
==== Front
Heliyon
Heliyon
Heliyon
2405-8440
Elsevier

S2405-8440(24)13608-0
10.1016/j.heliyon.2024.e37577
e37577
Research Article
Securing the IoT-enabled smart healthcare system: A PUF-based resource-efficient authentication mechanism
Alruwaili Omar Oalruwaili@ju.edu.sa
a
Tanveer Muhammad tanveer123giki@gmail.com
b
Alotaibi Faisal Mohammed c
Abdelfattah Waleed w.abdelfattah@ubt.edu.sa
d
Armghan Ammar aarmghan@ju.edu.sa
e⁎
Alserhani Faeiz M. fmserhani@ju.edu.sa
f
a Department of Computer Engineering and Networks, College of Computer and Information Sciences, Jouf University, Sakaka, 72388, Saudi Arabia
b Department of Computer Science, University of Management and Technology, Lahore, Pakistan
c Department of Computer Science, Prince Sattam bin Abdulaziz University, Al-Kharj, Ar Riyadh, Saudi Arabia
d General Subject Department, University of Business and Technology, Jeddah 23435, Saudi Arabia
e Department of Electrical Engineering, College of Engineering, Jouf University, Sakaka 72388, Saudi Arabia
f Department of Computer Engineering and Networks, College of Computer and Information Sciences, Jouf University, Sakaka, 72388, Saudi Arabia
⁎ Corresponding author. aarmghan@ju.edu.sa
10 9 2024
30 9 2024
10 9 2024
10 18 e3757729 6 2024
3 9 2024
5 9 2024
© 2024 The Author(s)
2024
https://creativecommons.org/licenses/by-nc/4.0/ This is an open access article under the CC BY-NC license (http://creativecommons.org/licenses/by-nc/4.0/).
As the Internet of Things (IoT) continues its rapid expansion, cloud computing has become integral to various smart healthcare applications. However, the proliferation of digital health services raises significant concerns regarding security and data privacy, making the protection of sensitive medical information paramount. To effectively tackle these challenges, it is crucial to establish resilient network infrastructure and data storage systems capable of defending against malicious entities and permitting access exclusively to authorized users. This requires the deployment of a robust authentication mechanism, wherein medical IoT devices, users (such as doctors or nurses), and servers undergo registration with a trusted authority. The process entails users retrieving data from the cloud server, while IoT devices collect patient data. Before granting access to data retrieval or storage, the cloud server verifies the authenticity of both the user and the IoT device, ensuring secure and authorized interactions within the system. With millions of interconnected smart medical IoT devices autonomously gathering and analyzing vital patient data, the importance of robust security measures becomes increasingly evident. Standard security protocols are fundamental in fortifying smart healthcare applications against potential threats. To confront these issues, this paper introduces a secure and resource-efficient cloud-enabled authentication mechanism. Through empirical analysis, it is demonstrated that our authentication mechanism effectively reduces computational and communication overheads, thereby improving overall system efficiency. Furthermore, both informal and formal analyses affirm the mechanism's resilience against potential cyberattacks, highlighting its effectiveness in safeguarding smart healthcare applications.

Keywords

Authentication
Encryption
Security
Healthcare
Scyther
Internet of things
==== Body
pmc1 Introduction

The Internet of Things (IoT) and intelligent/smart healthcare application represent cutting-edge domains at the intersection of technology and healthcare, revolutionizing the way medical services are delivered and experienced [1], [2], [3]. IoT's integration into various sectors has ushered in a new era of connectivity, data analytics, and operational efficiency. IoT promotes smart interaction between devices and systems, allowing businesses to gather, manage, and evaluate large volumes of data instantly. This leads to enhanced decision-making and increased operational flexibility [4], [5]. The emergence of IoT-enabled smart healthcare system marks a significant paradigm shift in healthcare delivery, leveraging innovative technologies such as wearable sensors, IoT devices, artificial intelligence, and big data analytics. These systems aim to provide personalized care outside traditional healthcare settings, empowering patients and healthcare providers alike. Through continuous data collection and analysis, IoT-enabled SHS facilitates early disease detection, personalized medical interventions, and overall health improvement [6].

The core of IoT-enabled smart healthcare systems is the effortless communication of health-related data gathered from diverse IoT devices such as wearable health trackers, medical equipment, and monitoring sensors [7], [8]. These devices capture real-time health metrics such as vital signs, medication adherence, and physical activity, transmitting this data to centralized servers or cloud platforms for analysis and storage. Fig. 1 shows the smart healthcare system. Integration with artificial intelligence further enhances these systems' capabilities, enabling automated diagnosis and personalized medical recommendations. Despite the transformative potential of IoT-enabled SHS, ensuring the security and privacy of patient data remains a critical challenge [9], [10]. The open nature of communication channels used in these systems raises concerns about unauthorized access and data breaches. Malicious actors could exploit vulnerabilities to manipulate or forge medical data, posing significant risks to patient safety and confidentiality [11].Figure 1 A use case of SHS: Users receive processed data while IoT devices transmit patient information to cloud servers.

Figure 1

Tackling these challenges necessitates strong authentication and key exchange (AKA) mechanisms to guarantee secure communication between users and medical servers. While traditional cryptographic techniques like symmetric and asymmetric encryption have been utilized in various AKA frameworks, many current solutions suffer from computational inefficiencies and security vulnerabilities, particularly in time-sensitive healthcare settings [12]. To counter this, our paper proposes two tailored AKA mechanisms specifically for IoT-enabled smart healthcare applications. The first enables IoT devices deployed in these applications to retrieve and store data on cloud servers, while the second facilitates users such as doctors and nurses in accessing the stored data. Both mechanisms leverage symmetric encryption algorithm (AES-CBC) and physical unclonable functions (PUFs) to enhance security and reliability while minimizing computational overhead. Through the integration of efficient encryption algorithms and hardware-based security mechanisms, our framework aims to mitigate the inherent security risks in IoT-enabled healthcare applications, ensuring the confidentiality and integrity of patient data.

2 Related work

To ensure seamless communication within IoT-based healthcare systems, numerous AKA mechanisms have been proposed in the exiting literature. In this direction, in [13], the authors developed an AKA mechanism for IoT-based e-healthcare systems, utilizing symmetric encryption and hash functions. While effective for two to three parties or IoT devices, their scheme encounters performance issues as the number of sensor nodes increases. AKA processes become computationally intensive, leading to higher computation costs. In [14], a fuzzy extractor-based AKA mechanism is presented, but it suffers from vulnerability to password-guessing attacks. The authors in [15] devised a system tailored for healthcare systems. They implemented lattice-based cryptography to fortify the scheme against potential quantum computation threats. Nevertheless, upon examination, it is pinpointed that their approach is vulnerable to impersonation, de-synchronization, and smart-card theft attacks. The authors in [16] have developed an authentication scheme for healthcare systems utilizing post-quantum cryptography. They confirmed the security of their proposed scheme through validation using the Scyther tool and the random oracle model.

The AKA mechanism outlined in [17], [18], [19], and [20], smart cards retain an explicit password validation parameter, rendering them susceptible to offline password-guessing attacks. Conversely, [21] and [22] lack password validation parameters, leaving them vulnerable to denial-of-service attacks. Despite [18] employing only three chaotic operations, it still falls short of ensuring perfect forward security in cases of long-term private key leaks. Additionally, despite utilizing elliptic curve cryptography, [22] stores a key in a storage device, undermining forward secrecy protection. [21] fails to provide anonymity due to plaintext identity transmission on public channels and cannot withstand clock synchronization attacks. Likewise, [17], [18], [19], [21], and [20], are incapable of resisting offline password-guessing attacks, thus failing to provide three-factor security directly. While [22] can resist such attacks, it remains susceptible to key-compromised impersonation and lacks forward secrecy. The AKA mechanism proposed in [23] is prone to key compromise user impersonation and clock synchronization attacks. The AKA protocol in [19] is vulnerable to offline password guessing and key-compromise user impersonation attacks and lacks smart-card revocation capabilities. Similarly, the AKA protocol in [17] is deficient in resisting offline password guessing, session-specific temporary information attacks, and clock synchronization attacks, and lacks both three-factor security and smart-card revocation functions. The authors in [24], proposed an AKA mechanism for the smart healthcare system using symmetric encryption and one way hash function, and its security is corroborated using the Scyther tool and ROR model. In [25], an authentication scheme tailored for low-power mobile devices is introduced. Unfortunately, it is vulnerable to password brute-force attacks due to essential security oversights. In response, the authors in [26], propose a lightweight mutual authentication scheme to establish a secure channel between users and their devices. While this secures network data from unauthorized access, it remains susceptible to device capture attacks. Another authentication approach, pioneered by the authors in [27], leverages biometric data for network node authentication. This method enhances security by integrating the patient's electrocardiogram signals into the authentication process. However, it grapples with issues of untraceability and key escrow. To address these shortcomings, the authors in [28], refine the aforementioned scheme by introducing anonymous AKA technique. Despite these improvements, scalability remains a challenge due to significant communication and computation overheads.

The authors in [29], proposed an AKA mechanism for the smart healthcare system using symmetric encryption and one way hash function, and its security is corroborated using the Scyther tool and ROR model. The authors of [30] introduced a two-factor AKA mechanism for healthcare applications on wireless sensor networks, utilizing symmetric encryption and decryption. However, despite claims of robustness, in [31], the authors identified vulnerabilities to offline password-guessing and privileged insider attacks within the protocol [30]. Furthermore, in [31], it is highlighted the absence of user anonymity in [30]. Subsequently, in [32], the authors argued that the AKA mechanism proposed in [31] is susceptible to offline password-guessing, user impersonation, and sensor node capture attacks. Nevertheless, in [33], the authors pointed out vulnerabilities in [32], including susceptibility to stolen smart card attacks, offline password-guessing attacks, user impersonation attacks, and DoS attacks, alongside ineffective mutual authentication. In [34], the authors introduced a secure patient monitoring system, yet [35] demonstrated vulnerabilities to offline password-guessing, user imitation, and known session-specific temporary information attacks within this protocol. Additionally, the authors in [36] proposed a lightweight AKA mechanism, but [37] identified susceptibility to sensor node capture attacks and inadequate authentication between users and devices. Furthermore, in [38], the authors proposed an AKA mechanism for ambient assisted medical living systems. The authors in [39], proposed an AKA mechanism for the smart healthcare system using symmetric encryption and one way hash function, and its security is corroborated using the Scyther tool and ROR model. A summary of these significant related works is provided in Table 1.Table 1 Summary of Various Related AKA Mechanisms Designed for Healthcare Application.

