Exploring Authentication Protocols for Secure and Efficient Internet of Medical Things Systems
Abstract
1. Introduction
- (i)
- Conducting systematic and objective comparative analysis of recent IoMT security protocols to quantitatively evaluate their performance and security metrics.
- (ii)
- Verifying the recent IoMT security protocols to derive essential security requirements for IoMT environments.
- (iii)
- Providing security guidelines for future research based on the results of comparative analysis and security assessment.
2. Background
2.1. IoT and IoMT
2.2. IoMT Communication Protocols
3. Recent Research
3.1. Literature Review
3.2. Evaluation
4. Security Verification
4.1. SVO Logic
- Modus Ponens: From and infer .
- Necessitation: From infer .
4.2. Scyther
5. Discussion
6. Conclusions
Supplementary Materials
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
Abbreviations
| 3ECAP | Three-Factor Efficient and Cost-Aware Authentication Protocol |
| 3-Factor | Three-Factor Authentication |
| 4G/5G | 4th Generation/5th Generation |
| AES | Advanced Encryption Standard |
| AVISPA | Automated Validation of Internet Security Protocols and Applications |
| BAKMP | Blockchain-based Authentication and Key Management Protocol |
| BAN-Logic | Burrows–Abadi–Needham Logic |
| BCI | Brain–Computer Interface |
| BLE | Bluetooth Low Energy |
| BYOD | Bring Your Own Device |
| CE | Consumer Electronics |
| CGM | Continuous Glucose Monitoring |
| CoAP | Constrained Application Protocol |
| CRT | Chinese Remainder Theorem |
| CVE | Common Vulnerabilities and Exposures |
| CVP | Closest Vector Problem |
| DBS | Deep Brain Stimulator |
| DH | Diffie–Hellman |
| ECC | Elliptic Curve Cryptography |
| ECG | Electrocardiogram |
| EHRs | Electronic Health Records |
| ESL | Ephemeral Secret Leakage |
| HL7 | Health Level Seven |
| ICDs | Implantable Cardioverter Defibrillators |
| IMD | Implantable Medical Device |
| IoMT | Internet of Medical Things |
| IoMT-SAF | Internet of Medical Things – Security Assessment Framework |
| IoT | Internet of Things |
| IoWD | Internet of Wearable Devices |
| L2FAK | Lightweight Two-Factor Authentication Framework |
| LBC | Lightweight Lattice-Based Cryptography |
| LTE | Long Term Evolution |
| LVADs | Left Ventricular Assist Devices |
| LWE | Learning with Errors |
| M2M | Machine-to-Machine |
| MASK | Mutual Authentication and Secret Key |
| MDs | Medical Devices |
| MITM | Man-In-The-Middle (Attack) |
| ML | Machine Learning |
| MQTT | Message Queuing Telemetry Transport |
| NFC | Near Field Communication |
| NFT | Non-Fungible Token |
| ProVerif | Protocol Verification Tool |
| PSLA2P | Provably Secured Lightweight Authenticated Key Agreement Protocol |
| PUF | Physically Unclonable Function |
| QoS | Quality of Service |
| RFID | Radio-Frequency Identification |
| RSA | Rivest–Shamir–Adleman (Public Key Cryptosystem) |
| SCS | Spinal Cord Stimulator |
| SDN | Software Defined Networking |
| Slither | Solidity Static Analysis Tool |
| S-IoMT | Smart Internet of Medical Things |
| SpO2 | Peripheral Capillary Oxygen Saturation |
| SVP | Shortest Vector Problem |
| TA | Trusted Authority |
| VNS | Vagus Nerve Stimulator |
| Wi-Fi | Wireless Fidelity |
| XAI | Explainable Artificial Intelligence |
| XOR | Exclusive OR |
Appendix A. Formal Verification Result for Abdussami et al. [44]
