A Lightweight Authentication Protocol for Wearable IoT Healthcare Devices: Design, Security Analysis, and Performance Evaluation

Authors

  • Shikha Tiwari

Keywords:

Body area network, Healthcare security, Lightweight authentication, Mutual authentication, Physically unclonable function, Session key agreement

Abstract

Wearable Internet of Things (IoT) devices used for continuous health monitoring — such as ECG patches, glucose monitors, smart insulin pumps, and fitness bands — transmit highly sensitive physiological data over resource-constrained wireless channels. Conventional public-key-based authentication schemes (RSA, bilinear pairing) impose computation, memory, and energy costs that exceed the capability of these battery-limited devices, exposing patients to impersonation, replay, and man-in-the-middle attacks. This article proposes a lightweight, hash- and XOR-based mutual authentication protocol tailored to wearable IoT healthcare devices, in which a Gateway Node (GWN) mediates registration, mutual authentication, and dynamic session-key agreement between the wearable sensor and the remote healthcare server, without relying on expensive asymmetric cryptographic primitives. The protocol further embeds a Physically Unclonable Function (PUF) response at registration for device-level anti-cloning protection and enforces periodic pseudo-identity and session-key refresh to defeat traceability attacks. Formal and informal security analysis shows resistance to replay, impersonation, man-in-the-middle, desynchronization, and stolen-verifier attacks while preserving anonymity and forward secrecy. Simulation-based performance evaluation demonstrates that the proposed protocol reduces computation time by up to 78% and energy consumption by up to 73% relative to RSA and ECC-based baselines, while incurring lower communication and storage overhead, making it well suited for large-scale, battery-powered wearable healthcare deployments.

References

C.-M. Chen, Z. Chen, S. Kumari, and M.-C. Lin, “LAP-IoHT: A Lightweight Authentication Protocol for the Internet of Health Things,” Sensors, vol. 22, no. 14, p. 5401, Jul. 2022.

M. Ahmim, N. Ouafi, I. Ullah, A. Ahmim, D. Chefrour, and R. Almukhlifi, “LSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things,” Computers, Materials & Continua, vol. 85, no. 3, pp. 5093–5116, 2025.

L. Khajehzadeh, H. Barati, and A. Barati, “A Lightweight Authentication and Authorization Method in IoT-based Medical Care,” Multimedia Tools and Applications, May 2024.

X. Li, M. H. Ibrahim, S. Kumari, A. K. Sangaiah, V. Gupta, and K.-K. R. Choo, “Anonymous Mutual Authentication and Key Agreement Scheme for Wearable Sensors in Wireless Body Area Networks,” Computer Networks, vol. 129, pp. 429–443, Mar. 2017.

S. Mandal, “Provably Secure Certificateless Protocol for Wireless Body Area Network,” Wireless Networks, vol. 29, no. 3, pp. 1421–1438, Dec. 2023.

C.-M. Chen, Z. Chen, S. Kumari, M. S. Obaidat, J. J. P. C. Rodrigues, and M. K. Khan, “Blockchain-Based Mutual Authentication Protocol for IoT-Enabled Decentralized Healthcare Environment,” IEEE Internet of Things Journal, vol. 11, no. 14, pp. 25394–25412, Jul. 2024.

M. Tanveer, A. A. A. El-Latif, A. U. Khan, M. Ahmad, and A. A. Ateya, “LEAF-IIoT: Lightweight and Efficient Authentication Framework for the Industrial Internet of Things,” IEEE Access, vol. 12, pp. 31771–31787, 2024.

M. Tanveer, S. A. Chelloug, M. Alabdulhafith, and A. A. A. El-Latif, “Lightweight Authentication Protocol for Connected Medical IoT Through Privacy-Preserving Access,” Egyptian Informatics Journal, vol. 26, p. 100474, Jun 2024.

M. Tanveer, A. U. Khan, M. Ahmad, T. N. Nguyen, and A. A. A. El-Latif, “Resource-Efficient Authenticated Data Sharing Mechanism for Smart Wearable Systems,” IEEE Transactions on Network Science and Engineering, vol. 10, no. 5, pp. 2525–2536, Sep. 2023.

