透過您的圖書館登入
IP:3.146.152.99
  • 會議論文
  • OpenAccess

植基於免憑證公鑰系統之可淨化數位簽章方法

摘要


在醫療健康的應用中,強化目前的去識別化技術來提供關鍵字遮蔽時的運用彈性,是提升醫療資訊隱私與促進醫療資訊加值運用的重要議題。現階段基於物聯網服務下的安全醫療資訊存取並沒有統一的安全標準與架構,缺乏一個安全執行的環境,如何確保健康醫療資訊在無線傳輸過程中的機密性、完整性、真確性將是未來的重要方向。在本論文中,我們考量免憑證公鑰系統的優點,即無須金鑰託管與額外的公鑰憑證管理負擔,提出基於免憑證公鑰系統的可淨化數位簽章方法,我們的方法支援批次驗證的功能,允許驗證者一次性地驗證所有的個別簽章。此外,驗證者亦有能力偵測出受到竄改的訊息區塊。在安全性分析的部分,我們正規地證明所提之簽章方法可以抵抗選擇明文攻擊的Type-II 及Type-III 偽造者。由分析比較的結果可以得知本論文所提之方法亦具有較佳的運算效率。

並列摘要


In medical and healthcare applications, it is an important issue to increase privacy of medical information and promote the utilization of value-added medical information by strengthening current deidentification techniques for providing the flexibility of hiding keywords. At present, there is no united security standard and infrastructure for accessing IoT-based secure medical information and lacking of a secure execution environment. How to ensure confidentiality, integrity and authentication of medical and health information during wireless transmission is a crucial problem of the future. In this paper, we consider the advantages of certificateless cryptosystems, i.e., no key-escrow problems and without the burden of public key certificate management, to propose a certificateless sanitizable signature scheme. Our mechanism supports batch verification allowing a recipient to verify all individual signatures within a logical step. Additionally, a verifier is capable of detecting altered message blocks. In the security analyses, we formally proved that the proposed signature scheme is existentially unforgeable against Type-II and Type-III adversaries under adaptive chosen-message attacks. The comparison results also revealed that our work has better computational efficiency.

延伸閱讀