Security vulnerability analysis for an improved anonymous authentication protocol for wearable health monitoring system in an aging society...International Society for Gerontechnology 13th World Conference, October 22-26, 2022, Daegu, South Korea.

Purpose The wearable health monitoring system (WHMS) plays a significant role in medical experts collecting and using patient medical data. The WHMS is becoming more popular than in the past through mobile devices due to meaningful progress in wireless sensor networks. However, because the data abou...

Descripción completa

Detalles Bibliográficos
Publicado en:Gerontechnology Vol. 21; pp. 1 - 2
Autores principales: Eom, G., Byeon, H., Choi, Y.
Formato: abstract equations & formulas proceedings research Journal Article
Publicado: International Society for Gerontechnology Oct2022
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=ccm&AN=161396209&site=ehost-live
header:
  @attributes:
    shortDbName: ccm
    uiTerm: 161396209
    longDbName: CINAHL Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    dissinfo:
    jinfo:
      jid:
        15691101
        904R
      jtl: Gerontechnology
      issn: 15691101
      maglogo: N
    pubinfo:
      dt: Oct2022
      vid: 21
      pid: 54298
      pub: International Society for Gerontechnology
    artinfo:
      ui:
        161396209
        161396209
        161396209
        10.4017/gt.2022.21.s.609.pp4
        161396209
      ppf: 1
      ppct: 1
      formats:
      tig:
        atl: Security vulnerability analysis for an improved anonymous authentication protocol for wearable health monitoring system in an aging society...International Society for Gerontechnology 13th World Conference, October 22-26, 2022, Daegu, South Korea.
      aug:
        au:
          Eom, G.
          Byeon, H.
          Choi, Y.
        affil: Inje University, Republic of Korea
      sug:
        subj:
          Health Status Evaluation
          Monitoring, Physiologic Equipment and Supplies
          Wearable Sensors
          Safety
          Protocols Evaluation
          Aging
          Congresses and Conferences South Korea
          Saudi Arabia
      ab: Purpose The wearable health monitoring system (WHMS) plays a significant role in medical experts collecting and using patient medical data. The WHMS is becoming more popular than in the past through mobile devices due to meaningful progress in wireless sensor networks. However, because the data about health used by the WHMS is related to privacy, it has to be protected from malicious access when wirelessly transmitted. Jiang et al. proposed a two-factor suitable for WHMSs using a fuzzy verifier. However, Jiaqing Mo et al. revealed that the protocol proposed by Jiang et al. had various security vulnerabilities and proposed an authentication protocol with improved security and guaranteed anonymity for WHMSs. In this paper, we analyse the authentication protocol proposed by Jiaqing Mo et al. and determine problems with the offline identification, password guessing attacks, operation process bit mismatch, no perfect forward secrecy, no mutual authentication and insider attacks. Method This paper analyzed the operation process of Jiang et al.'s protocol and found various vulnerability as off-line ID, PW guessing attack, operation process bit mismatch, no perfect forward secrecy, no mutual authentication and insider attack. According to Jiaqing Mo et al.'s proposed protocol, when an adversary acquires a MD, the adversary can extract information stored in the MD and then find out the user's ID and PW. The information of {Reg_i, A_i, C_i, m, n, h()} is sent to the MD through the GWN security channel. Thereafter, the MD calculates and updates A_i^*=A_i⊕h(ID_i||r_i) and D_i=r_i⊕h(h(ID_i||PW_i) mod m). Finally, information of {Reg_i, A_i, A_i^*, C_i, D_i, m, n, h()} is stored in the MD. Assuming that an adversary found out this through a physical analysis method, an ID and password can be derived through the formula of [Reg_i]^*=h(h(ID_i||R_i^*||HPW_i^*) mod m). ... Summarizing the above formula, the adversary will be aware of the information {Ai*, Di, m, h()} except for the ID and PW. The adversary repeatedly performs verification while continuing to change until the user's ID and PW are found. Ultimately, the user's exact ID and PW can be found. Results and Discussion In this paper, a security analysis was conducted after explaining the operation process of an authentication protocol with improved security and guaranteed anonymity for the WHMS proposed by Jiaqing Mo et al. The protocols proposed by Jiaqing Mo et al. have vulnerabilities in offline identification, password guessing attacks, operation process bit mismatch, no perfect forward secrecy, no mutual authentication and insider attack problems.
      pubtype: Academic Journal
      doctype:
        abstract
        equations & formulas
        proceedings
        research
        Journal Article
      ougenre: Article
    language: English
    refInfo:
    holdings:
      @attributes:
        islocal: N