M. K. Hasan, Z. Weichen, N. Safie, F. R. A. Ahmed, and T. M. Ghazal, “A Survey on Key Agreement and Authentication Protocol for Internet of Things Application,” IEEE Access, vol. 12, pp. 61642–61666, 2024.

X. Li, J. Peng, M. S. Obaidat, F. Wu, M. K. Khan, and C. Chen, “A Secure Three-Factor User Authentication Protocol with Forward Secrecy for Wireless Medical Sensor Network Systems,” IEEE Systems Journal, vol. 14, no. 1, pp. 39–50, Mar. 2020.

M. Masud, G. S. Gaba, K. Choudhary, M. S. Hossain, M. F. Alhamid, and G. Muhammad, “Lightweight and Anonymity-Preserving User Authentication Scheme for IoT-Based Healthcare,” IEEE Internet of Things Journal, vol. 9, no. 4, pp. 2649–2656, Feb. 2022.

A. M. Koya and D. P. P., “Anonymous Hybrid Mutual Authentication and Key Agreement Scheme for Wireless Body Area Network,” Computer Networks, vol. 140, pp. 138–151, May 2018.

A. Gupta, M. Tripathi, and A. Sharma, “A Provably Secure and Efficient Anonymous Mutual Authentication and Key Agreement Protocol for Wearable Devices in WBAN,” Computer Communications, vol. 160, pp. 311–325, Jun. 2020.

D. S. Gupta, S. H. Islam, M. S. Obaidat, A. Karati, and B. Sadoun, “LAAC: Lightweight Lattice-Based Authentication and Access Control Protocol for E-Health Systems in IoT Environments,” IEEE Systems Journal, vol. 15, no. 3, pp. 3620–3627, Sep. 2021.

M. Hölbl, M. Kompara, A. Kamišalić, and L. Nemec Zlatolas, “A Systematic Review of the Use of Blockchain in Healthcare,” Symmetry, vol. 10, no. 10, p. 470, Oct. 2018.

Z. Ali, S. Mahmood, K. Mansoor Ul Hassan, A. Daud, R. Alharbey, and A. Bukhari, “A Lightweight and Secure Authentication Scheme for Remote Monitoring of Patients in IoMT,” IEEE Access, vol. 12, pp. 73004–73020, 2024.

X. Chen, D. He, M. K. Khan, M. Luo, and C. Peng, “A Secure Certificateless Signcryption Scheme Without Pairing for Internet of Medical Things,” IEEE Internet of Things Journal, vol. 10, no. 10, pp. 9136–9147, May 2023.

F. Zhu, P. Li, H. Xu, and R. Wang, “A Novel Lightweight Authentication Scheme for RFID-Based Healthcare Systems,” Sensors, vol. 20, no. 17, p. 4846, Jan. 2020.

H. J. Lee, S. Kook, K. Kim, J. Ryu, Y. Lee, and D. Won, “LAMT: Lightweight and Anonymous Authentication Scheme for Medical Internet of Things Services,” Sensors, vol. 25, no. 3, p. 821, Jan 2025.

M. A. Jan, F. Khan, S. Mastorakis, M. Adil, A. Akbar, and N. Stergiou, “LightIoT: Lightweight and Secure Communication for Energy-Efficient IoT in Health Informatics,” IEEE Transactions on Green Communications and Networking, vol. 5, no. 3, pp. 1202–1211, Sep. 2021.

S. U. Jan, A. Ghani, A. Alzahrani, S. M. Saqlain, K. Yahya, and H. Sajjad, “Bandwidth and Power Efficient Lightweight Authentication Scheme for Healthcare System,” Journal of King Saud University - Computer and Information Sciences, vol. 35, no. 7, p. 101601, Jul. 2023.

T. Suleski, M. Ahmed, W. Yang, and E. Wang, “A Review of Multi-Factor Authentication in the Internet of Healthcare Things,” Digital Health, vol. 9, no. 1, pp. 1–20, May 2023.

B. Kuang, A. Fu, W. Susilo, S. Yu, and Y. Gao, “A Survey of Remote Attestation in Internet of Things: Attacks, Countermeasures, and Prospects,” Computers & Security, vol. 112, p. 102498, Jan. 2022.

Published

2026-08-13

Issue

Section

Articles