Table 1AKA Mechanism	Limitations of the Existing AKA Mechanisms/Schemes	
Ref. [40]	The scheme has a design flaw and weak against the privileged insider attack.	
Ref. [41]	The scheme cannot resist the de-synchronization and impersonation attacks.	
Ref. [42]	The scheme cannot resist the MITM and impersonation attacks.	
Ref. [43]	Unable to thwart impersonation and privileged insider attacks.	
Ref. [44]	Unable to resist password-guessing attacks.	
Ref. [45]	Unable to thwart DoS and replay attacks.	
Ref. [46]	Unable to thwart MITM and session key leakage attacks.	
Ref. [14]	Suffers from vulnerability to password-guessing attack	
Ref. [47]	Cannot prevent forgery and MITM attack	
Ref. [29]	Cannot prevent impersonation, and insider attacks	

The scheme proposed in [40] has a design flaw and is susceptible to privileged insider attacks. Similarly, the scheme in [41] cannot resist de-synchronization and impersonation attacks. The protocol described in [42] fails to defend against MITM and impersonation attacks. The scheme introduced in [43] is unable to thwart impersonation and privileged insider attacks. Additionally, the technique presented in [44] is vulnerable to password-guessing attacks. In the work in [45], the scheme cannot prevent DoS and replay attacks. Finally, the protocol discussed in [46] is unable to protect against MITM and session key leakage attacks.

2.1 Motivation and research contribution

After investigating various AKA mechanisms as discussed in Section 2, it becomes evident that these mechanisms lack security against multiple attacks, including session key, replay, and impersonation. Moreover, they suffer from key escrow issues. Additionally, they fail to assure perfect forward secrecy and are vulnerable to smart card and privileged insider attacks. Furthermore, they lack verification of protocol using established models or tools like the ROR model, BAN logic, or AVISPA. Drawing from these observations and identified security gaps, we propose two AKA mechanisms to address specific needs within the context of a smart patient monitoring system. The first mechanism focuses on retrieving patient data from IoT devices deployed in the system and securely storing this data on the cloud server. The second mechanism enables users, such as doctors and nurses, to securely retrieve the stored data from the cloud server. The main contributions of the paper include:• We introduce two mechanisms: IoTD-2-CS (IoT device-2-cloud server) and UX-2-CS (user-2-cloud server). These mechanisms employ symmetric encryption, PUF, and hash functions. IoTD-2-CS ensures the authenticity of IoT devices, establishing session keys between the IoT device and cloud server. Similarly, UX-2-CS verifies the authenticity of users, establishing session keys between the user and cloud server. The session keys established by these mechanisms ensure secure and unintelligible communication between IoT devices and cloud servers, as well as between users and cloud servers. The integration of PUF functionality enhances the physical security of the system.

• Both informal and formal security analyses of the proposed AKA mechanisms are performed to illustrate their resilience against various security attacks. It is demonstrated that both AKA mechanisms exhibit robust security resistance against MITM, replay, and impersonation attacks.

• The proposed UX-2-CS AKA mechanism is compared to closely related AKA mechanisms Ref. [48], Ref. [49], Ref. [50], and Ref. [51] in terms of computational cost, communication cost, and security functionalities. UX-2-CS AKA mechanism demonstrates a reduction in computational cost by 69 to 86.25 percent and a decrease in communication cost by 25.55 to 56.85 percent. Similarly, the AKA mechanisms for IoTD-2-CS servers are compared with Ref. [52], Ref. [53], Ref. [54], and Ref. [55] regarding computational cost, communication cost, and security functionalities. Additionally, the AKA mechanism for IoTD-2-CS shows a decrease in computational cost by 75 to 95.80 percent and a reduction in communication cost by 35.24 to 74.62 percent. UX-2-CS and IoTD-2-CS AKA mechanisms provide enhanced security features.

2.2 Paper outline

The paper is structured as follows: In Section 3, we present the system models and background knowledge required to elaborate on the proposed IoTD-2-CS and UX-2-CS AKA mechanisms. The detailed construction of both IoTD-2-CS and UX-2-CS AKA mechanisms is elaborated in Section 4. The security analysis of IoTD-2-CS and UX-2-CS AKA mechanisms is performed using both formal and informal methods in Section 5. The performance comparison of IoTD-2-CS and UX-2-CS AKA mechanisms is conducted in Section 6. The paper concludes with final remarks in Section 7.

3 System model and background knowledge

3.1 Network model

The presented AKA mechanism's network model, as depicted in Fig. 2, incorporates key components: user Ux, IoT devices ITDy, and cloud server CSy. Moreover, a trusted authority oversees the registration of Ux, ITDy, and CSy before their deployment in the smart healthcare application.Figure 2 Network model for user and IoT device authentication.

Figure 2

ITDy is tasked with collecting sensitive patient data within the hospital and transmitting it to CSy. Typically deployed in smart patient monitoring systems or worn by patients, these devices gather data about the patient and deliver it to CSy through an public wireless or wired communication link.

Ux includes nurses/doctors, home users, and policymakers who need to access data stored on CSy to make informed decisions. Communication between Ux and CSy occurs via the public wireless or wired communication link. Thus it is imperative to ensure the integrity of retrieved information by Ux from CSy and information stored by ITDy on CSy.

Both Ux and ITDy exchange information with CSy via the public wireless or wired communication link, which is vulnerable to various security threats. Attackers could intercept data transmitted over these channels, leading to potential security breaches. To mitigate this risk and prevent unauthorized access to communicated data, an AKA mechanism is imperative. For the smooth reading of the paper a list of notation is provided in Table 2.Table 2 Notations.

Table 2Notation	Description	
Ux	User	
RA	Registration authority	
CSY	Cloud server	
PSKCSy	Long-term secret key of the CSy	
PWUx	password of user	
⊕	XOR function	
CHUx	Challenge	
RUx	Response	
CHCSy	Challenge	
RCSy	Response generated at CSy	
PUF(⋅)	PUF function	
Ek(data)	Encryption of data with secret key K	
Dk(ct)	Decryption of ciphertext ct with secret key K	
Y1,Y2,Y6to Y9,Y12to Y14	Cipher texts generated by encryption algorithm in IoTD-2-CS AKA mechanism	
W1,W2,W8to W11,W14to W17	Cipher texts generated by encryption algorithm in UX-2-CS AKA mechanism	
A	Adversary or attacker	
IDi	Identity of the IoT device	
BioUx	Biometric information of Ui	
∥	Concatenation operation	
RGDCSy	Regeneration data for the biometric key at CSy	
RGDUx	Regeneration data for the biometric key at Ux	
Gen(⋅)	FE based biometric key generation algorithm	
Rep(⋅)	FE based biometric key regeneration algorithm	
σUx	Biometric key of the user	
IV	Initialization vector	
H(⋅)	Hash function	

3.2 Adversarial model

The widely recognized “Dolev-Yao threat (DY) model” [56], [57] enables an attacker, designated as A, to intercept communicated messages and manipulate them by modifying, deleting, or inserting fabricated data when communicating with other parties such as a patient (patient), doctor, and cloud server. Additionally, the CK-adversary model [10] is also considered as a paramount threat model, more contemporary in comparison to the DY model. In the CK-adversary model, attacker A may compromise the confidential credentials shared among interacting participants, potentially leading to session hijacking attacks and the compromise of session states and keys. Hence, when designing the proposed AKA mechanism, we ensured it offers both forward and backward secrecy, even in scenarios where A can compromise the current session key.

There is a possibility that a user's smart card or mobile device could be lost or stolen by A, enabling the extraction of all stored credentials through power analysis attacks. It is assumed that A can only guess either a low-entropy password or the identity of a patient at a given time, but not both simultaneously. Furthermore, it is anticipated that predicting the personal biometric and its corresponding biometric secret key would be significantly more challenging compared to guessing a low-entropy password of a patient [58], [59].

3.2.1 Security requirements

Here are the security requirements to consider when designing the IoTD-2-CS and UX-2-CS AKA mechanisms.• Mutual Authentication: The authentication mechanism is a necessary security measure in any system, guaranteeing that only authorized users or devices can access resources or services. In the context of IoTD-2-CS and UX-2-CS AKA mechanisms, robust authentication mechanisms are crucial to ascertain the identity of both IoT devices and users. This assists prevent unauthorized access, data breaches, and other security risks.

• Session Key Establishment: Throughout the authentication process, network entities establish a session key to facilitate encrypted communication for subsequent interactions. In the IoTD-2-CS and UX-2-CS AKA mechanism, IoT devices establish a session key with the cloud server to transmit patient data in an encrypted format. Authorized users, such as doctors and nurses, can securely access this encrypted data from the cloud server via the public Internet.

• Resistance to Various Security Attacks: The IoTD-2-CS and UX-2-CS AKA mechanisms need to withstand a range of security threats, including MITM attacks, replay attacks, impersonation attempts, DoS attacks, and insider attacks by privileged users.

3.3 Background knowledge

In this subsection, we will elaborate on the various cryptographic primitives used in designing the AKA mechanisms.

3.3.1 PUF

Physically unclonable functions (PUFs) are admiringly practical for hardware security due to their capability to develop unique hardware fingerprints. The inherent unpredictability caused by process variations during IC manufacturing makes PUFs impossible to replicate. Additionally, PUFs provide robust protection against physical tampering. They are widely used in applications such as random number generation, secret-key generation, and device authentication. PUFs are characterized by their uniqueness and reliability: uniqueness ensures that identical PUF functions on different devices produce distinct outputs, while reliability guarantees consistent responses to the same challenge over time [60], [61], [62].

3.3.2 FE

A fuzzy extractor is a cryptographic primitive designed to generate stable and secure keys from noisy or imprecise data, such as biometric information or physical unclonable functions (PUFs). This concept is crucial for enhancing security in systems where the exact reproducibility of input data is challenging.

Noisy Data Handling: Traditional cryptographic key generation requires precise input data, which is impractical for bio metrics and other noisy sources. Fuzzy extractors address this issue by reliably generating the same cryptographic key even from slightly different versions of the input data.

Error Tolerance: Fuzzy extractors can tolerate a certain amount of error in the input data, making them ideal for use with bio-metrics, which can vary slightly with each measurement due to factors like environmental conditions or user interaction [61], [62].

