Simple Group Password-based Authenticated Key Agreements for the Integrated EPR Information System
Autor: | I-Pin Chang, Ching-Cheng Wang, Tian-Fu Lee |
---|---|
Rok vydání: | 2013 |
Předmět: |
Zero-knowledge password proof
Medical Records Systems Computerized Computer science Medicine (miscellaneous) Health Informatics Computer security computer.software_genre One-time password S/KEY Password strength Access to Information User-Computer Interface Health Information Management Electronic Health Records Humans Session key Computer Security Group key Password Password policy Mathematical Concepts Systems Integration computer Confidentiality Software Information Systems |
Zdroj: | Journal of Medical Systems. 37 |
ISSN: | 1573-689X 0148-5598 |
DOI: | 10.1007/s10916-012-9916-1 |
Popis: | The security and privacy are important issues for electronic patient records (EPRs). The goal of EPRs is sharing the patients' medical histories such as the diagnosis records, reports and diagnosis image files among hospitals by the Internet. So the security issue for the integrated EPR information system is essential. That is, to ensure the information during transmission through by the Internet is secure and private. The group password-based authenticated key agreement (GPAKE) allows a group of users like doctors, nurses and patients to establish a common session key by using password authentication. Then the group of users can securely communicate by using this session key. Many approaches about GAPKE employ the public key infrastructure (PKI) in order to have higher security. However, it not only increases users' overheads and requires keeping an extra equipment for storing long-term secret keys, but also requires maintaining the public key system. This investigation presents a simple group password-based authenticated key agreement (SGPAKE) protocol for the integrated EPR information system. The proposed SGPAKE protocol does not require using the server or users' public keys. Each user only remembers his weak password shared with a trusted server, and then can obtain a common session key. Then all users can securely communicate by using this session key. The proposed SGPAKE protocol not only provides users with convince, but also has higher security. |
Databáze: | OpenAIRE |
Externí odkaz: |