| Derivation | |
Appendix B. Formal Verification Result for Qiu et al. [45]
| Derivation | |
Appendix C. Formal Verification Result for Lo et al. [46]
| Derivation | |
Appendix D. Formal Verification Result for Masud et al. [47]
| Derivation | |
Appendix E. Formal Verification Result for Miao et al. [48]
| Derivation | |
Appendix F. Formal Verification Result for Garg et al. [49]
| Derivation | |
Appendix G. Formal Verification Result for Pradhan et al. [50]
| Derivation | |
Appendix H. Formal Verification Result for Gautam et al. [51]
| Derivation | |
Appendix I. Formal Verification Result for Su et al. [53]
| Derivation | |
Appendix J. Formal Verification Result for Deebak et al. [54]
| Derivation | |
References
- Jain, S.; Nehra, M.; Kumar, R.; Dilbaghi, N.; Hu, T.; Kumar, S.; Kaushik, A.; Li, C.z. Internet of medical things (IoMT)-integrated biosensors for point-of-care testing of infectious diseases. Biosens. Bioelectron. 2021, 179, 113074. [Google Scholar] [CrossRef] [PubMed]
- Xenofontos, C.; Zografopoulos, I.; Konstantinou, C.; Jolfaei, A.; Khan, M.K.; Choo, K.K.R. Consumer, commercial, and industrial iot (in) security: Attack taxonomy and case studies. IEEE Internet Things J. 2021, 9, 199–221. [Google Scholar] [CrossRef]
- Mejía-Granda, C.M.; Fernández-Alemán, J.L.; Carrillo-de Gea, J.M.; García-Berná, J.A. Security vulnerabilities in healthcare: An analysis of medical devices and software. Med Biol. Eng. Comput. 2024, 62, 257–273. [Google Scholar] [CrossRef]
- He, P.; Huang, D.; Wu, D.; He, H.; Wei, Y.; Cui, Y.; Wang, R.; Peng, L. A survey of internet of medical things: Technology, application and future directions. Digit. Commun. Netw. 2024; in press. [Google Scholar] [CrossRef]
- Shivagangatharani, B.; Rabiya, M.S. Enabling Technologies in IoMT Smart Healthcare: A Survey. In Proceedings of the 2024 10th International Conference on Communication and Signal Processing (ICCSP), Melmaruvathur, India, 12–14 April 2024; pp. 665–670. [Google Scholar]
- Gkonis, P.; Giannopoulos, A.; Trakadas, P.; Masip-Bruin, X.; D’Andria, F. A survey on IoT-edge-cloud continuum systems: Status, challenges, use cases, and open issues. Future Internet 2023, 15, 383. [Google Scholar] [CrossRef]
- Osama, M.; Ateya, A.A.; Sayed, M.S.; Hammad, M.; Pławiak, P.; Abd El-Latif, A.A.; Elsayed, R.A. Internet of medical things and healthcare 4.0: Trends, requirements, challenges, and research directions. Sensors 2023, 23, 7435. [Google Scholar] [CrossRef]
- Abbas, T.; Khan, A.H.; Kanwal, K.; Daud, A.; Irfan, M.; Bukhari, A.; Alharbey, R. IoMT-Based Healthcare Systems: A Review. Comput. Syst. Sci. Eng. 2024, 48, 871–895. [Google Scholar] [CrossRef]
- Sindhuja, R. A survey of Internet of Medical Things (IoMT) applications, architectures and challenges in smart healthcare systems. In Proceedings of the 1st ITM Web of Conferences, Coimbatore, India, 23–24 June 2023; EDP Sciences: Les Ulis, France, 2023; Volume 56, p. 05013. [Google Scholar]
- Lu, T.; Ji, S.; Jin, W.; Yang, Q.; Luo, Q.; Ren, T.L. Biocompatible and long-term monitoring strategies of wearable, ingestible and implantable biosensors: Reform the next generation healthcare. Sensors 2023, 23, 2991. [Google Scholar] [CrossRef]
- Guo, Y.; Liu, X.; Peng, S.; Jiang, X.; Xu, K.; Chen, C.; Wang, Z.; Dai, C.; Chen, W. A review of wearable and unobtrusive sensing technologies for chronic disease management. Comput. Biol. Med. 2021, 129, 104163. [Google Scholar] [CrossRef] [PubMed]