The following are the main functions of the FE: Generation (Gen(⋅)): Takes a noisy input and produces a stable key and a helper string. The helper string does not reveal the key but is used to recover the key from similar inputs. Reproduction (Rep(⋅)): Uses the noisy input and the helper string to reproduce the original key. This process ensures that the same key is generated from inputs that are close to the original.

4 The proposed AKA mechanisms

This section introduces two AKA mechanisms. The first one is the UX-2-CS AKA mechanism, which handles the generation of the session key between the user and the cloud server following the validation of the user's authenticity. The second mechanism is responsible for generating the session key between the IoT device and the cloud server after verifying the authenticity of the IoT device. Both AKA mechanisms are further explained in the following subsections.

4.1 Cloud server registration

The trusted authority selects a unique long-term secret key PSKcsy for CSy. Additionally, the trusted authority selects CHcsy and sends PSKcsy and CHcsy to CSy securely. Moreover, CSy computes Rcsy=PUF(CHcsy), (Kcsy,RGDcsy)=Gen(Rcsy) and Ky=H(Kcsy∥PSKcsy). Finally, CSy keeps {RGDcsy,CHcsy,PSKcsy} in its own database.

4.2 Ux registration

The trusted authority is responsible for registering the user Ux before its deployment in the smart healthcare applications. Ux selects its identity IDUx, password PWUx, and imprints its own biometric information BioUx on the smart device owned by Ux. After getting IDUx, PWUx, and BioUx, Ux selects challenge CHUx and computes response RUx=PUF(CHUx), biometric key (σUx,RGDUx)=Gen(BioUx), K2=H(PWUx∥σUx), and sends K2, CHUx, and RUx to the CSy securely. CSy after getting K2 selects random number Rux and computes (W1,W2)=EKy{(IVcsy=Ky),(K2⊕Rux,Rux)} and sends (W1,W2) to the Ux securely. In addition CSy computes PIDx=H(K2) and stores the parameters {PIDx, CHUx, RUx} in its own database. Moreover, Ux computes IV2=H(PWUx∥IDUx), (Ctx2)=EK2{IV2,W1, W2}, and W4=H(W1∥W2∥K2∥IV2). Finally, Ux stores the credentials {Ctx2, (W1,W2), RGDUx, W4, Gen(⋅), Rep(⋅)} it its device's memory.

4.3 ITDk registration

The trusted authority is responsible for registering the IoT device before its deployment in the smart healthcare application. It selects a long-term secret key Kd, identity IDi, and challenge CHi, and sends IDi, Kd, and CHi to ITDk. Additionally, ITDk generates the response Rp=PUF(CHi) and securely transmits IDi, CHi, and Rp back to the trusted authority. The trusted authority then computes (Y1,Y2)=EKy{(IVj=Ky),(IDi⊕Rx1,Rx1)}, where Rx1 is a random number. Additionally, the trusted authority computes SIDi=H(IDi) and stores the parameters {SIDi,CHi,Rp} in the database of CSy. Moreover, the trusted authority securely transmits {Y1,Y2,Kd,IDi} to ITDk.

4.4 IoTD-2-CS AKA mechanism

In this phase, the session key between the IoT device and the cloud server is generated following mutual authentication. IoT devices can securely store information on the cloud server using the established session key. The steps outlined below are crucial for both session key generation and mutual authentication.

4.4.1 Step-1

When the IoT device has data to transmit to CSy, it initiates the mechanism known as IoTD-2-CS. In this process, the IoT device selects the timestamp Tx and computes.(1) Y4=H(Y1∥Y2∥IDi∥Tx).

It is important to emphasize that Y4 serves as the authentication parameter, verifying the integrity of the message at CSy. Furthermore, ITDk generates a message M1 containing {Tx,Y1,Y2,Y4} and transmits it to CSy through the public wireless or wired communication link.

4.4.2 Step-2

Upon receiving the message M1 from the IoT device, CSy verifies the freshness of M1 using the condition Tdl≥|Tre−Tx|. If this condition is met, CSy proceeds to compute the following:(2) Tdl≥|Tre−Tx|

(3) Rcsy⁎=PUF(CHcsy),

(4) Kcsy⁎=Rep(Kcsy⁎,RGDcsy),

(5) Ky=H(Kcsy⁎∥PSKcsy),

(6) (IDi⊕Rx,Rx)=DKy{(IVi=Ky),Y1,Y2},

(7) Y4=H(Y1∥Y2∥IDi∥Tx),

(8) Y5=?Y4.

It is worth mentioning that in the proposed IoTD-2-CS AKA mechanism we employed the symmetric encryption and decryption algorithm referred to as AES-CBC. Prior to authenticating the received message M1, CSy must calculate its secret key Ky, preceded by the computation of Rcsy⁎ and Kcsy⁎. Subsequently, after the decryption operation, CSy obtains the IDi of the IoT device and computes the authentication parameter Y4. Additionally, the integrity of the message M1 is verified through condition (8). Moreover, CSy computes SIDi=H(IDi) and retrieves {CHi,Rp} from its own database. CSy creates the response message M2 by selecting the values Rx1, Rm, and timestamps Ty through the following computations:(9) Y1n=(IDi⊕Rx1n),

(10) (Y1n,Y2n)=EKy{(IVj=Ky),(IDi⊕Rx1n,Rx1n)},

(11) (Y6,Y7,Y8,Y9)=EKd{(IVk=Y1),Y1n,Y2n,Rm,Rp},

(12) Y10=H(Y1n∥Y2n∥Rm∥CHi∥Ty∥Kd).

Furthermore, CSy generates a message M2 containing {Ty,Y6,Y7,Y8,Y9,Y10} and transmits it to ITDk through the public wireless or wired communication link.

4.4.3 Step-3

Upon reception of the message M2 from the IoT device, CSy validates the freshness of M2 by applying the condition Tdl≥|Tre−Ty|. If this condition holds true, CSy then proceeds to perform the following computations:(13) (Y1n,Y2n,Rm,Rp)=DKd{(IVl=Y1),Y6,Y7,Y8,Y9},

(14) Y11=H(Y1n∥Y2n∥Rm∥Rp∥Ty∥Kd),

(15) Y11=?Y10.

The authenticity of the received message M2 is confirmed by checking condition (15). If this condition is satisfied, CSy proceeds to perform the following computations after selecting Tz, Rn, and CHin.(16) (Kd1,RGDi⁎)=Gen(Rp),

(17) Rin=PUF(CHin),

(18) (Y12,Y13,Y14)=EKd1{(IVm=RGDi⁎),Rpn,CHin,Rn},

(19) SKi=H(Kd1∥CHin∥Rpn∥Rn∥Rm),

(20) Y15=H(RGDi⁎∥Rpn∥CHin∥Rn∥Kd1∥SKi).

After completing the aforementioned computations, ITDk constructs the message M3 with {Tz, RGDi⁎, Y12, Y13, Y14, Y15} and sends it to CSy via the public wireless or wired communication link.

4.4.4 Step-3

Upon reception of the message M2 from the IoT device, CSy validates the freshness of M2 by applying the condition Tdl≥|Tre−Tz|. If this condition holds true, CSy then proceeds to perform the following computations:(21) (Kd1)=Rep(Rp,RGDi⁎),

(22) (Rpn,CHin,Rn)=EKd1{(IVn=RGDi⁎),Y12,Y13,Y14},

(23) SKy=H(Kd1∥CHin∥Rpn∥Rn∥Rm),

(24) Y16=H(RGDi⁎∥Rpn∥CHin∥Rn∥Kd1∥SKy),

(25) Y15=?Y16.

Both CSy and ITDk compute the session keys SKi and SKy for encrypted communication in the future. The authenticity of the message M3 is verified using condition (25). The fulfillment of this condition also signifies successful authentication. Finally, CSy replaces (Rin,CHin) with (Ri,CHi) in its own database. The summary of the IoTD-2-CS is given in Fig. 3.Figure 3 AKA phase of IoTD-2-CS.

Figure 3

4.5 UX-2-CS AKA mechanism

During this phase, the generation of the session key between the user and the cloud server occurs after mutual authentication has been achieved. Users such as doctors, nurses, and others can securely access information stored on the cloud server. The following steps are essential for both session key generation and mutual authentication.

4.5.1 Step-1

The user Ux starts the AKA mechanism by taking BioUx, RGDUx, IDUx, and PWUx as the input parameters. Ux computes the following:(26) (σUx)=Rep(BioUx,RGDUx),

(27) K2=H(PWUx∥σUx),

(28) IV2=H(PWUx∥IDUx),

(29) (W1,W2)=DK2{IV2,Ctx2},

(30) W4=H(W1∥W2∥K2∥IV2),

(31) W4=?W2.

It is vital to state that σUx serves as the biometrically derived secret key, generated through the reproduction function of FE. In the decryption algorithm, K2 represents the secret key. IV2 stands for the initialization vector. Additionally, W4 functions as the authentication parameter, its validity assessed through the condition (31). Fulfillment of this condition indicates successful local verification of the user. Furthermore, upon meeting this criterion, Ux proceeds to select Tg, Ri, and calculates the following:(32) W5=H(K2∥Ri)⊕H(K2∥Tg),

(33) W6=H(H(K2∥Ri)∥Tg∥W1∥W2).

The above computed W5 and W6 are the component of the AKA message sent by Ux to CSy. Ux generates the message Mg1:{Tg,W1,W2,W5,W6} and sends this generated message to CSy via the public wireless or wired communication link.

4.5.2 Step-2

CSy obtains the message Mg1:{Tg,W1,W2,W5,W6} and extracts the timestamp. It then ascertains its freshness by comparing it with the condition Tdl≥|Tre−Tg|. If this condition is met, the CSy proceeds to compute the following:(34) Rcsy⁎=PUF(CHcsy),

(35) Kcsy⁎=Rep(Rcsy⁎,RGDcsy),

(36) Ky=H(Kcsy⁎∥PSKcsy),

(37) IVcsy=H(IDcsy∥Ky),

(38) (K2,Rux)=DKy{(IVcsy),W1,W2},

(39) H(K2∥Ri)=W5⊕H(K2∥Tg),

(40) W7=H(H(K2∥Ri)∥Tg∥W1∥W2),

(41) W6=?W7.

