1. Introduction
The IoHT has emerged as a revolutionary paradigm in modern healthcare which provides seamless connectivity between medical devices, sensors, wearable systems and healthcare applications via the internet. This interconnected ecosystem allows real-time monitoring, early diagnosis, personalised treatment and efficient patient care [
1,
2,
3,
4,
5]. The IoHT enhances access to healthcare, reduces operational expenses, and improves patient outcomes through remote patient monitoring and continuous health tracking, particularly in remote and underprivileged regions [
6,
7,
8]. In addition, the integration of advanced technologies such as cloud computing, artificial intelligence, and wireless connectivity has improved IoHT functionalities, facilitating intelligent and data-driven healthcare services.
The fast adoption of the IoHT is indicated by its increasing worldwide market (
Table 1) [
3]. The Internet of Things (IoT) market in the healthcare industry is projected to grow from an estimated United States Dollar (USD) ~44 billion in 2023 to over USD ~170 billion by 2030. The growth is primarily attributable to the high adoption of smart medical devices, wearable technology and smartphones for the continuous monitoring and management of patients’ health.
The IoHT offers many advantages, but its extensive deployment raises severe security and privacy concerns [
5,
9,
10,
11,
12,
13]. This is because healthcare data is very private and the infrastructure is very connected. Medical data is extremely sensitive and when it is leaked it can cause serious issues including a breakdown of trust in healthcare systems, decreased patient safety, and legal issues. IoHT environments are very different from each other and very dynamic. This makes them vulnerable to cyber threats such as data breaches, malware attacks, replay attacks, and insecure communication protocols.
The increasing number of cyberattacks against healthcare infrastructure further emphasises the need for secure IoHT systems [
5,
14,
15,
16,
17,
18,
19]. There have been reports of billions of attack attempts on IoHT devices each year. Connected medical devices are frequently the target because of their limited security capabilities. As IoHT systems are directly related to human lives, it is not only a technical requirement but also a societal and ethical requirement to ensure their security. In healthcare, malfunctioning software can seriously jeopardise the health of patients. Possible risks are illustrated by past events such as the Therac-25 accelerator accidents [
3,
20,
21,
22,
23,
24] and the possible re-configuration of pacemakers [
4,
25,
26]. Furthermore, unpredictable behaviour of a drug delivery system can cause serious problems with availability, endangering or even killing patients [
5,
27,
28,
29].
The resource-constrained nature of WSNs makes them particularly vulnerable to attacks, which are the backbone of IoHT systems [
6,
30,
31,
32,
33,
34]. Sensor nodes have limited memory and computational and communication bandwidths, which makes the implementation of classical cryptographic techniques difficult. Furthermore, these nodes are usually deployed in open or unattended environments, which makes them vulnerable to physical and network-based attacks [
7,
35,
36,
37,
38]. These challenges emphasise the necessity of lightweight, efficient, and robust cryptographic solutions for IoHT-enabled WSNs.
The existing cryptography techniques have some limitations in the scenario of the IoHT. Traditional encryption methods such as the AES are very secure but are resource intensive, making them impractical for resource-constrained devices. Key management is difficult, and the computational complexity is high for asymmetric cryptographic algorithms. Lightweight cryptography typically sacrifices some security in exchange for efficiency, for example, by offering limited support for authentication and data integrity [
8,
39,
40,
41,
42,
43,
44].
This results in an inherent trade-off between security and performance that continues to be a major research challenge in IoHT systems. A practical deployment involves a trade-off between strong security mechanisms and resource efficiency [
45,
46]. Existing solutions either provide high security by incurring higher computational costs or provide efficiency by sacrificing protection [
47,
48]. Thus, none of the existing solutions satisfy the complete requirements of IoHT environments. Therefore, there is a great need for:
A lightweight cryptographic framework providing confidentiality, integrity, and authentication;
A scalable and efficient solution compatible with resource-constrained WSN nodes;
A robust evaluation methodology capable of handling uncertainty and multiple decision criteria;
A systematic comparative framework for assessing performance against established cryptographic techniques.
To address these technical gaps is crucial in the development of next-generation secure IoHT systems. To tackle the identified challenges, this study evaluates the efficiency of the BitCube Cryptosystem (BC) [
23], which is a lightweight and novel cryptographic architecture, designed specifically for the IoHT-enabled WSNs [
6]. The BitCube approach uses structured transformations based on cube operations for strong security with less computational complexity, so it is suitable for constrained environments.
