Efficient Design of a Novel ECC-Based Public Key Scheme for Medical Data Protection by Utilization of NanoPi Fire
Dariush Abbasinezhad‐Mood, Morteza Nikooghadam · IEEE Transactions on Reliability · 2018
Investigating the literature reveals the fact that the key management protocols play a vital role in protecting the security and privacy of medical data in telecare medical information systems. Recently, Tseng et al. have proposed an interesting elliptic curve cryptosystem (ECC) based self-certified key management scheme that can yield secure channel for the communications of secure sensors (cluster members) and access point (cluster head). After careful consideration, we found that their scheme suffers from the cluster head impersonation, replay, and key replicating attacks. In addition, in the secure session phase, there are some errata and a point multiplication that is undefined in the ECC and hence is mathematically incorrect. Finally, yet importantly, their presented scheme has been adopted for a similar application by other authors with the same problem. Therefore, in this paper, we first try to elaborate the existing errata and security threats. Second, we propose a modified version, which is free from the challenges of their scheme. Eventually, we propose a novel anonymous ECC-based self-certified two-factor key management scheme that not only provides the desired security features, but also has much better efficiency than several recently-published schemes, such as the presented one by Tseng et al. Our formal security verification and proof besides the efficiency analysis support our claim.