In the preceding calculations, Rcsy denotes the response generated by the PUF function, utilizing CHcsy as its input, assigned to CSy during registration. The stable key Kcsy⁎ is reproduced using the FE reproduction function, with Rcsy⁎ as the input parameter. Additionally, CSy computes the decryption key Ky and the initialization vector IVcsy. CSy gets K2,Rux and H(K2∥Ri) from the decryption process. Furthermore, CSy calculates the authentication parameter W7, and the message validity is verified through condition (41). If this condition holds true, CSy proceeds to compute PIDx=H(K2), checks its existence in the database, and if found, retrieves (CHUx,RUx). Moreover, CSy selects Th, Rj, and Ruxn and computes the followings:(42) Ke=H(H(K2∥Ri)∥K2)

(43) (W1n,W2n)=EKy{(IVcsy),(K2⊕Ruxn),Ruxn}

(44) (W8,W9,W10,W11)=EKe{IV2=K2,CHUx,Rj,W1n,W2n}

(45) W12=H(Rj∥CHUx∥H(K2∥Ri)∥W8∥W9∥W1n∥W2n),

Here, the encryption key Ke is computed, and new parameters W1n and W2n are generated using this secret encryption key. Additionally, using the secret encryption key Ky, the parameters W8 and W9 are generated through the encryption process. Furthermore, the authentication parameter W10 is computed using the hash function. Finally, CSy constructs a message with parameters Mg2: {Th,W8,W9,W10,W11,W12} and transmit it to Ux.

4.5.3 Step-3

Ux verifies the freshness of the received message based on the condition Tdl≥|Tre−Th|. If true, Ux computes the following:(46) Kf=H(H(K2∥Ri)∥K2),

(47) (CHUx,Rj,W1n,W2n)=DKf{(IV3=K2),W8,W9,W10,W11}

(48) W13=H(Rj∥CHUx∥H(K2∥Ri)∥W8∥W9∥W1n∥W2n)

(49) W12=?W13,.

When Kf serves as the decryption key, the decryption process yields CHUx and Rj. Furthermore, it computes W11, representing the authentication parameter, while verifying the authenticity and integrity of message Mg2 through condition (49). If the criterion is fulfilled, and Ux chooses Rk, CHUxn, and Ti. Ux computes the following:(50) (Kz,RGDUx⁎)=Gen(CHUx),

(51) RUxn=PUF(CHUxn),

(52) (W12,W13,W14,W15)=EKf{(IV3=K2),RGDUx⁎,RUxn,CHUxn,Rk},

(53) SKUx=H(Kf∥CHUxn∥RUxn∥K2∥Rk∥Ri∥Rj),

(54) W16=H(RGDUx⁎∥RUxn∥CHUxn∥Rk∥Kz∥SKUx),

(55) (Ctx3)=EK2{IV2,W1n,W2n},

(56) W4n=H(W1n∥W2n∥K2∥IV2).

Through the FE generation function, parameters Kz and RGDUx⁎ are derived. Additionally, Ux computes RUxn using the PUF function. Subsequently, W12, W13, W14, and W15 are generated as cipher-texts using the encryption algorithm, with IV3=K2 serving as the initialization vector. A session key is then computed to facilitate encrypted communication, which occurs following mutual authentication. Finally, Ux obtains the authentication credential W16 and assembles the message Mg3:{Ti,W12,W13,W14,W15,W16} and deliver it to CSy. In addition, Ux updates Ctx3 with Ctx2 and W4n with W4,

4.5.4 Step-4

After getting Mg3, CSy verifies the freshness of the message based on the condition Tdl≥|Tre−Ti|. If the message is fresh then CSy computes the following:(57) (RGDUx⁎,RUxn,CHUxn,Rk)=DKf{(IV5=K2),W12,W13,W14,W15},

(58) Kz⁎=Rep(CHUx,RGDUx⁎),

(59) SKCSy=H(Kf∥CHUxn∥RUxn∥K2∥Rk∥Ri∥Rj),

(60) W17=H(RGDUx⁎∥RUxn∥CHUxn∥Rk∥Kz⁎∥SKCSy),

(61) W16=?W17.

During the decryption process, CSy obtains (RGDUx,RUxn,CHUxn,Rk) and derives Kz⁎ using the reproduction function of FE. Subsequently, a session key is computed to enable encrypted communication between Ux and CSy post mutual authentication. Following the computation of the authentication parameter W17, CSy verifies the integrity of the received message. If the message is authenticated, CSy updates its own database with (CHUxn,RUxn), replacing (CHUx,RUx). The user AKA mechanism is summarized in Fig. 4.Figure 4 AKA phase UX-2-CS.

Figure 4

4.6 Password update mechanism

The proposed UX-2-CS AKA mechanism facilitates password changes and biometric updates. To achieve this, the user Ux utilizes the old BiooUx, RGDUxo, IDUxo, and PWUxo as input parameters, and computes the following:(62) (σUxo)=Rep(BioUxo,RGDUxo),

(63) K2=H(PWUxo∥σUxo),

(64) IV2=H(PWUxo∥IDUxo),

(65) (W1o,W2o)=DK2o{IV2o,Ctx2o},

(66) W4o=H(W1o∥W2o∥K2o∥IV2o),

(67) W4o=?W2.

If condition (67) holds, then Ux generates new and updated secret parameters BioUxn, RGDUxn, IDUxn, and PWUxn. Ux computes the following:(68) (σUxn,RGDUxn)=Gen(BioUxn),

(69) K2n=H(PWUxn∥σUxn),

(70) IV2n=H(PWUxn∥IDUxn),

(71) (Ctx2n)=EK2n{IV2n,W1,W2},

(72) W4n=H(W1∥W2∥K2n∥IV2n).

Finally, Ux updates with {Ctx2, RGDUx, W4, Gen(⋅), Rep(⋅)} with {Ctx2n, RGDUxn, W4n, Gen(⋅), Rep(⋅)} in its own database.

5 Security analysis

In this section we will demonstrate the resiliency of IoTD-2-CS and UX-2-CS against various security threats through informal and formal security analysis.

5.1 Informal security analysis

Informal security analysis refers to non mathematical security analysis, which is carried out in this section to elaborate the resiliency of IoTD-2-CS and UX-2-CS against various security attacks.

5.1.1 Replay attack

The prevention of replay attacks is imperative in the proposed AKA mechanism. In the proposed IoTD-2-CS and UX-2-CS AKA mechanisms, we use timestamps to prevent replay attacks. In the IoTD-2-CS AKA mechanism, there are three messages exchanged during the AKA phase: M1, M2, and M3. Each message incorporates the latest timestamp. The validity of the timestamps is verified by the receiving network entity using the conditions Tdl≥|Tre−Tx|, Tdl≥|Tre−Ty|, and Tdl≥|Tre−Tz| for messages M1, M2, and M3, respectively. If any of these conditions fail, the associated message is considered to be delayed. In the UX-2-CS AKA mechanism, the receiving network entity verifies the freshness of the timestamps by using the conditions Tdl≥|Tre−Tg|, Tdl≥|Tre−Th|, and Tdl≥|Tre−Ti| for messages Mg1, Mg2, and Mg3, respectively. If any of these conditions fail, the related message is regarded as delayed. In this way, both AKA mechanisms prevent replay attacks.

5.1.2 DoS attack

In this attack, it is desirable to prevent legitimate users from generating too many AKA messages, which could overwhelm the resources of the CSy. These AKA messages are used to validate the user at CSy. In the proposed UX-2-CS AKA mechanism, users must perform local authentication before generating an AKA message with the parameters Mg1:{Tg,W1,W2,W5,W6}. To accomplish local authentication, Ux must check a specific condition W4=?W3. If this condition is met, Ux will generate Mg1. Otherwise, Ux will be unable to generate Mg1. In this way, the proposed UX-2-CS mechanism can prevent the DoS attack.

5.1.3 MITM attack

In the proposed IoTD-2-CS AKA mechanism, three messages are exchanged: M1:{Tx,Y1,Y2,Y4}, M2:{Ty,Y6,Y7,Y8,Y9,Y10}, and M3:{Tz,RGDi⁎,Y12,Y13,Y14,Y15}. These messages can be intercepted as discussed in the threat model. An attacker, after capturing these messages, can alter and resend them to the user or cloud server to compromise the AKA phase. However, the attacker cannot fabricate these messages without possessing the secret credentials, such as IDi, Rx1, CSy long-term secret key, and random numbers. Furthermore, the integrity of M1, M2, and M3 is verified through the conditions Y5=?Y4, Y11=?Y10, and Y15=?Y16. If any of these conditions fail, the AKA phase will be terminated. Similarly, the attacker cannot generate valid messages Mg1:{Tg,W1,W2,W5,W6}, Mg2:{Th,W8,W9,W10,W11,W12}, and Mg3:{Ti,W12,W13,W14,W15,W16}, communicated during the AKA phase of UX-2-CS, without the secret credentials used in the construction of these messages. Additionally, the integrity of Mg1, Mg2, and Mg3 is checked through the conditions W6=?W7, W12=?W13, and W18=?W19, respectively. The AKA phase will be successful if all the conditions are met; otherwise, it will be terminated. In this way, both AKA mechanisms can prevent MITM attacks.

5.1.4 IoT device impersonation attack

In the proposed IoTD-2-CS AKA mechanism, there are two message exchanges that occur during the AKA phase: M1:{Tx,Y1,Y2,Y4}, and M3:{Tz,RGDi⁎,Y12,Y13,Y14,Y15}. These messages are carefully crafted using a set of secret parameters, including the IoT device's identity, the long-term secret key of the cloud server, Kd, challenge and response parameters, and a secret key derived from the FE's key reproduction function. Lacking possession of these crucial parameters, an attacker would be unable to produce valid M1 and M3 to successfully impersonate as IoT device. In this way, the proposed IoTD-2-CS AKA mechanism can prevent the IoT device impersonation attacks.

5.1.5 User impersonation attack

In UX-2-CS AKA mechanism, messages exchanges during the AKA phase: Mg1:{Tg,W1,W2,W5,W6} and Mg3:{Ti,W12,W13,W14,W15,W16}. Both messages are constructed using the secret parameters: the identity of the user, the long-term secret key of the cloud server, and the secret key generated from the FE's key reproduction function. Additionally, these messages incorporate fresh random numbers. Therefore, both temporary and long-term secret credentials are necessary to modify these messages. Without possessing these parameters, the attacker cannot generate valid Mg1 and Mg3 to impersonate the legitimate user. In this way, the proposed UX-2-CS AKA mechanism can prevent the user impersonation attacks.