- Özkartal, T.; Demarchi, A.; Caputo, M.L.; Baldi, E.; Conte, G.; Auricchio, A. Perioperative management of patients with cardiac implantable electronic devices and utility of magnet application. J. Clin. Med. 2022, 11, 691. [Google Scholar] [CrossRef] [PubMed]
- Varshney, A.S.; DeFilippis, E.M.; Cowger, J.A.; Netuka, I.; Pinney, S.P.; Givertz, M.M. Trends and outcomes of left ventricular assist device therapy: JACC focus seminar. J. Am. Coll. Cardiol. 2022, 79, 1092–1107. [Google Scholar] [CrossRef] [PubMed]
- Wu, Y.C.; Liao, Y.S.; Yeh, W.H.; Liang, S.F.; Shaw, F.Z. Directions of deep brain stimulation for epilepsy and Parkinson’s disease. Front. Neurosci. 2021, 15, 680938. [Google Scholar] [CrossRef] [PubMed]
- Lam, C.M.; Latif, U.; Sack, A.; Govindan, S.; Sanderson, M.; Vu, D.T.; Smith, G.; Sayed, D.; Khan, T. Advances in spinal cord stimulation. Bioengineering 2023, 10, 185. [Google Scholar] [CrossRef] [PubMed]
- Wang, C.; Wu, B.; Lin, R.; Cheng, Y.; Huang, J.; Chen, Y.; Bai, J. Vagus nerve stimulation: A physical therapy with promising potential for central nervous system disorders. Front. Neurol. 2024, 15, 1516242. [Google Scholar] [CrossRef]
- Ahmed, A.; Taj, I.; Farhan, K.; Tariq, B.; Raufi, N. Revolutionizing diabetes care: New insulin pump and algorithm-based software for automatic insulin delivery. IJS Glob. Health 2024, 7, e0431. [Google Scholar] [CrossRef]
- Schaepelynck, P.; Renard, E.; Jeandidier, N.; Hanaire, H.; Fermon, C.; Rudoni, S.; Catargi, B.; Riveline, J.P.; Guerci, B.; Millot, L.; et al. A recent survey confirms the efficacy and the safety of implanted insulin pumps during long-term use in poorly controlled type 1 diabetes patients. Diabetes Technol. Ther. 2011, 13, 657–660. [Google Scholar] [CrossRef]
- Tchoe, H.J.; Shin, H.W.; Shin, C.M.; Lim, C.M. Assisted breathing with a diaphragm pacing system: A systematic review. Yonsei Med. J. 2020, 61, 1024. [Google Scholar]
- Islam, A.S.; Pingree, G.; Chafin, A.; Fitzpatrick IV, T.H.; Nord, R.S. Respiratory sensing lead malfunction in upper airway stimulation: A single institution report. Laryngoscope 2024, 134, 1479–1484. [Google Scholar] [CrossRef]
- Kim, H.; Ahn, J.; Rhee, J.; Ahn, S. Application of wireless power transfer technology to implantable medical devices. In Proceedings of the 2022 IEEE MTT-S International Microwave Biomedical Conference (IMBioC), Suzhou, China, 16–18 May 2022; pp. 299–301. [Google Scholar]
- Catuogno, L.; Galdi, C. Implantable Medical Device Security. Cryptography 2024, 8, 53. [Google Scholar] [CrossRef]
- Köhler, C.; Bartschke, A.; Fürstenau, D.; Schaaf, T.; Salgado-Baez, E. The Value of Smartwatches in the Health Care Sector for Monitoring, Nudging, and Predicting: Viewpoint on 25 Years of Research. J. Med. Internet Res. 2024, 26, e58936. [Google Scholar] [CrossRef]
- Perez-Guzman, M.C.; Shang, T.; Zhang, J.Y.; Jornsay, D.; Klonoff, D.C. Continuous glucose monitoring in the hospital. Endocrinol. Metab. 2021, 36, 240–255. [Google Scholar] [CrossRef]
- Liu, W.; Zhang, J.; Li, C. Design of intelligent wearable equipment based on real-time dynamic ECG-monitoring system. Am. J. Transl. Res. 2023, 15, 6413. [Google Scholar]
