A Robust and Reusable Ecg-Based Authentication and Data Encryption Scheme for Ehealth Systems

Pei Huang,Borui Li,Linke Guo,Zhanpeng Jin,Yu Chen
DOI: https://doi.org/10.1109/glocom.2016.7841541
2016-01-01
Abstract:eHealth systems generate from the integration of information and communication technologies with traditional healthcare systems. They have widely replaced paper-based systems due to their prominent features of convenience and accuracy. However, eHealth systems also face many challenges, such as the privacy and security concerns over patients' identities and their personal health records (PHRs). Traditional cryptographic approaches are only capable of verifying "what you possess" or "what you remember" with the help of trust authorities. As a result, they are not suitable for medical applications and cannot handle above concerns effectively. Using biometrics can verify "who you are" due to permanence, distinctiveness, and undeniability properties of biometrics. It outstands conventional authentication and encryption approaches in eHealth systems. A promising one among all is the ECG (ElectroCardioGram) signal, which is easier to implement than other biometrics. Unfortunately, most of existing works do not take the nonuniformity of ECG signals into consideration. Besides, they do not protect ECG signals well despite their sensitivity. Hence, we propose a robust and reusable authentication and encryption scheme based on ECG signals for eHealth systems. Our scheme can authenticate patients' identities and protect their PHRs, enable the reuse of the same ECG signal, and preserve the privacy of ECG signals. Theoretical and empirical evaluations demonstrate the security, effectiveness, and efficiency of the proposed scheme.
What problem does this paper attempt to address?