5.1.6 Cloud server impersonation attack

In this attack, the attacker generates a random message with random parameters to make it appear to Ux as if it is from the legitimate cloud server. In the IoTD-2-CS system, the cloud server generates the message M2:{Ty,Y6,Y7,Y8,Y9,Y10} in response to M1 received from the IoT device. The attacker cannot generate a valid message without having parameters such as Kd, IDi, a random number, and a challenge response parameter stored in the cloud server's database. Therefore, the proposed IoTD-2-CS AKA mechanism can withstand cloud server impersonation attacks. Similarly, to generate the valid message Mg2:{Th,W8,W9,W10,W11,W12}, which is transmitted by the cloud server during the AKA phase of the UX-2-CS AKA mechanism, an attacker would need to know the parameters K2, Ri, IDUx, and the challenge response parameters stored in the cloud server's database. Since these parameters are known only to the user and the cloud server, the attacker cannot generate the valid message Mg2. Therefore, the proposed UX-2-CS AKA mechanism effectively protects against cloud server impersonation attacks.

5.1.7 De-synchronization attack

De-synchronization occurs due to the updating of one or more parameters during the AKA phase. However, it is possible that some parameters are updated on one network entity, while due to an eavesdropping attack, the parameters that need updating remain unchanged on the other side. In the proposed AKA mechanism, such a state does not exist, thereby preventing any desynchronization.

5.1.8 Password guessing attack

In this attack, the attacker's objective is to change or update the user's password after somehow obtaining the user's device. The attacker utilizes power analysis attacks to extract data stored in the device's memory, including {Ctx2, RGDUx, W4, Gen(⋅), Rep(⋅)}. With this information, the attacker can change the user's password only if the condition W4=?W3 is true. This condition holds true only if the attacker knows the user's secret credentials, such as the password, identity, and biometric key. Without these credentials, the condition W4=?W3 cannot be met. Therefore, the attacker cannot successfully execute a password change or password guessing attack against the proposed UX-2-CS AKA mechanism.

5.1.9 Temporary parameter leakage attack

This paper proposes two AKA mechanisms. In IoTD-2-CS, the session key SKi(=SKy)=H(Kd1∥CHin∥Rpn∥Rn∥Rm) is generated during its AKA phase. During the AKA phase of UX-2-CS, the session key SKUx(=SKCSy)=H(Kf∥CHUxn∥RUxn∥K2∥Rk∥Ri∥Rj) is generated. Both session keys are derived from a combination of temporary secret credentials and permanent credentials of various entities within the healthcare application. To compromise the security of either session key, an adversary must simultaneously compromise both the temporary and permanent credentials of the network entities. This ensures that the proposed AKA mechanisms can effectively temporary parameter leakage attack.

5.1.10 Anonymity and un-traceability attack

During the execution of the AKA phases of IoTD-2-CS and UX-2-CS AKA mechanisms the following messages are exchanged M1:{Tx,Y1,Y2,Y4}, M2:{Ty,Y6,Y7,Y8,Y9,Y10}, and M3:{Tz,RGDi⁎,Y12,Y13,Y14,Y15} and Mg1:{Tg,W1,W2,W5,W6}, Mg2:{Th,W8,W9,W10,W11,W12}, and Mg3:{Ti,W12,W13,W14,W15,W16}, respectively. All these messages are random due to the involvement of the current timestamps and random numbers. The adversary can not find any correlation between different AKA sessions. In addition, the attacker can't find the identity of the user and IoT device from the captured messages. Hence, the proposed AKA mechanisms provide anonymity and un-traceability features.

5.2 Security analysis using random or real (ROR) model

Through ROR model, UX-2-CS is thoroughly examined, and A is given permission to construct a variety of queries that allow for the execution of legitimate attacks. Various components of the ROR model are described as follows.

Participants: Within the UX-2-CS framework, three key entities/participants are involved: Ux (User), CSy (Mobile Edge Server). The instances I1 and I2 representing Ux and CSy are denoted as ΦUxI1 and ΦCSyI2, respectively, functioning as oracles.

Partnership: If instances ΦUxI1 and ΦCSyI2 have a common SK, they establish a partnership at the acceptance state.

Freshness: By A, the SK generated during the AKA phase between ΦUxI1 and ΦCSyI2 cannot be revealed or made public.

Table 3 contains a list of these queries. We evaluate every potential query in order to formally verify the security of UX-2-CS. The subsequent variety of queries are used to simulate various attack scenarios against UX-2-CS.Table 3 ROR Model Queries.

Table 3Query	Explanation of the Query	
Execute(ΦUxI1,ΦCSyI2)	Using this query, an adversary can extract the exchanged messages during a legitimate execution of the protocol between a client instance and server instance.	
Test(ΦI1)	Consider a bit b ∈ 0,1 that has been picked at arbitrary. Upon asking this query, if b = 1, the output symbolizes the real secret value for instance Ux. However, if b = 0, the outcome consists of an arbitrary vector of the same size as the secret value. If the secret value for Ux is undefined, the query yields null value.	
Reveal(ΦI1)	A can access the session key maintained by oracle ΦI1 with this query.	
Send(ΦI1,M)	When communication is intercepted, an adversary might alter a message and reroute it to its intended recipient. This query produces the response message generated by instance Ux upon receiving message M.	
Corrupt(ΦI1)	This query simulates a smart stolen device attack, where an adversary extracts all secret parameters stored in the smart device employing physical attacks, such as side-channel analysis.	

Theorem 1 Let A be a polynomial time (pti) bounded adversary challenging the security of UX-2-CS. We use HQ2 , qrs , and HP2 to represent hash, send, and PUF queries, respectively. The password dictionary space is denoted as PASD , and the length of the biometric key is indicated by 2le . Moreover, the parameters C′ and s′ are defined in Zipf's law as described in [63] . |PUS| and |HS| denote the PUF and hash output space. Furthermore, AdvAIND−CPA(pti) represents the advantage of A in compromising the security of an AES-CBC. The estimation of A 's advantage in compromising the security of the session key generated during the AKA phase of UX-2-CS is as follows. (73) AdvAUX−2−CS(pti)≤HQ2|HS|+HP2|PUS|+max⁡{C′⋅qrss′,qrs2le}+2⋅AdvAIND−CPA(pti)

Proof We establish the proof of Theorem 1 by analyzing the trailing five games GM0, GM1, GM2, GM3, and GM4 for UX-2-CS [8]. The adversary A's advantage in compromising the security of the secret session key is denoted as AdvAUX−2−CS(pti)=|2⋅AdvGM−1|. Here, “AdvGM” signifies the likelihood of A winning by accurately predicting the bit “b” in each game.

GM0: In this scenario, A launches a genuine attack on UX-2-CS AKA mechanisms. According to the success criteria, we have attained the intended result.(74) AdvAUX−2−CS(pti)=|2⋅AdvGM0−1|.

GM1: In this game, A can intercept messages like Mg1, Mg2, and Mg3 exchanged during AKA phase of UX-2-CS, through an eavesdropping attack facilitated by the query Execute(ΦUxI1,ΦCSyI2). After successfully intercepting Mg1, Mg2, and Mg3, A must generate a valid session key SKUx(=SKCSy)=H(Kf∥CHUxn∥RUxn∥K2∥Rk∥Ri∥Rj), which is created by combining both long-term and temporary random parameters. In the final phase of GM1, A performs the operations Reveal(ΦI1) to uncover the suspected secret key and Test(ΦI1) to compare the actual secret key with a random bit. Without access to both the long-term and temporary random parameters, A cannot generate a valid session key. Therefore, the probability of A succeeding is considered negligible. As a result, GM0 and GM1 become indistinguishable. Hence, we can infer that:(75) AdvGM1=AdvGM0

GM2: In this game, A employs a hash query to an oracle to launch an active attack. The hash function is utilized in the proposed UX-2-CS AKA mechanism for generating the encryption key and session key (SK) for the user and CSy, respectively. Additionally, the hash function is involved in generating Mg1:{Tg,W1,W2,W5,W6}, Mg2:{Th,W8,W9,W10,W11,W12}, and Mg3:{Ti,W12,W13,W14,W15,W16} during the AKA phase of UX-2-CS. By performing multiple hash searches, A aims to find collisions, thereby compromising the security of both the encryption key and SK. All communicated messages, such as Mg1, Mg2, and Mg3 during the AKA phases of UX-2-CS, contain elements of unpredictability due to the inclusion of secret parameters, timestamps, random integers, and identities. However, the probability of finding collisions is considered negligible, as illustrated by the birthday paradox. This low likelihood of collision also applies to PUF queries, similar to hash queries.(76) AdvGM2−AdvGM1≤HQ22|HS|+HP22|PUS|.

GM3: During the course of the game, A initiated an active attack by executing the Corrupt(ΦI1) query. Subsequently, upon successfully compromising the device used by the user, the attacker managed to obtain a set of credentials {Ctx2, RGDUx, W4, Gen(⋅), Rep(⋅)} stored in the device's memory. A's objective is to ascertain the user's password. By making password guesses, A can validate them using the extracted information Ctx2, RGDUx and W4 by leveraging Zipf's law on passwords [63], [64], [65], [66], [67]. In scenarios involving trawling guessing attacks, A's success rate exceeds 0.5 when qrs=107 or 108. Moreover, when A employs the target user's personal data in targeted guessing attacks, A's success rate surpasses 0.5 when qrs≤106. Additionally, since FE in UX-2-CS can extract a maximum of le random bits, the likelihood of A guessing the biometric key σUx∈{0,1}le is approximately 2le [58], [68]. However, the likelihood of accurately guessing the biometric key is extremely low, approximately 121e, due to the inherent difficulty in guessing biometric data. Furthermore, the system imposes limitations on the number of failed password attempts allowed. If the system restricts the number of incorrect password attempts, Zipf's law on passwords leads to the following result:(77) AdvGM3−AdvGM2≤max⁡{C′⋅qrss′,qrs2le}.

GM4: In this gaming scenario, A employs Execute(ΦUxI1,ΦCSyI2) to capture three messages: Mg1:{Tg,W1,W2,W5,W6}, Mg2:{Th,W8,W9,W10,W11,W12}, and Mg3:{Ti,W12,W13,W14,W15,W16}. All messages exchanged during the AKA phase of UX-2-CS are encrypted using the AES-CBC encryption algorithm. Upon obtaining these messages, A aims to uncover all confidential data that was encrypted and transmitted between the user and CSy. To achieve this, A must compromise the security of the AES-CBC mechanism. The following objective is achieved:(78) AdvGM4−AdvGM3≤AdvAIND−CPA(pti)

Upon completion of all games, A fails to attain a considerable advantage in accurately forecasting the bit “b”. Therefore, we conclude that(79) AdvGM4=1/2

From (74) and (75), we get(80) AdvAUX−2−CS(pti)=|2⋅AdvGM0−12|.