In this MCDM framework, HF AHP and TOPSIS are combined to provide a comprehensive and objective evaluation. The HF AHP–TOPSIS approach was selected because experts often hesitate among multiple assessment values when evaluating IoT cryptographic algorithms across conflicting criteria, such as security, computational efficiency, energy consumption, memory requirements, and scalability. Unlike conventional fuzzy approaches, hesitant fuzzy sets explicitly capture this hesitation by allowing multiple membership values for a single assessment. Compared with other fuzzy sets, the proposed approach offers a better balance between uncertainty representation, computational efficiency, and decision-making accuracy. Therefore, it is well suited for evaluating lightweight cryptographic algorithms in IoT environments. The main contributions of this paper are summarized as follows:
The BC is a new cryptographic primitive for IoHT security that goes beyond substitution–permutation structures. It is a lightweight design based on a Rubik’s cube with rotational transformations.
Innovative evaluation framework: This is the first use of a hybrid HF AHP–TOPSIS model for cryptosystem evaluation, which enables multi-criteria trade-offs and nuanced handling of uncertainty in IoHT security decision-making.
Complete comparative analysis: A comprehensive benchmarking study of BitCube against seven popular lightweight cryptosystems demonstrates its enhanced security strength, scalability, and execution speed in IoHT environments with limited resources.
Empirical validation in the context of healthcare: Experimental findings support BitCube’s applicability for IoHT-enabled WSNs and establish it as a workable security solution tailored to the particular limitations of medical sensing equipment.
Future-focused adaptability: The work ensures relevance for upcoming IoHT deployments by laying the groundwork to grow BitCube to energy-efficient, real-time, and hardware-level implementations.
The present study is structured around four core research questions to systematically guide the evaluation of the proposed approach. The first step is to compare the performance of the BC [
23] with the traditional and lightweight cryptographic algorithms including AES and IoHT-oriented cyphers in terms of various metrics, including security strength, computational efficiency, memory footprint, and general resource demands, to evaluate its suitability for resource-constrained IoHT environments. Second, the study demonstrates that the HF AHP is capable of effectively managing the uncertainty and hesitation of experts during the prioritisation of evaluation criteria and results in more reliable decision-making for cryptographic algorithm selection. Thirdly, it studies the ranking of different cryptographic techniques applying the TOPSIS and determines the relative position of the BC among the competing methods. Finally, the study investigates the practical feasibility of BitCube for deployment in resource-constrained scenarios such as IoHT systems by analysing its overall performance and the trade-offs between security and efficiency metrics.
The remainder of this paper is organized as follows.
Section 2 presents the materials and methods employed in this study. Specifically,
Section 2.1 reviews the most relevant recent literature, while
Section 2.2 describes the BitCube Cryptosystem, including its functional requirements (
Section 2.2.1) and hierarchical evaluation structure (
Section 2.2.2).
Section 2.3 provides a comprehensive description of the proposed methodology, which integrates HF, AHP, and TOPSIS.
Section 3 presents the experimental results, sensitivity analysis, and comparative evaluation with alternative decision-making methods. Finally,
Section 4 concludes the paper by summarizing the key findings, discussing the implications of the study, and outlining directions for future research.
3. Numerical Analysis and Results
A comprehensive comparative analysis was conducted to evaluate the effectiveness and practical utility of the proposed BitCube cryptographic framework in comparison with existing cryptographic solutions [
24]. To ensure an objective assessment, a systematic numerical evaluation approach was adopted, providing quantitative insights into the performance, efficiency, and applicability of the considered frameworks. The TOPSIS was employed as the primary ranking mechanism to prioritise competing cryptographic alternatives based on multiple evaluation criteria [
40]. The framework for achieving the highest overall score was identified as the most suitable solution, reflecting its superior performance across the selected criteria. To support this evaluation, a hierarchical decision structure was developed, enabling a systematic assessment of existing research contributions. The AHP was applied within a hierarchical framework to ensure a consistent, transparent, and logically structured decision-making process [
41,
42].
To further enhance the robustness of the evaluation, the HF AHP was incorporated into the proposed methodology. The HF AHP is a widely recognized MCDM technique that effectively handles uncertainty, ambiguity, and hesitation in expert judgments, thereby producing more reliable priority rankings [
43]. In this study, the HF AHP was utilised to determine the relative importance of the key evaluation criteria associated with lightweight, secure, and energy-efficient cryptographic frameworks for IoHT environments. By accommodating multiple possible preference values from experts, the proposed approach provides a more realistic representation of human decision-making and establishes a robust decision-support framework for researchers and practitioners working in IoHT security [
44].
