Securing EHR in Healthcare 4.0: A Robust Mobile-Biometric Approach
Securing electronic healthcare records: A mobile-based biometric authentication approach
The paper introduces a mobile-based biometric authentication framework designed for Healthcare 4.0 to secure Electronic Healthcare Records (EHR). It utilizes a multi-factor approach involving mobile devices, wearables, and cloud servers to establish secure session keys, achieving a SOTA balance between security robustness and computational efficiency.
TL;DR
In the era of Healthcare 4.0, the shift from hospital-centric to patient-centric care demands ironclad security for sensitive Electronic Healthcare Records (EHR). This paper proposes a lightweight, biometric-based authentication framework that leverages mobile and wearable devices. By utilizing Elliptic Curve Cryptography (ECC) and formal verification via the AVISPA tool, the authors deliver a scheme that is faster (0.068s) and more secure than previous SOTA methods.
Problem & Motivation: The "Doctor-Centered" Vulnerability
Traditional healthcare systems are historically doctor-centered, where data is managed by professionals and accessed via relatively static portals. In a modern Healthcare 4.0 environment:
- Remote Monitoring: Vital signs are transmitted in real-time from Wearable Devices (WDs) to Cloud Servers (CS) via potentially insecure channels.
- Privacy Fragmentation: Patients lack granular control over who (Admin, Doctor, or Caregiver) sees their records.
- Security Gaps: Existing protocols are often susceptible to Man-In-The-Middle (MIM) attacks, lack Perfect Forward Secrecy (PFS), or are computationally too heavy for low-power wearables.
The authors' insight is to empower patients to "self-authenticate" using their own biometrics and mobile devices (MDs), creating a decentralized trust bridge between their bodies and the cloud.
Methodology: ECC Meets Biometric Hashing
The core of the methodology is a multi-phase authentication and access control protocol involving three main entities: the Patient, the Doctor, and the Cloud Server (CS).
1. Model Architecture
The system consists of five components: the patient’s wearables (data collection), the mobile device (local processing), access points (transmission), the cloud server (storage/verification), and the doctor (consumer).

2. Cryptographic Ingredients
- Elliptic Curve Cryptography (ECC): Chosen for its high security-to-key-length ratio, making it ideal for mobile devices.
- Biometric Hashing: Instead of storing raw biometrics, the system uses a perceptual hash (Biu) to ensure privacy even if the server is compromised.
- Mutual Authentication: Both the User and the Cloud Server must verify each other's identities before a Session Key (SK) is generated.
3. Granular Access Control
The authors introduce three distinct algorithms to define the workflows for Admins, Patients, and Doctors. This ensures that a doctor cannot simply "pull" data; they must be "granted" access by either the Admin or the Patient.

Experiments & Results: Efficiency Without Compromise
Testing was conducted using the AVISPA (Automated Validation of Internet Security Protocols and Applications) tool, specifically the OFMC and CL-ATSE backends, to prove the protocol's resistance to MIM and Replay attacks.
Performance Benchmarks
- Computation Speed: The total time for the user side is only 0.04414s, which is significantly lower than competitor schemes (like Sharif et al. at 0.1321s).
- Communication Overhead: With only two messages required for authentication (1504 bits total), the protocol preserves bandwidth and battery life.

Security Features
Unlike previous works, this approach provides a "clean sweep" of security features: Mutual Authentication, Anonymity, PFS, Scalability, and resistance to Privileged Insider and Stolen Device attacks.
Critical Analysis & Conclusion
The Takeaway
The paper successfully proves that modern healthcare security doesn't have to be slow. By moving the logic to the patient’s mobile device and using ECC, the system provides a robust defense-in-depth against increasingly sophisticated cyber-attacks.
Limitations & Future Work
While the protocol is efficient, it still relies on the central availability of a Cloud Server. The authors hint at looking into the Tactile Internet next—where latency becomes even more critical (sub-millisecond). Additionally, integrating this with Blockchain (as noted in their references) could potentially eliminate the "Single Point of Failure" of the cloud server entirely.
Final Thought
For developers and researchers in the m-Health space, this paper offers a rigorous template for using formal verification to ensure that "lightweight" doesn't mean "insecure."