From (80), we get(81) 12.AdvAUX−2−CS(pti)=|AdvGM0−AdvGM4|.

By using (79) and (81), we obtain(82) 12.AdvAUX−2−CS(pti)=|AdvGM1−AdvGM4|

Upon considering the triangular inequality, we have(83) |AdvI1−AdvGM4|≤|AdvGM1−AdvGM2|+|AdvGM2−AdvGM4|≤|AdvGM1−AdvGM2|+|AdvGM2−AdvGM3|+|AdvGM3−AdvGM4|.

By using (76), (78), and (83), we get(84) AdvAUX−2−CS(pti)≤HQ2|HS|+HP2|PU|+max⁡{C′⋅qrss′,qrs2le}+2.AdvAIND−CPA(pti).

 □

5.3 Security evaluation of IoTD-2-CS and the UX-2-CS AKA mechanisms using scyther

We utilized the Scyther tool to assess the security robustness of the proposed IoTD-2-CS and the UX-2-CS AKA mechanisms. Scyther employs the Security Protocol Description Language (SPDL) to express code, providing a reliable simulation environment. We opted for Scyther over AVISPA due to the several advantages it offers. Notably, it excels in identifying multi-protocol attacks, assumes the coexistence of multiple protocols on the same network, utilizes SPDL as its primary language, facilitates the identification of multi-protocol attacks, and supports both finite and unbounded session counts. Additionally, Scyther generates attack graphs if attacks are detected within the protocol and allows protocol assessment with a predetermined or infinite number of sessions. Scyther serves as an automated tool for evaluating, confirming, and assessing security frameworks and methods. Its unique features make it a valuable asset, publicly accessible for use. Particularly, Scyther's “pattern refinement algorithm” aids in providing concise representations of trace sets, aiding in categorizing potential protocol actions and security issues. Its widespread usage within research circles attests to its efficiency. In evaluating the IoTD-2-CS AKA and UX-2-CS AKA mechanisms, implementations are conducted using SPDL. Scyther evaluates the SPDL script representing two essential roles for UX-2-CS: Ux for the user and CSy for the medical cloud server. Similarly, Scyther assesses the SPDL script representing two crucial roles for IoTD-2-CS: ITDk for the IoT device and CSy for the medical cloud server. The SPDL script, as illustrated in Fig. 5 and Fig. 6 comprises various claims associated with each role, all of which are verified by Scyther.Figure 5 Security analysis of IoTD-2-CS AKA mechanism using the Scyther tool.

Figure 5

Figure 6 Security analysis of UX-2-CS AKA mechanism using the Scyther tool.

Figure 6

6 Results and performance analysis

We assess the efficiency of the proposed IoTD-2-CS AKA mechanism in terms of computational cost, communication overhead, and security functionalities. For simulating the cloud server, IoT and user devices, we employ Raspberry Pi 3 B+ Rev 1.3, running Ubuntu 20.04 LTS (64-bit OS), with a 1.4 GHz quad-core processor, 4 cores, and 1 GB of RAM. We use the cryptographic library “MIRACL” for implementing the all the cryptographic primitives used in the proposed IoTD-2-CS and UX-2-CS AKA mechanisms and related security schemes. The execution time for each primitive is provided in Table 4 [69], [70].Table 4 Average Computational Time for Cryptographic Primitives.

Table 4Cryptographic Primitive	Symbol	Average Computational Time (ms)	
ECC Multiplication	TEM	2.88	
ECC Addition	TEA	0.016	
Hash Algorithms	TH	0.309	
Fuzzy Extractors	TFE	2.88	
Bi-linear Pairings	TBP	32.08	
Symmetric Encryption/Decryption	TENC	0.018/0.014	
Physical Unclonable Functions	TPF	0.00054 [71]	
Exponential	TEX	0.039	

6.1 Security features analysis

The security feature of the proposed IoTD-2-CS and UX-2-CS AKA mechanism are compared with the related AKA schemes. Table 5 provides a comparison of the security features between the proposed AKA mechanisms and their associated security schemes. It clearly shows that the proposed AKA mechanism offers enhanced security features, notably through the integration of the PUF function at the medical cloud server side. Moreover, the PUF is used to generate the secret key for the medical cloud server, which is not explicitly stored in the server's database. This effectively prevents insider attacks from accessing the secret key of the medical cloud server. This approach helps in preventing privileged insider attacks within the proposed AKA mechanisms, a guarantee not offered by other related security schemes.Table 5 Analysis of Security Function.

Table 5AKA Mechanism	SFEA-A	SFEA-B	SFEA-C	SFEA-D	SFEA-E	SFEA-F	SFEA-G	SFEA-H	SFEA-I	
Ref. [48]	×	×	✓	✓	✓	✓	×	✓	-	
Ref. [49]	✓	×	✓	✓	✓	✓	×	✓	-	
Ref. [50]	✓	×	✓	✓	✓	✓	×	✓	-	
Ref. [55]	✓	×	✓	✓	✓	✓	×	✓	-	
Ref. [52]	✓	×	✓	✓	✓	✓	×	✓	✓	
Ref. [53]	✓	×	✓	✓	✓	✓	×	✓	✓	
Ref. [54]	✓	×	✓	✓	✓	✓	×	✓	✓	
Ref. [51]	✓	×	✓	✓	✓	✓	×	✓	✓	
UX-2-CS	✓	✓	✓	✓	✓	✓	✓	✓	✓	
IoTD-2-CS	✓	✓	✓	✓	✓	✓	✓	✓	N/A	
SFEA-A: “Impersonation Attack”; SFEA-B: “PUF functionality”; SFEA-C: “MITM Attack”; SFEA-D: “Anonymity”; SFEA-E: “Mutual Authentication”; SFEA-F: “Replay Attack”; SFEA-G: “Privileged Insider Attack”, SFEA-H: “DoS Attack”, SFEA-I: “Password Guessing Attack”; ✓: “reflects the function's supported”; ×: “signifies the not supported feature.”.

6.2 Computational cost analysis

In this subsection, we analyze the computational cost required to complete the IoTD-2-CS AKA mechanism and the UX-2-CS AKA mechanism. The computational cost of the IoTD-2-CS AKA mechanism is 14.4 ms, which is 84.46%, 95.80%, 78.59%, and 75.15% less than Ref. [52], Ref. [53], Ref. [54], and Ref. [55], respectively. A comparison of the computational cost between the IoTD-2-CS AKA mechanism and related security schemes is presented in Table 6 and Fig. 7(b). Similarly, the computational cost of the UX-2-CS AKA mechanism is 86.25%, 72.76%, 69.51%, and 71.06% less than Ref. [48], Ref. [49], Ref. [50], and Ref. [51], respectively. A comparison of the computational cost between the UX-2-CS AKA mechanism and related security schemes is provided in Table 6 and Fig. 7(d). During the AKA phase, communication happens through an open channel, making it vulnerable to various attacks such as jamming and eavesdropping. These attacks can disrupt the execution of the AKA phase, leading to increased computational time. This scenario is illustrated in Fig. 7(a) and Fig. 7(c).Table 6 Computational Cost Analysis of IoTD-2-CS and UX-2-CS AKA Mechanisms.

Table 6AKA Mechanism	Computational Cost for UX-2-CS	
Ref. [48]	3TBP + 9TEM + 4TEX + 5EA + 9TH ≈ 125.81 ms	
Ref. [49]	TBP + 10TEM + TEX + TEA + 7TH ≈ 63.10 ms	
Ref. [50]	TBP + 7TEM + 2TEA + 4TEX + 13TH ≈ 56.44 ms	
Ref. [51]	20TEM + TEA + 6TH ≈ 58 ms	
UX-2-CS	17TH + 4TFE + 24TENC + 2TPF ≈ 17.21 ms	
	
AKA Mechanism	Computational Cost for IoTD-2-CS	
	
Ref. [52]	23TEM + 23TH ≈ 73.35 ms	
Ref. [53]	4TBP + 47TEM + 26TH ≈ 271.71 ms	
Ref. [54]	13TEM + 2TFE + 4TEX + 32TH ≈ 53.24 ms	
Ref. [55]	14TEM + 18TH ≈ 45.88 ms	
IoTD-2-CS	8TH + 3TFE + 16TENC + 2PF ≈ 11.4 ms	

Figure 7 Comparison of computational and communication costs.

Figure 7

6.3 Communication cost analysis

In this subsection, we estimate the communication of both the IoTD-2-CS AKA mechanism and the UX-2-CS AKA mechanism. To estimate the communication cost for both mechanisms, we assume the length of various parameters as follows: ECC point size is 320 bits, hash algorithm output length is 256 bits, random numbers are 128 bits, the AES-CBC block size is 128 bits, the AES-CBC key size is 256 bits, the initialization vector size is 128 bits, challenge size is 128 bits, response size is 128 bits, timestamp is of 32 bits size, identity size is 128 bits, and biometric key length is 256 bits. During the executing of the IoTD-2-CS AKA mechanism there are following message exchange to set up session key M1:{Tx,Y1,Y2,Y4}, M2:{Ty,Y6,Y7,Y8,Y9,Y10}, and M3:{Tz,RGDi⁎,Y12,Y13,Y14,Y15}. The sizes of M1, M2, and M3 are 544 bits, 800 bits, and 832 bits, respectively, totaling 2176 bits to complete the AKA phase of the IoTD-2-CS AKA mechanism. In comparison, related security schemes such as Ref. [52], Ref. [53], Ref. [54], and Ref. [55] require 3360 bits, 8576 bits, 3660 bits, and 4416 bits, respectively. It is noteworthy that the IoTD-2-CS AKA mechanism entails 40.55%, 74.62%, 35.24%, and 50.72% less communication cost compared to schemes Ref. [52], Ref. [53], Ref. [54], and Ref. [55], respectively. Table 7 and Fig. 7(f) provide a comparative analysis of the communication costs during the IoTD-2-CS AKA mechanism. During the AKA phase, communication ensues via an open channel, making it susceptible to various attacks such as jamming and eavesdropping. These attacks can disrupt the execution of the AKA phase and increase the communication cost. This is illustrated in Fig. 7(e).Table 7 Communication Cost Analysis of UX-2-CS and IoTD-2-CS AKA Mechanisms.

