Pseudonym-based privacy protection for Steppy application
Heri Arum Nugroho, Yoga Priyana, Ary Setijadi Prihatmanto, Kyung-Hyune Rhee · 2016
Steppy is an Android-based application which is used for calculating the number of footsteps. The Steppy data is stored in the database and is shown on the Shesop website. When Personal Health Record (PHR) features on the website, privacy becomes vulnerable to various attacks so it needs reliable and effective technique for privacy preserving. In order to improve the security of data which are displayed on the Shesop website, anyone who access the site should not tamper without permission. In this paper, we adopt pseudonym technique and apply it to the Shesop website to construct secure application. We review the existing system and make some recommendations to preserve the privacy of user and we design pseudonym technique using time based one-time password (TOTP). Furthermore, we present an approach to address the security needs and pseudonym algorithms to tackle the security requirements. In addition, the proposed scheme can overcome the leaked information, the real identity of patients is never disclosed to anyone. Analysis result shows that the proposed scheme can enhance the user privacy against the adversary contained in the mobile healthcare networks (MHNs), which can be regarded as one of the most vulnerable conditions for patient's data.