Simple group password-based authenticated key agreements for the integrated EPR information system

J Med Syst. 2013 Apr;37(2):9916. doi: 10.1007/s10916-012-9916-1. Epub 2013 Jan 19.

Abstract

The security and privacy are important issues for electronic patient records (EPRs). The goal of EPRs is sharing the patients' medical histories such as the diagnosis records, reports and diagnosis image files among hospitals by the Internet. So the security issue for the integrated EPR information system is essential. That is, to ensure the information during transmission through by the Internet is secure and private. The group password-based authenticated key agreement (GPAKE) allows a group of users like doctors, nurses and patients to establish a common session key by using password authentication. Then the group of users can securely communicate by using this session key. Many approaches about GAPKE employ the public key infrastructure (PKI) in order to have higher security. However, it not only increases users' overheads and requires keeping an extra equipment for storing long-term secret keys, but also requires maintaining the public key system. This investigation presents a simple group password-based authenticated key agreement (SGPAKE) protocol for the integrated EPR information system. The proposed SGPAKE protocol does not require using the server or users' public keys. Each user only remembers his weak password shared with a trusted server, and then can obtain a common session key. Then all users can securely communicate by using this session key. The proposed SGPAKE protocol not only provides users with convince, but also has higher security.

Publication types

  • Research Support, Non-U.S. Gov't

MeSH terms

  • Access to Information*
  • Computer Security*
  • Confidentiality*
  • Electronic Health Records
  • Humans
  • Mathematical Concepts
  • Medical Records Systems, Computerized / organization & administration*
  • Software
  • Systems Integration
  • User-Computer Interface*