Table 7AKA Mechanism	Communication Cost (bits)	
Ref. [48]	5632	
Ref. [49]	5284	
Ref. [50]	4736	
Ref. [51]	3264	
UX-2-CS	2430	
	
AKA Mechanism	Communication Cost (bits)	
	
Ref. [52]	3360	
Ref. [53]	8576	
Ref. [54]	3660	
Ref. [55]	4416	
IoTD-2-CS	2176	

Similarly, during the execution of the UX-2-CS AKA mechanism, the following message exchanges occur to establish the session key: Mg1:{Tg,W1,W2,W5,W6}, Mg2:{Th,W8,W9,W10,W11,W12, Mg3:{Ti,W12,W13,W14,W15,W16}. The sizes of Mg1, Mg2, and Mg3 are 800 bits, 800 bits, and 830 bits, respectively, totaling 2430 bits to complete the AKA phase of the IoTD-2-CS AKA mechanism. In contrast, related security schemes such as Ref. [48], Ref. [49], Ref. [50], and Ref. [51] require 5632 bits, 5284 bits, 4736 bits, and 3264, respectively. It's noteworthy that the UX-2-CS AKA mechanism entails 56.85%, 54.01%, 48.69%, and 25.55% less communication cost compared to schemes Ref. [48], Ref. [49], Ref. [50], and Ref. [51], respectively. Table 7 and Fig. 7(h) provide a comparative analysis of the communication costs during the UX-2-CS AKA mechanism. The AKA phase takes place over an open communication channel, making it vulnerable to attacks like jamming and eavesdropping. Such attacks can interfere with the AKA phase, resulting in higher communication costs. This scenario is depicted in Fig. 7(g).

Given the numerous users in the healthcare system accessing data from the cloud server simultaneously, along with many IoT devices collecting patient data and sending it to the cloud, it is essential to reduce bandwidth requirements during the AKA phase. The bandwidth requirements comparison between the proposed AKA mechanisms and related AKA mechanisms is shown in Fig. 8 and Fig. 9.Figure 8 Bandwidth requirement of IoTD-2-CS AKA mechanism and related AKA mechanisms.

Figure 8

Figure 9 Bandwidth requirement of UX-2-CS AKA mechanism and related AKA mechanisms.

Figure 9

7 Conclusion

Smart healthcare applications incorporate a mixture of IoT devices, wearables, sensors, and data analytics to oversee patient health, manage medical records, and facilitate remote consultations. Nevertheless, the implementation of these applications has raised significant security concerns. To meet the security requirements, this paper introduced two AKA mechanisms, IoTD-2-CS and UX-2-CS, which utilize physical unclonable functions, symmetric encryption, and hash functions to bolster security. In IoTD-2-CS and UX-2-CS, a session key was established between the IoT device, user, and cloud server through mutual authentication to enable encrypted communication. Informal security analysis demonstrated the resilience of these proposed mechanisms against various attacks. Furthermore, the efficiency of the AKA mechanisms was assessed against other security mechanisms, revealing that the UX-2-CS AKA mechanism required 69 to 86.25 percent less computational cost and 25.55 to 56.85 percent lower communication cost. Additionally, the IoTD-2-CS AKA mechanism for IoT devices required 75 to 95.80 percent less computational cost and 35.24 to 74.62 percent lower communication cost. These results advocate that the proposed AKA mechanisms are appropriate for healthcare applications.

CRediT authorship contribution statement

Omar Alruwaili: Writing – original draft, Validation, Investigation, Funding acquisition, Formal analysis, Data curation, Conceptualization. Muhammad Tanveer: Writing – review & editing, Writing – original draft, Visualization, Software, Methodology, Formal analysis, Data curation, Conceptualization. Faisal Mohammed Alotaibi: Visualization, Validation, Resources, Investigation, Funding acquisition, Conceptualization. Waleed Abdelfattah: Visualization, Supervision, Resources, Methodology, Investigation, Formal analysis. Ammar Armghan: Writing – review & editing, Visualization, Supervision, Project administration, Investigation, Funding acquisition, Data curation, Conceptualization. Faeiz M. Alserhani: Validation, Supervision, Resources, Methodology, Investigation, Funding acquisition, Formal analysis, Conceptualization.

Declaration of Competing Interest

The authors declare the following financial interests/personal relationships which may be considered as potential competing interests: Ammar reports a relationship with Al Jouf University that includes: employment. Ammar has patent n/a pending to n/a. The authors of this manuscript would like to declare that there are no conflicts of interest regarding the publication of this paper. We confirm that there has been no financial support or personal relationships that could have appeared to influence the work reported in this manuscript.

If there are other authors, they declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.

Data availability

No external data is used in this paper, and all the data generated are part of the paper.

Acknowledgement

This work was funded by the Deanship of Graduate Studies and Scientific Research at Jouf University under grant No. (DGSSR-2023-02-02355 ).
==== Refs
References

