arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2610.04661cs.CR

医疗物联网的后量子认证协议

Post-Quantum Authentication Protocol for Internet of Medical Things

Kartick Sutradhar, Ranjitha Venkatesh

首次发表
浏览论文内容

中文总结 AI 辅助

针对医疗物联网面临量子攻击及消息篡改等安全威胁,本文提出一种基于格密码与区块链的后量子认证协议,实现消息签名与批量验证,提升大规模系统性能。

中文摘要 AI 辅助

IoMT通信系统应提供来源认证,并确保患者设备产生的消息在传输到网关及由其他医院服务进一步处理时具有完整性保护。针对IoMT,本文讨论了作为医疗报告提供的消息上的篡改、冒充和重放攻击。同时,考虑到潜在的量子攻击,本文还解决了通信系统的长期安全性问题。为此,我们设计了一种满足实际实施要求的协议,该协议采用类似ISIS的格基构造并结合区块链技术概念。患者设备生成包含时间戳和关键信息的规范JSON格式医疗报告。利用随机数,患者使用由消息哈希生成的挑战对消息创建密码签名。网关利用与特定患者关联的可信账本公钥验证签名,并确保所传输消息的新鲜性。为优化许多设备同时与网关交互时的性能,网关使用向量化模线性方程执行批量签名验证。可信账本使用防篡改的REGISTER和TRUST UPDATE条目,维护每个注册患者的信任分数,并在每次ACCEPT/REJECT操作后更新该值。我们的原型应用展示了新患者注册流程、医疗报告的签名与验证、账本审计以及性能评估。基于我们在原型中的实验,我们认为,当应用于大规模系统时,批量验证优于简单签名验证方法。

英文摘要

IoMT communication systems should provide origin authentication and ensure integrity protection for the messages produced by patients' devices for transmission to gateways and further processing by other hospital services. With regard to IoMT, this paper discusses tampering, impersonation, and replay attacks on messages provided as medical reports. Long-term security of the communication system is also addressed considering potential quantum attacks. For this purpose, we design a protocol that meets requirements of practical implementation and employs an ISIS like lattice-based construction combined with concepts of the blockchain technology. Patients' devices generate a canonical JSON format medical report containing a timestamp and critical information. Using a nonce, the patients create a cryptographic signature of the message with a challenge generated from hash of a message. The gateway verifies signatures utilizing the public key of a trusted ledger associated with a particular patient and ensures freshness of the transmitted message. To optimize the performance in case when many devices interact with a gateway at once, the gateway performs batch signature validation using vectorized modular linear equations. The trusted ledger uses tamper-resistant REGISTER and TRUST UPDATE entries, maintaining a trust score of each registered patient and updating the value after each ACCEPT/REJECT operation. Our prototype application demonstrates registration procedure of a new patient, signing and verifying medical reports, auditing of the ledger, and performance assessment. Based on our experiments in the prototype, we argue that, when applied to large-scale systems, batch verification is superior to simple signature validation approach.

发表机构

  • Indian Institute of Information Technology Sri City(斯里城市印度信息学院)
  • GITAM University Bengaluru(班加罗尔 GITAM 大学)

机构由 AI 辅助整理,请以论文原文为准。

↑