Ahmim, Marwa and Ouafi, Nour and Ullah, Insaf and Ahmim, Ahmed and Chefrour, Djalel and Almukhlifi, Reham (2025) LSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things. Computers, Materials and Continua, 85 (3). pp. 5093-5116. DOI https://doi.org/10.32604/cmc.2025.067641
Ahmim, Marwa and Ouafi, Nour and Ullah, Insaf and Ahmim, Ahmed and Chefrour, Djalel and Almukhlifi, Reham (2025) LSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things. Computers, Materials and Continua, 85 (3). pp. 5093-5116. DOI https://doi.org/10.32604/cmc.2025.067641
Ahmim, Marwa and Ouafi, Nour and Ullah, Insaf and Ahmim, Ahmed and Chefrour, Djalel and Almukhlifi, Reham (2025) LSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things. Computers, Materials and Continua, 85 (3). pp. 5093-5116. DOI https://doi.org/10.32604/cmc.2025.067641
Abstract
The Internet of Healthcare Things (IoHT) marks a significant breakthrough in modern medicine by enabling a new era of healthcare services. IoHT supports real-time, continuous, and personalized monitoring of patients’ health conditions. However, the security of sensitive data exchanged within IoHT remains a major concern, as the widespread connectivity and wireless nature of these systems expose them to various vulnerabilities. Potential threats include unauthorized access, device compromise, data breaches, and data alteration, all of which may compromise the confidentiality and integrity of patient information. In this paper, we provide an in-depth security analysis of LAP-IoHT, an authentication scheme designed to ensure secure communication in Internet of Healthcare Things environments. This analysis reveals several vulnerabilities in the LAP-IoHT protocol, namely its inability to resist various attacks, including user impersonation and privileged insider threats. To address these issues, we introduce LSAP-IoHT, a secure and lightweight authentication protocol for the Internet of Healthcare Things (IoHT). This protocol leverages Elliptic Curve Cryptography (ECC), Physical Unclonable Functions (PUFs), and Three-Factor Authentication (3FA). Its security is validated through both informal analysis and formal verification using the Scyther tool and the Real-Or-Random (ROR) model. The results demonstrate strong resistance against man-in-the-middle (MITM) attacks, replay attacks, identity spoofing, stolen smart device attacks, and insider threats, while maintaining low computational and communication costs.
| Item Type: | Article |
|---|---|
| Uncontrolled Keywords: | Internet of healthcare things (IoHT); authentication protocol; cryptanalysis; attacks |
| Subjects: | Z Bibliography. Library Science. Information Resources > ZZ OA Fund (articles) |
| Divisions: | Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
| SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
| Depositing User: | Unnamed user with email elements@essex.ac.uk |
| Date Deposited: | 04 Jun 2026 16:25 |
| Last Modified: | 04 Jun 2026 16:26 |
| URI: | http://repository.essex.ac.uk/id/eprint/42459 |
Available files
Filename: TSP_CMC_67641.pdf
Licence: Creative Commons: Attribution 4.0