- Wong, S.H.D.; Deen, G.R.; Bates, J.S.; Maiti, C.; Lam, C.Y.K.; Pachauri, A.; AlAnsari, R.; Bělskỳ, P.; Yoon, J.; Dodda, J.M. Smart skin-adhesive patches: From design to biomedical applications. Adv. Funct. Mater. 2023, 33, 2213560. [Google Scholar] [CrossRef]
- Zhang, J.; Li, J.; Huang, Z.; Huang, D.; Yu, H.; Li, Z. Recent progress in wearable brain–computer interface (BCI) devices based on electroencephalogram (EEG) for medical applications: A review. Health Data Sci. 2023, 3, 0096. [Google Scholar] [CrossRef]
- Huang, M.; Peng, Q.; Zhu, X.; Deng, T.; Cao, R.; Liu, W. Ensuring Trustworthy and Secure IoT: Fundamentals, Threats, Solutions, and Future Hotspots. Comput. Netw. 2025, 263, 111218. [Google Scholar] [CrossRef]
- Lombardi, M.; Pascale, F.; Santaniello, D. Internet of things: A general overview between architectures, protocols and applications. Information 2021, 12, 87. [Google Scholar] [CrossRef]
- Mrabet, H.; Belguith, S.; Alhomoud, A.; Jemai, A. A survey of IoT security based on a layered architecture of sensing and data analysis. Sensors 2020, 20, 3625. [Google Scholar] [CrossRef] [PubMed]
- Calderón, D.; Folgado, F.J.; González, I.; Calderón, A.J. Implementation and experimental application of industrial IoT architecture using automation and IoT Hardware/Software. Sensors 2024, 24, 8074. [Google Scholar] [CrossRef]
- Koulouras, G.; Katsoulis, S.; Zantalis, F. Evolution of Bluetooth Technology: BLE in the IoT Ecosystem. Sensors 2025, 25, 996. [Google Scholar] [CrossRef]
- Zohourian, A.; Dadkhah, S.; Neto, E.C.P.; Mahdikhani, H.; Danso, P.K.; Molyneaux, H.; Ghorbani, A.A. IoT Zigbee device security: A comprehensive review. Internet Things 2023, 22, 100791. [Google Scholar] [CrossRef]
- Devi, D.H.; Duraisamy, K.; Armghan, A.; Alsharari, M.; Aliqab, K.; Sorathiya, V.; Das, S.; Rashid, N. 5G technology in healthcare and wearable devices: A review. Sensors 2023, 23, 2519. [Google Scholar] [CrossRef] [PubMed]
- Alshammari, H.H. The internet of things healthcare monitoring system based on MQTT protocol. Alex. Eng. J. 2023, 69, 275–287. [Google Scholar] [CrossRef]
- Bormann, C.; Castellani, A.P.; Shelby, Z. Coap: An application protocol for billions of tiny internet nodes. IEEE Internet Comput. 2012, 16, 62–67. [Google Scholar] [CrossRef]
- Saripalle, R.; Runyan, C.; Russell, M. Using HL7 FHIR to achieve interoperability in patient health record. J. Biomed. Inform. 2019, 94, 103188. [Google Scholar] [CrossRef]
- Askar, N.A.; Habbal, A.; Mohammed, A.H.; Sajat, M.S.; Yusupov, Z.; Kodirov, D. Architecture, protocols, and applications of the internet of medical things (IoMT). J. Commun. 2022, 17, 900–918. [Google Scholar] [CrossRef]
- Razdan, S.; Sharma, S. Internet of medical things (IoMT): Overview, emerging technologies, and case studies. IETE Tech. Rev. 2022, 39, 775–788. [Google Scholar] [CrossRef]
- Alsubaei, F.; Abuhussein, A.; Shandilya, V.; Shiva, S. IoMT-SAF: Internet of medical things security assessment framework. Internet Things 2019, 8, 100123. [Google Scholar] [CrossRef]
- Ghubaish, A.; Salman, T.; Zolanvari, M.; Unal, D.; Al-Ali, A.; Jain, R. Recent advances in the internet-of-medical-things (IoMT) systems security. IEEE Internet Things J. 2020, 8, 8707–8718. [Google Scholar] [CrossRef]
- Hatzivasilis, G.; Soultatos, O.; Ioannidis, S.; Verikoukis, C.; Demetriou, G.; Tsatsoulis, C. Review of security and privacy for the Internet of Medical Things (IoMT). In Proceedings of the 2019 15th International Conference on Distributed Computing in Sensor Systems (DCOSS), Santorini, Greece, 29–31 May 2019; pp. 457–464. [Google Scholar]
