• DocumentCode
    107480
  • Title

    Revocable and Scalable Certificateless Remote Authentication Protocol With Anonymity for Wireless Body Area Networks

  • Author

    Hu Xiong ; Zhiguang Qin

  • Author_Institution
    Sch. of Inf. & Software Eng., Univ. of Electron. Sci. & Technol. of China, Chengdu, China
  • Volume
    10
  • Issue
    7
  • fYear
    2015
  • fDate
    Jul-15
  • Firstpage
    1442
  • Lastpage
    1455
  • Abstract
    To ensure the security and privacy of the patient´s health status in the wireless body area networks (WBANs), it is critical to secure the extra-body communication between the smart portable device held by the WBAN client and the application providers, such as the hospital, physician or medical staff. Based on certificateless cryptography, this paper proposes a remote authentication protocol featured with nonrepudiation, client anonymity, key escrow resistance, and revocability for extra-body communication in the WBANs. First, we present a certificateless encryption scheme and a certificateless signature scheme with efficient revocation against short-term key exposure, which we believe are of independent interest. Then, a certificateless anonymous remote authentication with revocation is constructed by incorporating the proposed encryption scheme and signature scheme. Our revocation mechanism is highly scalable, which is especially suitable for the large-scale WBANs, in the sense that the key-update overhead on the side of trusted party increased logarithmically in the number of users. As far as we know, this is the first time considering the revocation functionality of anonymous remote authentication for the WBANs. Both theoretic analysis and experimental simulations show that the proposed authentication protocol is provably secure in the random oracle model and highly practical.
  • Keywords
    body area networks; cryptographic protocols; data privacy; medical information systems; message authentication; wireless sensor networks; WBAN client; certificateless anonymous remote authentication; certificateless cryptography; certificateless encryption scheme; certificateless remote authentication protocol; certificateless signature scheme; client anonymity; extra-body communication; key escrow resistance; key-update overhead; large-scale WBAN; nonrepudiation; patient health status privacy; patient health status security; random oracle model; revocation mechanism; short-term key exposure; smart portable device; wireless body area networks; Authentication; Communication system security; Encryption; Protocols; Public key; Wireless communication; Anonymity; certificateless cryptography; remote authentication; revocation; wireless body area network;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2015.2414399
  • Filename
    7063237