Title :
Revocable and Scalable Certificateless Remote Authentication Protocol With Anonymity for Wireless Body Area Networks
Author :
Hu Xiong ; Zhiguang Qin
Author_Institution :
Sch. of Inf. & Software Eng., Univ. of Electron. Sci. & Technol. of China, Chengdu, China
Abstract :
To ensure the security and privacy of the patient´s health status in the wireless body area networks (WBANs), it is critical to secure the extra-body communication between the smart portable device held by the WBAN client and the application providers, such as the hospital, physician or medical staff. Based on certificateless cryptography, this paper proposes a remote authentication protocol featured with nonrepudiation, client anonymity, key escrow resistance, and revocability for extra-body communication in the WBANs. First, we present a certificateless encryption scheme and a certificateless signature scheme with efficient revocation against short-term key exposure, which we believe are of independent interest. Then, a certificateless anonymous remote authentication with revocation is constructed by incorporating the proposed encryption scheme and signature scheme. Our revocation mechanism is highly scalable, which is especially suitable for the large-scale WBANs, in the sense that the key-update overhead on the side of trusted party increased logarithmically in the number of users. As far as we know, this is the first time considering the revocation functionality of anonymous remote authentication for the WBANs. Both theoretic analysis and experimental simulations show that the proposed authentication protocol is provably secure in the random oracle model and highly practical.
Keywords :
body area networks; cryptographic protocols; data privacy; medical information systems; message authentication; wireless sensor networks; WBAN client; certificateless anonymous remote authentication; certificateless cryptography; certificateless encryption scheme; certificateless remote authentication protocol; certificateless signature scheme; client anonymity; extra-body communication; key escrow resistance; key-update overhead; large-scale WBAN; nonrepudiation; patient health status privacy; patient health status security; random oracle model; revocation mechanism; short-term key exposure; smart portable device; wireless body area networks; Authentication; Communication system security; Encryption; Protocols; Public key; Wireless communication; Anonymity; certificateless cryptography; remote authentication; revocation; wireless body area network;
Journal_Title :
Information Forensics and Security, IEEE Transactions on
DOI :
10.1109/TIFS.2015.2414399