The analysis was conducted using data obtained from a carefully selected panel of 48 experts representing both academia and industry. The expert group comprised cybersecurity specialists, IoHT architects, and researchers with substantial experience in IoHT-enabled WSNs [
36]. A purposive sampling approach was adopted to ensure that all participants possessed relevant and demonstrated domain expertise. Each expert had between 10 and 15 years of professional experience and satisfied clearly defined inclusion criteria, including proven competence in cybersecurity or IoHT applications, prior involvement in related research or system development, and willingness to contribute to structured pairwise comparison evaluations. To enhance transparency, reproducibility, and methodological clarity,
Appendix A presents a representative sample of the questionnaire used for expert elicitation, while the complete dataset supporting the analysis has been provided as a
Supplementary File accompanying this manuscript [
45].
The participating experts completed pairwise comparison matrices for all evaluation criteria and sub-criteria using TFNs and standardized hesitant fuzzy rating scales. This structured assessment process enhanced objectivity and reduced the potential influence of individual bias [
38]. To maintain consistency in responses, a dedicated HF AHP evaluation worksheet was provided to all participants. Established methodologies reported in previous studies [
36,
37,
38] were followed, while quantitative performance measures were also incorporated to strengthen the reliability of the evaluation. The resulting dataset comprised expert judgments, aggregated hesitant fuzzy assessments, criterion weights, and performance evaluations of the cryptographic alternatives under consideration [
46].
The computational analysis was performed by implementing Equations (1)–(16), which were used to construct the hesitant fuzzy pairwise comparison matrix, perform defuzzification, and derive the normalized criterion weights (
Table 12). The hierarchical structure adopted for the evaluation, together with the positioning of the proposed BitCube framework within the decision model, is illustrated in
Figure 2. The final criterion weights and the corresponding defuzzified pairwise comparison matrix are presented in
Table 13 and
Figure 4. The overall ranking process was achieved by integrating expert judgments with the proposed computational framework [
47]. To ensure methodological rigor, accuracy, and reproducibility, the AHP calculations were conducted using Super Decisions Version 3.2, while fuzzy computations were performed according to the proposed HF AHP methodology [
48].
Subsequently, the HF-TOPSIS methodology was implemented using Equations (17)–(26). The results of this stage are presented in
Table 14 (subjective cognition results),
Table 15 (normalized fuzzy decision matrix), and
Table 16 (weighted normalized decision matrix). The final ranking outcomes, including the closeness coefficients and ranking scores, are reported in
Table 17 and illustrated in
Figure 5. The results demonstrate that the proposed BitCube framework consistently achieves a highly competitive ranking and emerges as the most suitable alternative among the evaluated cryptographic schemes. These findings validate the effectiveness of the proposed framework in delivering secure, lightweight, and energy-efficient cryptographic protection for resource-constrained IoHT environments.
Table 17 presents the final outcomes of the Hesitant Fuzzy AHP–TOPSIS framework by evaluating seven cryptographic alternatives based on their distances from the positive ideal solution (Distance
+) and negative ideal solution (Distance
−), culminating in the computation of the closeness coefficient and final ranking.
The results clearly indicate that the A7 achieves the highest performance with a closeness coefficient of 0.6580, ranking first among all alternatives. This outcome is primarily attributed to its lowest Distance+ value (0.3180) and the highest Distance− value (0.6120), indicating that BitCube is the closest to the ideal solution while being farthest from the negative ideal solution. This demonstrates its superior balance across multiple criteria such as processing efficiency, energy efficiency, and confidentiality, which are critical in IoHT environments.
Among the benchmark schemes, A4 ranks second with a closeness coefficient of 0.5760, reflecting its strong cryptographic strength and relatively efficient performance in constrained environments. A1 follows in third place (0.5630), showing competitive efficiency but slightly lower overall balance compared to A4.
A5 occupies the fourth position, indicating that although it provides strong security through hybridization, the additional computational overhead reduces its overall suitability in resource-constrained IoHT settings. A2 and A3 rank fifth and sixth, respectively, reflecting moderate performance but weaker suitability in terms of modern IoHT requirements such as energy efficiency and scalability. A6 ranks last (0.4460), mainly due to its comparatively higher Distance+ and lower Distance− values, suggesting weaker overall alignment with the ideal solution in this multi-criteria evaluation context.