1 Chen C.-M. Chen Z. Das A.K. Chaudhry S.A. A security-enhanced and ultra-lightweight communication protocol for internet of medical things IEEE Int. Things J. 2023
2 Chen C.-M. Chen Z. Kumari S. Obaidat M.S. Rodrigues J.J.P.C. Khan M.K. Blockchain-based mutual authentication protocol for iot-enabled decentralized healthcare environment IEEE Int. Things J. 2024 1 10.1109/JIOT.2024.3396488
3 Srivastava A. Kumar A. Efficient Methods for Authentication for Internet-of-Things Devices Based on e-Health Scheme Artificial Intelligence, Blockchain, Computing and Security vol. 2 2024 CRC Press 407 412
4 Abbasi I.A. Jan S.U. Alqahtani A.S. Khan A.S. Algarni F. A lightweight and robust authentication scheme for the healthcare system using public cloud server PLoS ONE 19 1 2024 e0294429
5 Arpitha T. Chouhan D. Shreyas J. Anonymous and robust biometric authentication scheme for secure social iot healthcare applications J. Eng. Appl. Sci. 71 1 2024 8
6 Bathalapalli V.K. Mohanty S.P. Kougianos E. Iyer V. Rout B. Pufchain 3.0: hardware-assisted distributed ledger for robust authentication in healthcare cyber–physical systems Sensors 24 3 2024 938 38339656
7 Chen X. Wang B. Li H. A privacy-preserving multi-factor authentication scheme for cloud-assisted iomt with post-quantum security J. Inf. Secur. Appl. 81 2024 103708
8 Tanveer M. Bashir A.K. Alzahrani B.A. Albeshri A. Alsubhi K. Chaudhry S.A. Cadf-cse: chaotic map-based authenticated data access/sharing framework for iot-enabled cloud storage environment Phys. Commun. 59 2023 102087
9 Chen C.-M. Chen Z. Kumari S. Obaidat M.S. Rodrigues J.J. Khan M.K. Blockchain-based mutual authentication protocol for iot-enabled decentralized healthcare environment IEEE Int. Things J. 2024
10 Tanveer M. Chelloug S.A. Ahmad M. Abd El-Latif A.A. Leaf-iiot: lightweight and efficient authentication framework for the industrial internet of things IEEE Access 2024
11 Tanveer M. Ahmad M. Nguyen T.N. Abd El-Latif A.A. Resource-efficient authenticated data sharing mechanism for smart wearable systems IEEE Trans. Netw. Sci. Eng. 2022
12 Hasan M.K. Weichen Z. Safie N. Ahmed F.R.A. Ghazal T.M. A survey on key agreement and authentication protocol for internet of things application IEEE Access 2024
13 Hussien Z.A. Jin H. Abduljabbar Z.A. Hussain M.A. Yassin A.A. Abbdal S.H. Al Sibahee M.A. Zou D. Secure and efficient e-health scheme based on the internet of things 2016 IEEE International Conference on Signal Processing, Communications and Computing (ICSPCC) 2016 1 6 10.1109/ICSPCC.2016.7753621
14 Chen Y. Ge Y. Wang Y. Zeng Z. An improved three-factor user authentication and key agreement scheme for wireless medical sensor networks IEEE Access 7 2019 85440 85451 10.1109/ACCESS.2019.2923777
15 Gupta D.S. Islam S.H. Obaidat M.S. Karati A. Sadoun B. Laac: lightweight lattice-based authentication and access control protocol for e-health systems in iot environments IEEE Syst. J. 15 3 2021 3620 3627 10.1109/JSYST.2020.3016065
16 Adeli M. Bagheri N. Maimani H.R. Kumari S. Rodrigues J.J.P.C. A post-quantum compliant authentication scheme for iot healthcare systems IEEE Int. Things J. 11 4 2024 6111 6118 10.1109/JIOT.2023.3309931
17 Wazid M. Das A.K. Kumar N. Rodrigues J.J.P.C. Secure three-factor user authentication scheme for renewable-energy-based smart grid environment IEEE Trans. Ind. Inform. 13 6 2017 3144 3153 10.1109/TII.2017.2732999
18 Roy S. Chatterjee S. Das A.K. Chattopadhyay S. Kumari S. Jo M. Chaotic map-based anonymous user authentication scheme with user biometrics and fuzzy extractor for crowdsourcing internet of things IEEE Int. Things J. 5 4 2018 2884 2895 10.1109/JIOT.2017.2714179
19 Islam S.H. Vijayakumar P. Bhuiyan M.Z.A. Amin R. Rajeev M. V. Balusamy B. A provably secure three-factor session initiation protocol for multimedia big data communications IEEE Int. Things J. 5 5 2018 3408 3418 10.1109/JIOT.2017.2739921
20 Zhu H. Hao X. A provable authenticated key agreement protocol with privacy protection using smart card based on chaotic maps Nonlinear Dyn. 81 2015 311 321
21 Liu Y. Xue K. An improved secure and efficient password and chaos-based two-party key agreement protocol Nonlinear Dyn. 84 2016 549 557
22 Tsai J.-L. Lo N.-W. Wu T.-C. Novel anonymous authentication scheme using smart cards IEEE Trans. Ind. Inform. 9 4 2012 2004 2013
23 Jiang Q. Wei F. Fu S. Ma J. Li G. Alelaiwi A. Robust extended chaotic maps-based three-factor authentication scheme preserving biometric template privacy Nonlinear Dyn. 83 2016 2085 2101
24 Tanveer M. Chelloug S.A. Alabdulhafith M. El-Latif A.A.A. Lightweight authentication protocol for connected medical iot through privacy-preserving access Egypt. Inform. J. 26 2024 100474 10.1016/j.eij.2024.100474 https://www.sciencedirect.com/science/article/pii/S1110866524000379
25 Li X. Peng J. Obaidat M.S. Wu F. Khan M.K. Chen C. A secure three-factor user authentication protocol with forward secrecy for wireless medical sensor network systems IEEE Syst. J. 14 1 2019 39 50
26 Masud M. Gaba G.S. Choudhary K. Hossain M.S. Alhamid M.F. Muhammad G. Lightweight and anonymity-preserving user authentication scheme for iot-based healthcare IEEE Int. Things J. 9 4 2021 2649 2656
27 Koya A.M. Deepthi P. Anonymous hybrid mutual authentication and key agreement scheme for wireless body area network Comput. Netw. 140 2018 138 151
28 Gupta A. Tripathi M. Sharma A. A provably secure and efficient anonymous mutual authentication and key agreement protocol for wearable devices in wban Comput. Commun. 160 2020 311 325
29 Tanveer M. Alkhayyat A. Chaudhry S.A. Zikria Y.B. Kim S.W. Reas-tmis: resource-efficient authentication scheme for telecare medical information system IEEE Access 10 2022 23008 23021
30 Kumar P. Lee S.-G. Lee H.-J. E-sap: efficient-strong authentication protocol for healthcare applications using wireless medical sensor networks Sensors 12 2 2012 1625 1647 22438729
31 He D. Kumar N. Chen J. Lee C.-C. Chilamkurti N. Yeo S.-S. Robust anonymous authentication protocol for health-care applications using wireless medical sensor networks Multimed. Syst. 21 2015 49 60
32 Wu F. Xu L. Kumari S. Li X. An improved and anonymous two-factor authentication protocol for health-care applications with wireless medical sensor networks Multimed. Syst. 23 2017 195 205
33 Srinivas J. Mishra D. Mukhopadhyay S. A mutual authentication framework for wireless medical sensor networks J. Med. Syst. 41 2017 1 19 27817129
34 Amin R. Islam S.H. Biswas G. Khan M.K. Kumar N. A robust and anonymous patient monitoring system using wireless medical sensor networks Future Gener. Comput. Syst. 80 2018 483 495
35 Ali R. Pal A.K. Kumari S. Sangaiah A.K. Li X. Wu F. An enhanced three factor based authentication protocol using wireless medical sensor networks for healthcare monitoring J. Ambient Intell. Humaniz. Comput. 2018 1 22
36 Bayat M. Das A.K. Pournaghi M. Far H.A.N. Fotuhi M. Doostari M. A lightweight and secure two-factor authentication scheme for wireless body area networks in health-care iot Comput. Netw. Int. J. Comput. Telecommun. 1 1 2020
37 Chen C.-M. Li Z. Chaudhry S.A. Li L. Attacks and solutions for a two-factor authentication protocol for wireless body area networks Secur. Commun. Netw. 2021 2021 1 12
38 He D. Zeadally S. Authentication protocol for an ambient assisted living system IEEE Commun. Mag. 53 1 2015 71 77
39 Aldosary A. Tanveer M. Paaf-shs: puf and authenticated encryption based authentication framework for the iot-enabled smart healthcare system Int. Things 26 2024 101159 10.1016/j.iot.2024.101159
40 Amintoosi H. Nikooghadam M. Shojafar M. Kumari S. Alazab M. Slight: a lightweight authentication scheme for smart healthcare services Comput. Electr. Eng. 99 2022 107803
41 Kumari A. Kumar V. Abbasi M.Y. Kumari S. Chaudhary P. Chen C.-M. Csef: cloud-based secure and efficient framework for smart medical system using ecc IEEE Access 8 2020 107838 107852 10.1109/ACCESS.2020.3001152
42 Hajian R. ZakeriKia S. Erfani S. Mirabi M. Shaparak: scalable healthcare authentication protocol with attack-resilience and anonymous key-agreement Comput. Netw. 183 2020 107567 10.1016/j.comnet.2020.107567 https://www.sciencedirect.com/science/article/pii/S1389128620312147
43 Wu Z.-Y. Lee Y.-C. Lai F. Lee H.-C. Chung Y. A secure authentication scheme for telecare medicine information systems J. Med. Syst. 36 2012 1529 1535 20978928
44 Debiao H. Jianhua C. Rui Z. A more secure authentication scheme for telecare medicine information systems J. Med. Syst. 36 2012 1989 1995 21360017
45 Jiang Q. Khan M.K. Lu X. Ma J. He D. A privacy preserving three-factor authentication protocol for e-health clouds J. Supercomput. 72 2016 3826 3849
46 Wang W. Chen Q. Yin Z. Srivastava G. Gadekallu T.R. Alsolami F. Su C. Blockchain and puf-based lightweight authentication protocol for wireless medical sensor networks IEEE Int. Things J. 9 11 2021 8883 8891
47 Ryu J. Oh J. Kwon D. Son S. Lee J. Park Y. Park Y. Secure ecc-based three-factor mutual authentication protocol for telecare medical information system IEEE Access 10 2022 11511 11526 10.1109/ACCESS.2022.3145959
48 Irshad A. Sher M. Ahmad H.F. Alzahrani B.A. Chaudhry S.A. Kumar R. An improved multi-server authentication scheme for distributed mobile cloud computing services KSII Trans. Int. Inf. Syst. 10 12 2016 5529 5552
49 Li Y. Cheng Q. Liu X. Li X. A secure anonymous identity-based scheme in new authentication architecture for mobile edge computing IEEE Syst. J. 15 1 2020 935 946
50 Rakeei M. Moazami F. An efficient and provably secure authenticated key agreement scheme for mobile edge computing Wirel. Netw. 28 7 2022 2983 2999
51 Seifelnasr M. AlTawy R. Youssef A. Ghadafi E. Privacy-preserving mutual authentication protocol with forward secrecy for iot-edge-cloud IEEE Int. Things J. 2023
52 Porambage P. Braeken A. Schmitt C. Gurtov A. Ylianttila M. Stiller B. Group key establishment for enabling secure multicast communication in wireless sensor networks deployed for iot applications IEEE Access 3 2015 1503 1511
53 Yu B. Li H. Anonymous authentication key agreement scheme with pairing-based cryptography for home-based multi-sensor internet of things Int. J. Distrib. Sens. Netw. 15 9 2019 1550147719879379
54 Wazid M. Das A.K. Kumar N. Alazab M. Designing authenticated key management scheme in 6g-enabled network in a box deployed for industrial applications IEEE Trans. Ind. Inform. 17 10 2020 7174 7184
55 Wang K.-H. Chen C.-M. Fang W. Wu T.-Y. A secure authentication scheme for internet of things Pervasive Mob. Comput. 42 2017 15 26
56 Tanveer M. Aldosary A. Khokhar S.-u.-d. Das A.K. Aldossari S.A. Chaudhry S.A. Paf-iod: puf-enabled authentication framework for the internet of drones IEEE Trans. Veh. Technol. 2024 1 15 10.1109/TVT.2024.3365992
57 Dolev D. Yao A. On the security of public key protocols IEEE Trans. Inf. Theory 29 2 1983 198 208
58 Wazid M. Das A.K. Odelu V. Kumar N. Conti M. Jo M. Design of secure user authenticated key management protocol for generic iot networks IEEE Int. Things J. 5 1 2017 269 282
59 Wazid M. Das A.K. Odelu V. Kumar N. Susilo W. Secure remote user authenticated key establishment protocol for smart home environment IEEE Trans. Dependable Secure Comput. 17 2 2017 391 406
60 Yu S. Park K. Puf-based robust and anonymous authentication and key establishment scheme for v2g networks IEEE Int. Things J. 11 9 2024 15450 15464 10.1109/JIOT.2024.3349689
61 Tian C. Ma J. Li T. Zhang J. Ma C. Xi N. Provably and physically secure uav-assisted authentication protocol for iot devices in unattended settings IEEE Trans. Inf. Forensics Secur. 19 2024 4448 4463 10.1109/TIFS.2024.3379861
62 Hou W. Sun Y. Li D. Guan Z. Liu J. Lightweight and privacy-preserving charging reservation authentication protocol for 5g-v2g IEEE Trans. Veh. Technol. 72 6 2023 7871 7883 10.1109/TVT.2023.3241324
63 Wang D. Cheng H. Wang P. Huang X. Jian G. Zipf's law in passwords IEEE Trans. Inf. Forensics Secur. 12 11 2017 2776 2791
64 Wang D. Zhang Z. Wang P. Yan J. Huang X. Targeted online password guessing: an underestimated threat Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security 2016 1242 1254
65 Roy S. Das A.K. Chatterjee S. Kumar N. Chattopadhyay S. Rodrigues J.J. Provably secure fine-grained data access control over multiple cloud servers in mobile cloud computing based healthcare applications IEEE Trans. Ind. Inform. 15 1 2018 457 468
66 Wang D. Wang P. Two birds with one stone: two-factor authentication with security beyond conventional bound IEEE Trans. Dependable Secure Comput. 15 4 2016 708 722
67 Wang Q. Wang D. Cheng C. He D. Quantum2fa: efficient quantum-resistant two-factor authentication scheme for mobile devices IEEE Trans. Dependable Secure Comput. 20 1 2021 193 208
68 Srinivas J. Das A.K. Kumar N. Rodrigues J.J.P.C. Tcalas: temporal credential-based anonymous lightweight authentication scheme for internet of drones environment IEEE Trans. Veh. Technol. 68 7 2019 6903 6916 10.1109/TVT.2019.2911672
69 Bera B. Das A.K. Sutrala A.K. Private blockchain-based access control mechanism for unauthorized uav detection and mitigation in internet of drones environment Comput. Commun. 166 2021 91 109
70 Bera B. Saha S. Das A.K. Vasilakos A.V. Designing blockchain-based access control protocol in iot-enabled smart-grid system IEEE Int. Things J. 8 7 2020 5744 5761
71 Alladi T. Naren N. Bansal G. Chamola V. Guizani M. SecAuthUAV: a novel authentication scheme for UAV-ground station and UAV-UAV communication IEEE Trans. Veh. Technol. 10 2020 10.1109/TVT.2020.3033060
