• DocumentCode
    44103
  • Title

    A Privacy-Preserving Attribute-Based Authentication System for Mobile Health Networks

  • Author

    Linke Guo ; Chi Zhang ; Jinyuan Sun ; Yuguang Fang

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Univ. of Florida, Gainesville, FL, USA
  • Volume
    13
  • Issue
    9
  • fYear
    2014
  • fDate
    Sept. 2014
  • Firstpage
    1927
  • Lastpage
    1941
  • Abstract
    Electronic healthcare (eHealth) systems have replaced paper-based medical systems due to the attractive features such as universal accessibility, high accuracy, and low cost. As a major component of eHealth systems, mobile healthcare (mHealth) applies mobile devices, such as smartphones and tablets, to enable patient-to-physician and patient-to-patient communications for better healthcare and quality of life (QoL). Unfortunately, patients´ concerns on potential leakage of personal health records (PHRs) is the biggest stumbling block. In current eHealth/mHealth networks, patients´ medical records are usually associated with a set of attributes like existing symptoms and undergoing treatments based on the information collected from portable devices. To guarantee the authenticity of those attributes, PHRs should be verifiable. However, due to the linkability between identities and PHRs, existing mHealth systems fail to preserve patient identity privacy while providing medical services. To solve this problem, we propose a decentralized system that leverages users´ verifiable attributes to authenticate each other while preserving attribute and identity privacy. Moreover, we design authentication strategies with progressive privacy requirements in different interactions among participating entities. Finally, we have thoroughly evaluated the security and computational overheads for our proposed schemes via extensive simulations and experiments.
  • Keywords
    biomedical communication; cryptography; electronic health records; health care; mobile radio; telecommunication security; PHR; QoL; decentralized system; eHealth networks; eHealth systems; electronic healthcare systems; mHealth networks; medical services; mobile devices; mobile health networks; mobile healthcare; paper-based medical systems; patient identity privacy; patient-to-patient communications; patient-to-physician communications; patients medical records; personal health records; privacy-preserving attribute-based authentication system; quality of life; smartphones; tablets; Authentication; Cryptography; Medical diagnostic imaging; Medical services; Mobile computing; Privacy; Authentication; Mobile Health Systems; Privacy; Security; homomorphic encryption; non-interactive witness-indistinguishable; non-interactive zero-knowledge proof;
  • fLanguage
    English
  • Journal_Title
    Mobile Computing, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1536-1233
  • Type

    jour

  • DOI
    10.1109/TMC.2013.84
  • Filename
    6560020