The ranking results demonstrate a clear separation between the proposed BitCube Cryptosystem and existing cryptographic methods, highlighting its superior capability in achieving an optimal trade-off among security strength, computational efficiency, and resource constraints.
Figure 5 visually reinforces this ranking pattern, showing a consistent dominance of BitCube over competing alternatives.
Importantly, the monotonic relationship between Distance
+, Distance
−, and the closeness coefficient confirms the correctness and stability of the TOPSIS computation, thereby validating the robustness of the proposed hesitant fuzzy decision-making framework for IoHT security evaluation. Further, the sensitivity analysis (
Table 18 and
Figure 6) evaluates the stability of the proposed HF AHP–TOPSIS framework by varying the criterion weights and observing consistent ranking behaviour of all alternatives.
Table 18 presents a comprehensive sensitivity analysis of the proposed HF AHP–TOPSIS framework, evaluating the stability of the ranking results under systematic variation of the individual criterion weights. When the weight of C1 (processing efficiency) is varied, the weights of the remaining criteria are proportionally adjusted to ensure that the total weight remains equal to one. Any increase or decrease in the weight of C1 is balanced by proportionally scaling the weights of C2–C8, thereby maintaining consistency in the overall decision-making framework and preventing ambiguity in the distribution of criterion importance. This analysis serves as an important validation step to examine the robustness, consistency, and reliability of the decision-making model in IoHT environments.
The results demonstrate that the ranking structure remains highly stable across all sensitivity scenarios. In all cases, A7 consistently achieves the highest closeness coefficient, ranging from 0.651 to 0.693, thereby maintaining rank 1 across all perturbations. This confirms that the superiority of BitCube is not dependent on a specific weighting configuration but remains stable under different decision priorities.
From a validation perspective, the observed limited variation in closeness coefficients indicates that the model exhibits low sensitivity to moderate changes in expert preference weights, which is a desirable property in MCDM frameworks. This stability validates the reliability of the HF AHP–TOPSIS approach in handling uncertainty and hesitation in expert judgments, particularly in IoHT security evaluation where subjective assessments are inherently variable.
Among all scenarios, BitCube achieves its highest performance when C8 is emphasized (0.693), followed closely by C6 (0.689) and C4 (0.681). These results further validate that BitCube is especially robust in security-critical conditions, which are the primary requirements in healthcare-oriented sensor networks. Even under the most conservative scenario (variation in average execution time C3), BitCube maintains a strong closeness coefficient of 0.651, confirming its consistent optimal positioning across all tested conditions.
The comparative alternatives (A1–A6) also demonstrate stable but lower performance trends. A4 consistently ranks second, indicating strong cryptographic strength but slightly reduced efficiency in constrained environments. A1 generally occupies the third position, while A5, A2, and A3 follow with moderate performance variations. A6 remains consistently the weakest alternative across all scenarios, validating its comparatively lower suitability for IoHT applications.
Importantly, the narrow spread in closeness coefficient values across all alternatives confirms the internal consistency and numerical stability of the HF AHP–TOPSIS model. This also validates that the proposed decision-making framework does not produce unstable rankings under slight perturbations in weights, thereby reinforcing its applicability for real-world uncertain environments.
Furthermore, the validation results corroborate the findings from the main TOPSIS evaluation (
Table 17), demonstrating convergent validity of the proposed approach. The consistency between baseline rankings and sensitivity-based outcomes confirms that the model is both methodologically sound and decision-robust, making it suitable for evaluating cryptographic systems in resource-constrained IoHT networks.
Figure 6 visually supports these observations by illustrating the stability of rankings across all scenarios, clearly showing the persistent dominance of the BitCube Cryptosystem and reinforcing the reliability of the proposed HF AHP–TOPSIS framework.
Table 19 presents a comprehensive comparative evaluation of the proposed cryptographic alternatives using five MCDM approaches, namely HF AHP–TOPSIS, Fuzzy AHP–TOPSIS, Classical AHP–TOPSIS, Fuzzy Analytic Network Process (ANP)–TOPSIS, and Classical ANP–TOPSIS.
The main objective of this comparative study is to examine the robustness, consistency, and validation strength of the proposed framework under different decision-making paradigms.
The results clearly show that A7 consistently achieves the highest closeness coefficient across all methods, ranging from 0.6129 to 0.6580, and retains rank 1 in every case. This demonstrates strong method-invariant stability, confirming that the superiority of BitCube is not dependent on a specific MCDM formulation but is consistently observed across both hierarchical (AHP-based) and network-based (ANP-based) structures, as well as fuzzy and classical environments.
