智慧医疗(smart healthcare)是集人工智慧、物联网、云计算、大数据以及移动互联网、传感技术等新一代信息技术于一体,与传统医疗健康服务紧密融合而形成的新型医疗健康服务业态的总称。利用先进的物联网技术、互联网技术和移动通信技术等,通过智慧化手段,将与医疗、卫生、健康、服务相关的信息、设备、人员以及资源联结起来,并实现有效互动,确保人们及时获得可预防、可治疗的医疗服务,对实现我国互联网+医疗政策,提高城市生活质量有显著作用。目前,随着相关理论和技术的逐渐成熟,智慧医疗在逐渐改变人们的思维模式和生活方式。然而,智慧医疗系统具有异构融合、跨域、协同自治、动态变化、开放互联的网络特性,给其带来了巨大的信息安全和通信安全方面的挑战。因此,研究智慧医疗环境下的信息安全和通信安全技术对智慧城市的健康发展具有重要的意义。 本文围绕智慧医疗的数据安全存储、数据安全采集以及医疗设备信号通信安全技术展开了系统研究,所取得的主要成果如下: 一、对云环境下医疗大数据存储审计方案进行研究。针对云存储数据所有权和管理的分离,用户检验数据完整性困难的问题,提出一种基于自认证公钥系统的公共审计协议。安全分析表明,攻击者在采集的审计信息中提取不到用户密钥和用户数据。此外,该协议不仅能有效地抵抗签名伪造攻击,而且能有效地抵抗证明伪造攻击。与其他公开审计方案相比,基于自认证公钥系统的公共审计方案在存储开销、通信带宽和验证效率方面都有较大的提高。 二、对医疗大数据采集隐私性保护方法进行研究。物联网技术(IOT)在医疗服务领域的广泛使用,推动了智能医疗服务水平的显著提高。然而,也给数据收集带来了潜在的隐私威胁。在医疗服务系统中,健康及医疗数据通常包含患者的隐私信息,而这些隐私数据通常通过网络进行传播,如果这些隐私数据得不到妥善保护会导致用户隐私数据的泄露。因此,针对医疗服务系统的数据采集隐私保护方案越来越重要。本论文基于经典的(a,k)-匿名模型提出一种面向智慧医疗的数据采集隐私保护方案(PPDC),并采用客户端-服务器-用户(CS2U)模型对医疗服务系统进行威胁模型分析。在客户端,基于(a,k)-匿名模型的匿名原则生成抗攻击的匿名元组,并采用自底向上的聚类方法生成满足(a1,k1)-匿名原则的聚类分组。在服务端,采用泛化技术降低通信成本,然后基于非加权组平均法(UPGMA)对聚类进行合并,实现对(a1,k1)-匿名数据进行压缩,从而使数据满足更深层次的(a2,k2)-匿名隐私要求(a1≥a2,k2≥k1)。理论分析和实验结果表明,该方案具有良好的保密性和数据质量。 三、对医疗设备信号通信安全技术进行研究。基于差分相关的通信突发信号检测方法,分析了一种差分相关突发检测(DCBD)方法的理论性能,推导了漏检率和虚警率性能的解析表达式,考虑了承载消息的信号部分所引起的虚警,并证明了该虚警概率与纯噪声引起的虚警概率相近。基于理论分析结果,总结了该检测方法的特性。理论分析结果和仿真结果都表明,差分相关突发检测方法性能不受频偏影响,是一种常虚警(CFAR)检测方法,同时该方法的检测门限独立于信号幅度。这些特性意味着该方法对于突发检测而言非常实用。分析结果还对在不同信号条件下如何设置检测门限以满足检测性能要求给出了参考。 关键词:智慧医疗 物联网 云存储 数据安全 隐私保护 公共审计 自认证公钥 突发检测 差分相关
Smart healthcare is a new type of medical and health service industry that integrates artificial intelligence, Internet of things, cloud computing, big data, mobile Internet, sensor technology and other new generation information technologies, and is closely integrated with traditional medical and health services. Using the advanced Internet technology, Internet technology and mobile communication technology, etc., by means of wisdom will be related to health, health, health, services, equipment, personnel, information and resources, and realize the effective interaction, ensure people timely access to prevention, treatment, medical service, to realize our country Internet + medical policy, improve the urban quality of life have a significant effect.. Smart healthcare are gradually changing people's thinking mode and lifestyle with the gradual maturity of relevant theories and technologies. However, smart healthcare system has unique characteristics including heterogeneous integration, cross-domain, collaborative autonomy, dynamic changes and open interconnection raise security challenges for information security and communication security. Therefore, the research of information security and communication security technology is of great significance to the healthy development of smart healthcare. We focuses on the data security storage, data security collection and signal burst detection technology research of smart healthcare in this paper. The main contributions are as follows: 1、 A new public auditing protocol with self-certified public keys for medical data. Cloud storage can provide a way to effectively store and manage big data. However, due to the separation of data ownership and management, it is difficult for users to check the integrity of data in a traditional way, which leads to the introduction of the auditing techniques. In this paper, a novel public auditing protocol is proposed with self-certified public key system. The security analysis shows that attackers can neither derive user's secret key nor derive users' data from the collected auditing information in the presented scheme. Furthermore, it can effectively against not only the signature forging attacks, but also the proofs forging attacks. Compared with other public auditing scheme, our scheme based on the selfcertified public key system has been improved in storage overhead, communication bandwidth and verification efficiency. 2、 A Privacy-Preserving Scheme for Data Collection in Healthcare Services Systems. The widely use of IoT technologies in healthcare services has pushed forward medical intelligence level of services. However, it also brings potential privacy threat to the data collection. In healthcare services system, health and medical data that contains privacy information are often transmitted among networks, and such privacy information should be protected. Therefore, there is a need for privacy-preserving data collection (PPDC) scheme to protect clients (patients) data. We adopt (a,k)-anonymity model as privacy pretection scheme for data collection, and propose a novel anonymity-based PPDC method for healthcare services in this paper. The threat model is analyzed in the client-server-to-user (CS2U) model. On client-side, we utilize (a,k)-anonymity notion to generate anonymous tuples which can resist possible attack, and adopt a bottom-up clustering method to create clusters that satisfy a base privacy level of (a₁,k₁)-anonymity. On server-side, we reduce the communication cost through generalization technology, and compress (a₁,k₁)-anonymous data through an UPGMA-based cluster combination method to make the data meet the deeper level of privacy (a₂,k₂)-anonymity (a₁≥a₂, k₂≥k₁). Theoretical analysis and experimental results prove that our scheme is effective in privacy-preserving and data quality. 3、Research on signal communication security technology of medical equipment. Performance Analysis of a Diferential-Correlation Based Burst Detection Method. Burst detection is an initial step for burst-mode demodulation. The theoretical performance of a diferential-correlation based burst detection (DCBD) method is analyzed. The expressions of miss detection probability and false alarm probability (FAP) of this method are derived. The FAP arisen from message signals are also considered and proved to be close to the FAP arisen from noise signals, which is not covered in other similar works. Based on the theoretical analysis, the properties of the detection method are concluded. Both the analytical analysis and the simulation results show that DCBD is robust to frequency ofset and is a CFAR method. Furthermore, the detection threshold is independent of the signal amplitude. These properties indicate that DCBD is very proper and practical for burst detection. The analytical results also give references how the threshold should be set to meet the system performance requirements for various signal conditions. Keywords: Smart Healthcare; Internet of Thing; Could Storage; Data Security; Privacy Protection; Public Auditing; Self-certified Public Key; Burst Detection; Differential-Correlation;