challenges such as security considerations, privacy, and authentication in data transmission in heterogeneous Internet of Things networks. This article examines the solution proposed by Masud and colleagues and points out the existing threats and vulnerabilities, such as node clone/replication attacks. To overcome these drawbacks, we propose an improved lightweight authentication protocol for a smart healthcare system. In the proposed protocol, the mutual authentication process consists of two steps. The doctor sends their information for authentication and the desired sensor node ID to the gateway for communication. After successful confirmation of authentication, the gateway node, in turn, sends a message to the sensor node to complete the authentication process. After confirming the authentication process, the node sends a message to the gateway to complete the authentication process and key agreement. Once the authentication process of the sensor node is confirmed, the gateway sends a message to the medical user based on their authentication along with the session key. The security of the proposed protocol is demonstrated through automatic validation of protocols using tools like ProVerif and internet security programs. Additionally, security features and performance analysis are compared to other schemes. The results show that the improved proposed protocol provides a higher level of security while ensuring computational and communication efficiency. It is also resistant to attacks such as mutual authentication, identity anonymity and untraceability, ensures data privacy, and provides perfect forward secrecy, among others. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Multimedia Tools & Applications is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=184870648
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s11042-024-19379-2
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 40
        StartPage: 11137
    Subjects:
      – SubjectFull: Internet of medical things
        Type: general
      – SubjectFull: Wireless sensor network security
        Type: general
      – SubjectFull: Wireless sensor nodes
        Type: general
      – SubjectFull: Data privacy
        Type: general
      – SubjectFull: Internet privacy
        Type: general
    Titles:
      – TitleFull: A lightweight authentication and authorization method in IoT-based medical care.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Khajehzadeh, Laleh
      – PersonEntity:
          Name:
            NameFull: Barati, Hamid
      – PersonEntity:
          Name:
            NameFull: Barati, Ali
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 21
              M: 04
              Text: Apr2025
              Type: published
              Y: 2025
          Identifiers:
            – Type: issn-print
              Value: 13807501
          Numbering:
            – Type: volume
              Value: 84
            – Type: issue
              Value: 12
          Titles:
            – TitleFull: Multimedia Tools & Applications
              Type: main
ResultId 1