- Bhushan, B.; Kumar, A.; Agarwal, A.K.; Kumar, A.; Bhattacharya, P.; Kumar, A. Towards a secure and sustainable internet of medical things (iomt): Requirements, design challenges, security techniques, and future trends. Sustainability 2023, 15, 6177. [Google Scholar] [CrossRef]
- Abdussami, M.; Amin, R.; Vollala, S. Provably secured lightweight authenticated key agreement protocol for modern health industry. Ad Hoc Netw. 2023, 141, 103094. [Google Scholar] [CrossRef]
- Qiu, S.; Li, J.; Di, X.; Li, X.; Wu, Y.; Ibrahim, M. Lightweight mutual authentication scheme based on blockchain for the Internet of Medical Things. IEEE Internet Things J. 2024, 12, 8848–8861. [Google Scholar] [CrossRef]
- Lo, C.K.M.; Tan, S.F.; Chung, G.C. Enhanced Authentication Protocol for Securing Internet of Medical Things with Lightweight Post-Quantum Cryptography. In Proceedings of the 2024 IEEE International Conference on Artificial Intelligence in Engineering and Technology (IICAIET), Kota Kinabalu, Malaysia, 26–28 August 2024; pp. 625–630. [Google Scholar]
- Masud, M.; Gaba, G.S.; Alqahtani, S.; Muhammad, G.; Gupta, B.B.; Kumar, P.; Ghoneim, A. A lightweight and robust secure key establishment protocol for internet of medical things in COVID-19 patients care. IEEE Internet Things J. 2020, 8, 15694–15703. [Google Scholar] [CrossRef] [PubMed]
- Miao, J.; Wang, Z.; Wu, Z.; Ning, X.; Tiwari, P. A blockchain-enabled privacy-preserving authentication management protocol for Internet of Medical Things. Expert Syst. Appl. 2024, 237, 121329. [Google Scholar] [CrossRef]
- Garg, N.; Wazid, M.; Das, A.K.; Singh, D.P.; Rodrigues, J.J.; Park, Y. BAKMP-IoMT: Design of blockchain enabled authenticated key management protocol for internet of medical things deployment. IEEE Access 2020, 8, 95956–95977. [Google Scholar] [CrossRef]
- Pradhan, M.; Mohanty, S. A blockchain-assisted multifactor authentication protocol for enhancing IoMT security. IEEE Internet Things J. 2024, 11, 39323–39332. [Google Scholar] [CrossRef]
- Gautam, D.; Thakur, G.; Obaidat, M.S.; Hsiao, K.F.; Kumar, P. Security Analysis and Improvement of Authenticated Key Agreement Protocol for Remote Patient Monitoring IoMT. In Proceedings of the 2024 International Conference on Communications, Computing, Cybersecurity, and Informatics (CCCI), Beijing, China, 16–18 October 2024; pp. 1–8. [Google Scholar]
- Chen, C.M.; Liu, S.; Li, X.; Islam, S.H.; Das, A.K. A provably-secure authenticated key agreement protocol for remote patient monitoring IoMT. J. Syst. Archit. 2023, 136, 102831. [Google Scholar] [CrossRef]
- Su, X.; Xu, Y. Secure and Lightweight Cluster-Based User Authentication Protocol for IoMT Deployment. Sensors 2024, 24, 7119. [Google Scholar] [CrossRef]
- Deebak, B.; Hwang, S.O. Federated learning-based lightweight two-factor authentication framework with privacy preservation for mobile sink in the social IOMT. Electronics 2023, 12, 1250. [Google Scholar] [CrossRef]
- ISO/IEC 29128-1:2023; Information Security, Cybersecurity and Privacy Protection—Verification of Cryptographic Protocols—Part 1: Framework. International standard; International Organization for Standardization: Geneva, Switzerland, 2023.
