Authentication and Authorization Mechanisms for Internet of Healthcare Things
Srinivasan Lakshmi Narasimhan · 2022
The potential risk posed by a vulnerable and security-compromised healthcare system, which deploys devices working with the Internet of Things (IoT), weighs extremely high on its consequential damages to its stakeholders – whether they be patients, doctors, other medical professionals, administrators, regulators, insurers or vendors. The risk of harm far outweighs the benefits of unbridled proliferation and thus requires comprehensive resolution. Cyber-attacks could lead to false claims being preferred on insurance companies with stolen patient personal data, fake data could be introduced with hard to measure consequences and botnets could infiltrate the network and cause havoc through DNS attacks or introduction of malware—all of this causes mayhem inpatient healthcare systems. The purpose of introducing innovative applications like the internet of things is to enrich healthcare services, with enhanced quality in speed and delivery of a discernible range of services to the stakeholders, and the same stability is threatened when there is an attack using stolen data. The key to overcoming the challenge of intrusion into the system is to identify genuine users by implementing a robust and comprehensive mechanism of authentication (knowing and validating) and then authorization (allowing access to permissible activities). With the multitude of devices connected to the healthcare system in the IoT scenario, it is rather a formidable and daunting task; however, it is both doable and effective in neutralizing the challenges of hacking. Graded adoption of authentication and authorization is recommended, contingent on the type of use – routine data capture and recording vis-à-vis online procedure performed with or without remote support.