Provably Secure Anti-Phishing Scheme for Medical Information in Smart Healthcare

Shuangshuang Liu, Zhi Wang, Saru Kumari, Jianhui Lv, Chien‐Ming Chen · IEEE Internet of Things Journal · 2024

In the rapidly evolving field of smart healthcare, integrating modern information technologies, such as Internet of Things, big data, and AI, has significantly enhanced the quality, efficiency, and accessibility of medical services. However, this technological advancement also brings substantial security challenges, particularly regarding protecting electronic medical records (EMRs) from phishing attacks. This article presents a provably secure anti-phishing scheme to safeguard EMRs in smart healthcare systems. By utilizing authentication and key agreement technology, our proposed scheme ensures mutual authentication between users and servers, leveraging elliptic curve encryption, symmetric encryption, hash functions, and XOR operations to secure session keys and verify the legitimacy of medical records. Our scheme addresses critical security challenges, including phishing attacks, stolen mobile device attacks, offline password guessing attacks, replay attacks, and temporary information leakage. The real-oracle-random (ROR) model validates the correctness and security of our scheme, confirming its robustness against common cybersecurity threats. Performance evaluations demonstrate that our scheme provides enhanced security and offers lower time and communication costs compared to existing methods. This makes it a highly efficient and practical solution for safeguarding patient data in smart healthcare environments, ultimately contributing to the reliability and trustworthiness of smart healthcare systems.

Read the paper · More papers on PaperTik