- Syverson, P.F.; Van Oorschot, P.C. On unifying some cryptographic protocol logics. In Proceedings of the 1994 IEEE Computer Society Symposium on Research in Security and Privacy, Oakland, CA, USA, 16–18 May 1994; pp. 14–28. [Google Scholar]
- Cremers, C.J. The scyther tool: Verification, falsification, and analysis of security protocols: Tool paper. In Computer Aided Verification, Proceedings of the 20th International Conference on Computer Aided Verification, Princeton, NJ, USA, 7–14 July 2008; Springer: Berlin/Heidelberg, Germany, 2008; pp. 414–418. [Google Scholar]



| Type | Ref. | Purpose | Description | Advantages | Challenges |
|---|---|---|---|---|---|
| IoMT Survey | [38] | - Description of the challenges associated with IoMT | - Integrates new-generation tech. (such as ML, blockchain, fog, and edge computing) | - Enables analysis of medical data using machine learning - Achieves low latency and efficient data processing through fog and edge computing | - Mobility - Security and privacy - Interoperability and scalability - Real-time operation - Low-power operation |
| IoMT Survey | [39] | - Design of an IoMT security framework and application of an e-healthcare system | - Investigates PUF, blockchain, AI, and SDN - Validated through three case studies evaluating authentication, security, performance, and data collection | - Proposes an IoMT architecture - Applies new technology for security and performance - Maps real-life applicability - Conducts experimental validation through case studies | - Difficulty in activating SDN - Black-box problem in AI (XAI) - Blockchain scalability |
| IoMT Survey | [40] | - Design of a web-based security-assessment framework | - Uses an ontology- and scenario-based approach to create a web-based security-assessment framework (IoMT-SAF) - Supports the evaluation of protection and deterrence capabilities | - Utilizes real-world security-threat cases and cyberattack data - Evaluates framework performance using the CVE list | - Security-profile definition is lengthy and complex |
| IoMT Survey | [41] | - Research on recent advances in IoMT security | - Proposes a three-stage IoMT security framework addressing data collection, data in transit, and data storage | - Analyzes IoMT security requirements - Proposes an IoMT security framework | - Blockchain scalability - Securing remote setup and providing alternative access methods |
| IoMT Survey | [42] | - Review of IoMT security models and various key algorithms | - Discusses security requirements of the IoMT model - Discusses symmetric-key algorithms - Discusses keyless algorithms | - Identifies security weaknesses in IoMT systems- Details methods to accomplish end-to-end security - Presents mechanisms that protect privacy and anonymity | - High infrastructure cost - Strain on existing networks - Lack of standardization |
| IoMT Survey | [43] | - Survey of IoMT security requirements, design issues, methods, and future trends | - Analyzes IoMT background and security threats - Investigation of security requirements - Reviews design challenges associated with the IoMT environment - Presents various security technologies | - Offers detailed classification of device sensors associated with the IoMT - Presents security requirements - Investigates security techniques | - Security and privacy issues - Design complexity - Network-connectivity limitations |
| Protocol | [44] | - Lightweight authentication and key-agreement protocol | - Introduces a lightweight authenticated key-agreement scheme for IoMT systems - Verified security via Scyther - Outperforms existing methods in cost and security | - Reduces encryption overhead through Hashing and XOR - Performance optimization | - Persistent threats and security/privacy challenges |
| Protocol | [45] | - Proposes a lightweight mutual-authentication protocol using blockchain | - Employs ECC and CRT for efficient identity verification - Integrates NFTs to provide immutable and verifiable identity records on the blockchain | - Verified against replay and MITM attacks via AVISPA - In performance evaluation, low communication and storage costs | - Risk of device hijacking - Vulnerabilities in centralized identity management - Residual delays in NFT registration |