To further validate the reliability of the proposed results, a correlation analysis was conducted among the ranking outputs of all MCDM methods. The results show a very high positive correlation (Pearson’s r > 0.97) between HF AHP–TOPSIS and the other approaches, indicating strong agreement in ranking behaviour. Similarly, Spearman’s rank correlation coefficients (ρ > 0.95) confirm that the ordering of alternatives remains highly consistent across all methods. This high correlation confirms the convergent validity of the proposed HF AHP–TOPSIS framework and demonstrates that the ranking stability is statistically robust rather than coincidental.
Among the benchmark schemes, A4 consistently ranks second across all methods, followed by A1. The intermediate alternatives—A5, A2, and A3—show minor variations in closeness coefficients across different MCDM techniques but maintain relatively stable ranking positions. A6 consistently ranks last, reinforcing its limited suitability for IoHT environments.
From a validation standpoint, the high inter-method correlation values (r > 0.97, ρ > 0.95) confirm that the proposed decision model is highly reliable and not sensitive to the choice of MCDM methodology. This strengthens the external validity of the study and confirms that the obtained rankings are both reproducible and stable under different analytical frameworks.
Additionally, the slightly higher discrimination capability observed in the HF AHP–TOPSIS approach demonstrates its improved ability to handle uncertainty and hesitation in expert judgments, leading to more expressive and realistic decision outcomes. Importantly, this enhancement does not alter the ranking structure, further reinforcing the robustness of the model.
Figure 7 visually supports these findings by illustrating the consistent performance trend across all methods, clearly showing the dominance of BitCube and the strong alignment among all MCDM approaches. Overall, the combined evidence from the ranking stability, correlation analysis, and method agreement validates the methodological soundness and practical reliability of the proposed HF AHP–TOPSIS framework for IoHT security evaluation.
4. Conclusions
This study performed a comprehensive review of cryptographic frameworks for IoHT environments, with a special focus on the proposed BC. Through integrating the HF AHP with TOPSIS and extending the analysis to multiple MCDM approaches, the study provided a solid and systematic framework for assessing lightweight, secure, and energy-efficient cryptographic solutions. The combination of expert-driven evaluation, hierarchical modelling, and quantitative analysis offers a reliable and practical decision-support mechanism for the selection of suitable cryptographic techniques for resource-constrained healthcare systems.
The analysis shows that the BitCube framework always received the maximum proximity coefficient at the first evaluation and maintained the top position in the sensitivity analysis and comparing analysis with other MCDM techniques. The results demonstrate that BitCube offers a fair trade-off between processor efficiency, energy consumption, memory usage, security strength and computational complexity. The constancy of the rankings for varied criteria weights and decision-making procedures proves the robustness and usefulness of the evaluation system. The remaining cryptosystems showed moderate to low application in IoHT-enabled WSN scenarios. Lightweight Masked AES and ECC are the second and third most applicable cryptosystems in IoHT-enabled WSN scenarios.
These encouraging results notwithstanding, there are some limitations to the study that should be noted.
First, the evaluation is largely based on expert judgements, which are structured and validated by fuzzy logic, but it may be subjectively biased.
Second, the performance metrics used in the analysis are simulated or theoretical, not based on real-world deployment data, which may affect the practical generalisation of the results.
Third, the criteria we chose are comprehensive but might not account for all emerging requirements such as scalability, interoperability, and resistance to advanced cyber threats.
The research also concentrates on a limited range of cryptographic alternatives that might not cover the whole spectrum of contemporary cryptographic innovations.
These limitations can be mitigated in future work by including real-time experimental validation of the proposed BitCube framework in practical IoHT deployments. Broadening the criteria for evaluation such as key management cost, side-channel resistance, randomness requirements, throughput, code size, and regulatory suitability to cover scalability, adaptability, and resilience to quantum attacks would add depth to the analysis. Furthermore, the employment of advanced decision-making techniques, such as hybrid AI-driven MCDM models or machine learning-based optimisation methods, could enhance the accuracy and automation of the evaluation process. Future research can also explore the applicability of the proposed framework in other domains such as smart grids, industrial IoT, and cyber–physical systems, thereby extending its impact beyond healthcare.
The proposed BC, with the support of a rigorous and validated evaluation framework, is a very effective solution to secure and efficient cryptographic implementation in IoHT environments. Besides the new cryptographic approach, the work proposes a scalable and reliable methodology to evaluate security frameworks in new technological ecosystems.