一种健壮的针对6G支持的远程医疗信息系统的认证协议

Lightweight Authentication Protocol for 6G-Enabled Remote Healthcare Information Systems

  • 摘要: 可穿戴设备使用规模的迅速增长与第六代移动通信技术(Sixth Generation Mobile Communication Technology,6G)的持续演进,正推动各类物联网(Internet of Things,IoT)应用迈向新的发展阶段。在此背景下,远程医疗信息系统作为一项关键基础服务日益凸显,其能够在远程医疗服务器上实现患者相关敏感数据的存储与访问,并支持授权实体通过公共互联网进行交互。然而,公共互联网固有的脆弱性使远程医疗信息系统面临恶意攻击和隐私泄露等安全威胁,因此迫切需要通过身份认证与密钥协商机制保障此类关键服务的安全性。在密钥协商过程中,各参与方通过公共信道交换临时密钥信息,并最终建立共享会话密钥,以支持后续加密通信,进而保证传输数据的机密性与完整性。尽管目前已提出一些面向远程医疗信息系统的代表性方案,但现有方案往往带来较高的计算、通信和能量开销,这对资源受限的用户终端构成了现实挑战。此外,部分轻量级协议未能实现其宣称的安全与功能目标,容易受到多种已知攻击的威胁。针对上述挑战,本文提出了一种健壮的针对远程医疗信息系统的认证协议。该协议利用密码散列函数实现用户与医疗服务器之间的相互认证和会话密钥协商,在保障安全性的同时通过最小化计算操作提升效率。全面的安全分析与性能评估结果表明,本文所提出的协议有效克服了现有方法的局限性,能够全面满足关键的安全与功能需求,并在计算开销、通信开销、运行开销以及能量开销之间实现合理权衡,从而为资源受限的远程医疗信息系统提供了一种切实可行且高效的解决方案。

     

    Abstract: The rapid proliferation of wearable devices, coupled with the continuous evolution of the sixth generation mobile communication technology (6G), has propelled Internet of Things applications into a new phase of development. In this context, remote healthcare information systems have emerged as a critical foundational service, enabling the storage and management of patients’ sensitive data on remote medical servers while supporting interactions with authorized entities over public networks. However, the inherent vulnerability of the public internet exposes such systems to a wide spectrum of security threats, including malicious attacks and privacy leakage. Consequently, the design of robust authentication and key-agreement mechanisms has become indispensable for safeguarding these mission-critical services. During key agreement, participating entities exchange ephemeral keying materials over public channels to establish a shared session key, which facilitates subsequent encrypted communication and ensures the confidentiality and integrity of the transmitted data. Although several representative schemes have been proposed for remote healthcare information systems, many of them incur substantial computational, communication, and energy overheads, rendering them unsuitable for resource-constrained user devices. Moreover, certain lightweight protocols fail to achieve their claimed security and functional objectives, leaving them susceptible to a variety of known attacks. To overcome these limitations, this study proposes a robust authentication protocol tailored for remote healthcare information systems. The proposed scheme leverages cryptographic hash functions to achieve mutual authentication and session-key establishment between users and medical servers. By minimizing computational operations, the protocol enhances efficiency without compromising security. Comprehensive security analysis and performance evaluation results demonstrate that the proposed protocol effectively overcomes the limitations of the existing approaches, fully satisfies critical security and functional requirements, and achieves a well-balanced trade-off among computational cost, communication overhead, runtime overhead, and energy consumption. Therefore, it provides a practical and efficient solution for resource-constrained remote healthcare information systems.

     

/

返回文章
返回