클라우드 기반 의료 사이버 물리 시스템용 경량 인증 프로토콜의 보안 취약점 개선 설계
Security Vulnerability Analysis and Enhancement of a Lightweight Authentication Protocol for Cloud-Based Healthcare Cyber-Physical Systems
Medical Cyber-Physical Systems (MCPS) integrate IoT and cloud technologies for patient monitoring, requiring lightweight authentication. Nikkhah and Safkhani proposed LAPCHS, claiming formal security validation. This study re-examines LAPCHS, identifying three unresolved weaknesses: anonymity leakage via SID-MT1 dependency, desynchronization attacks by blocking AT4 updates, and tag impersonation risks from weak x'⊕y' masking. Equation-based attack traces explain each vulnerability. To mitigate these, we propose a redesigned MT1 with session randomness, a commit-and-confirm update procedure, and strengthened dual-masking for x'. Simulations confirm the improved protocol preserves lightweight costs while enhancing anonymity, synchronization resilience, and impersonation resistance. Keywords: RFID Authentication; MCPS; Cloud Healthcare; Lightweight Protocol; Vulnerability Analysis.
목차
Abstract 1. 서론 2. 관련 연구 3. 연구 방법 4. 프로토콜 분석 4.1 제안 프로토콜 개요 4.2 식별된 보안 취약점 5. 제안하는 개선 방안 6. 모의 실험 및 평가 7. 결론 References