| Protocol | [46] | - Proposes a lightweight authentication protocol based on post-quantum cryptography | - Replaces current authentication methods used in the IoMT, which rely on simple passwords and lack additional layers of protection, posing a risk of data breaches. - Introduces a lightweight authentication protocol based on post-quantum cryptography | - Strong security against quantum attacks - Efficient key generation to support the performance and scalability of the IoMT device | - Entity verification - Authentication of medical devices |
| Protocol | [47] | - Proposes an ultra-lightweight and secure RFID authentication scheme | - Uses the solutions of homogeneous linear equations as keys - Minimizes tag costs and allows tags to encrypt and decrypt data through lightweight computations | - Minimizes costs - Enables mutual authentication - Suitable for emergency-response applications | - Limited applicability to realistic medical scenarios - High scanning cost |
| Protocol | [48] | - Privacy-protection authentication-management protocol | - Employs three-factor authentication to ensure user identity is verified on login. - Employs the Chebyshev chaotic map to support the authentication process and key security | - Verified via BAN logic - Resists attacks and results in various security attributes. | - Lightweight blockchain limitations - Need for a reliable authentication and verification mechanism without a TA - Lack of research on quantum-resistant cryptography algorithms |
| Protocol | [49] | - Proposed authentication and key management based on blockchain | - Need for a secure authentication key-management protocol leveraging tamper-resistant and decentralized blockchain mechanisms to secure communications in IoMT environments. | - Robust against attacks (replay, MITM, impersonation, ESL attacks, etc.) - Formally verified for security using AVISPA. | - Not mentioned in this paper. |
| Protocol | [50] | - Proposes a multifactor user-authentication protocol using blockchain and elliptic curve cryptography (ECC) | - Implements a multi-authentication protocol based on blockchain and ECC. - Demonstrates resistance to various attacks in security verification | - Low computational cost - Enhanced security and computational performance | - High cost due to blockchain usage - Higher communication overhead. |
| Protocol | [51] | - Analysis of Chen et al. [52] authentication protocol - Improves on Chen et al.’s authentication protocol | - Addresses the shortcomings of Chen et al. with an improved authentication protocol using elliptic curve discrete-logarithms, encryption and hashing methods. | - Robust against attacks (replay, MITM, impersonation, ESL attacks, etc.) - Formally verified for security using AVISPA. | - Limited application of emerging technologies, machine learning, quantum cryptography, and blockchain technology |
| Protocol | [53] | - User-authentication protocol (3ECAP) | - Uses three-factor authentication (passwords, biometrics, smart cards) and mitigates privilege-escalation attacks with Merkle tree-based access control. | - Verified security via ProVerif - Resistant to attacks (replay, MITM, Sensor hijacking etc.) | - Not mentioned in this paper. |
| Authentication framework | [54] | - Lightweight two-factor authentication framework (L2FAK) | - Addresses gap: existing approaches fail to address several security vulnerabilities, such as user and gateway tampering | - Improves transmission efficiency and reduces overhead compared to existing methods. - Enhances authentication accuracy in medical applications using federated learning. | - Not mentioned in this paper. |
| Security Requirement | Abdussami et al. [44] | Qiu et al. [45] | Lo et al. [46] | Masud et al. [47] | Miao et al. [48] | Garg et al. [49] | Pradhan et al. [50] | Gautam et al. [51] | Su et al. [53] | Deebak et al. [54] |
