Skip to main content
Log in

ECC-based lightweight authentication and access control scheme for IoT E-healthcare

  • Application of soft computing
  • Published:
Soft Computing Aims and scope Submit manuscript

Abstract

The E-healthcare system has a complex architecture, diverse business types, and sensitive data security. To meet the secure communication and access control requirements in the user–medical server, user–patient, patient–medical server, and other scenarios in the E-healthcare system, secure and efficient authenticated key agreement and access authorization scheme need to be studied. However, the existing multi-server solutions do not consider the authentication requirements of the Wireless Body Area Network (WBAN) and are not suitable for user–patient, patient–medical server scenarios; most of the existing WBAN authentication schemes are single-server type, which are difficult to meet the requirements of multi-server applications, and the study of user–patient real-time scenarios has not received due attention. This work first reveals the structural flaws and security vulnerabilities of the existing typical schemes and then proposes an authentication and access control architecture suitable for multiple scenarios of the E-healthcare system with separate management and business and designs a novel ECC-based multi-factor remote authentication and access control scheme for E-healthcare using physically unclonable function (PUF) and hash. Security analysis and efficiency analysis show that the new scheme has achieved improved functionality and higher security while maintaining low computational and communication overhead.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Institutional subscriptions

Fig. 1
Fig. 2
Fig. 3
Fig. 4
Fig. 5
Fig. 6
Fig. 7
Fig. 8

Similar content being viewed by others

Availability of data and material

Not applicable.

References

Download references

Acknowledgements

This work was funded by the National Natural Science Foundation of China No. 61976142; the Zhejiang Province Natural Science Foundation of China under Grant No. LY19F020045. The authors gratefully acknowledge the anonymous reviewers for their valuable comments.

Funding

This work was funded by the National Natural Science Foundation of China No. 61976142; the Zhejiang Province Natural Science Foundation of China under Grant No. LY19F020045; and the Smart City Construction Plan of Anning District, Lanzhou City (2021-2035).

Author information

Authors and Affiliations

Authors

Contributions

Qiao Yan contributed to supervision; Hailong Yao was involved in conceptualization, methodology, and writing—original draft preparation; Xingbing Fu contributed to writing—reviewing and editing; and Zhibin Zhang and Caihui Lan provided software.

Corresponding author

Correspondence to Qiao Yan.

Ethics declarations

Conflict of interest

The authors declare that they have no conflict of interest.

Code availability

The code that supports the findings of this study is available from the corresponding author upon reasonable request.

Additional information

Publisher's Note

Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and permissions

Reprints and permissions

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Yao, H., Yan, Q., Fu, X. et al. ECC-based lightweight authentication and access control scheme for IoT E-healthcare. Soft Comput 26, 4441–4461 (2022). https://doi.org/10.1007/s00500-021-06512-8

Download citation

  • Accepted:

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.1007/s00500-021-06512-8

Keywords

Navigation