|---|---|---|---|---|---|---|---|---|---|---|
| Authentication ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Mutual Authentication ✓ | ✓ | × | × | ✓ | ✓ | ✓ | ✓ | × | × | × |
| Confidentiality ✓ | × | × | ✓ | ✓ | ✓ | × | ✓ | ✓ | ✓ | ✓ |
| Integrity ✓ | ✓ | × | ✓ | ✓ | ✓ | × | ✓ | ✓ | ✓ | ✓ |
| Untraceability | × | ✓ | × | ✓ | ✓ | ✓ | × | × | ✓ | ✓ |
| Privacy Preservation ✓ | × | × | × | × | × | × | × | ✓ | × | ✓ |
| Anonymity | ✓ | ✓ | × | ✓ | ✓ | ✓ | × | × | ✓ | ✓ |
| Multi-Factor Authentication | × | × | × | × | ✓ | × | ✓ | × | × | ✓ |
| Freshness ✓ | ✓ | × | × | × | ✓ | ✓ | ✓ | ✓ | ✓ | × |
| Secure Session Key ✓ | ✓ | × | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Forward/Backward Secrecy ✓ | ✓ | × | × | × | ✓ | × | × | ✓ | × | × |
| Lightweight Operation ✓ | × | × | ✓ | ✓ | ✓ | ✓ | × | ✓ | ✓ | ✓ |
| Post-Quantum Security | × | × | ✓ | × | × | × | × | × | × | × |
| Emergency | ✓ | × | × | × | × | × | × | × | ✓ | ✓ |
| Ref. | Computation Time | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| [44] | 43 | 22 | 1 | 1 | - | - | - | - | - | - | - | - | 2.691 |
| [45] | 15 | 13 | 3 | 3 | - | - | 17 | - | - | 6 | - | - | 30.631 |
| [46] | 8 | 4 | 4 | 4 | - | - | 10 | - | - | - | - | - | 6.678 |
| [47] | 39 | 27 | - | - | - | - | - | - | - | - | - | - | 1.15 |
| [48] | 28 | 13 | - | - | 2 | 2 | - | 3 | 2 | - | - | - | 12.657 |
| [49] | 57 | 6 | 1 | 1 | 5 | 5 | - | - | - | 1 | - | - | 32.01 |
| [50] | 12 | 2 | - | - | 1 | 1 | - | 2 | - | - | - | - | 6.176 |
| [51] | 17 | 3 | - | - | 4 | 4 | 3 | - | - | - | - | - | 23.989 |
| [53] | 35 | 1 | 2 | 2 | 3 | 3 | 4 | - | - | 1 | 4 | - | 21.609 |
| [54] | 42 | 12 | 1 | 1 | 3 | 3 | - | - | - | - | 3 | 2 | 19.973 |
| Equipment | Specification |
|---|---|
| CPU | Intel i7-12700 (2.1 GHz) |
| RAM | DDR-4 16 GB |
| VGA | NVIDIA GeForce RTX 2080 |
| OS | Microsoft Windows 11 Pro |
| Compiler | MSVC |
| Notation | Meaning |
|---|---|
| Axioms | Formula |
|---|---|
| Believing Axioms (BA) | 1. 2. |
| Source Association Axiom (SAA) | 1. |
| Receiving Axioms (RA) | 1. 2. |
| Possession Axioms (PA) | 1. 2. 3. |
| Comprehension Axioms (CA) | 1. |
| Saying Axioms (SA) | 1. 2. |
| Freshness Axioms (FA) | 1. 2. |
| Jurisdiction Axiom (JR) | 1. |
| Nonce-Verification Axioms (NV) | 1. |
| Diffie-Hellman Key Exchange Axioms (DH) | 1. |
| Ref. | Verification by the Authors’ Own | SVO | Scyther | Scyther Properties | |||||
|---|---|---|---|---|---|---|---|---|---|
| Niagree | Nisynch | Weakagree | Secret | SKR | Alive | ||||
| [44] | × | × | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
| [45] | × | × | × | × | ✓ | ✓ | ✓ | ✓ | |
| [46] | − | × | O | ✓ | ✓ | ✓ | × | ✓ | ✓ |
| [47] | − | × | O | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| [48] | O | O | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
| [49] | O | × | × | × | × | ✓ | ✓ | × | |
| [50] | O | × | × | × | ✓ | × | ✓ | ✓ | |
| [51] | − | × | O | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| [53] | × | × | × | × | × | ✓ | ✓ | × | |
| [54] | − | × | O | × | × | × | × | × | × |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Lee, S.; Kang, K.A.; Lee, S.; Kim, J. Exploring Authentication Protocols for Secure and Efficient Internet of Medical Things Systems. Electronics 2025, 14, 4164. https://doi.org/10.3390/electronics14214164
Lee S, Kang KA, Lee S, Kim J. Exploring Authentication Protocols for Secure and Efficient Internet of Medical Things Systems. Electronics. 2025; 14(21):4164. https://doi.org/10.3390/electronics14214164
Chicago/Turabian StyleLee, Seungbin, Kyeong A Kang, Soowang Lee, and Jiyoon Kim. 2025. "Exploring Authentication Protocols for Secure and Efficient Internet of Medical Things Systems" Electronics 14, no. 21: 4164. https://doi.org/10.3390/electronics14214164
APA StyleLee, S., Kang, K. A., Lee, S., & Kim, J. (2025). Exploring Authentication Protocols for Secure and Efficient Internet of Medical Things Systems. Electronics, 14(21), 4164. https://doi.org/10.3390/electronics14214164

