Vulnerability Analysis of Privacy-Preserving Four-Factor Authentication for Medical IoT Environments and Sustainable Development Goals
Haewon Byeon · Journal of Lifestyle and SDGs Review · 2025
Objective: The objective of this study is to conduct a comprehensive analysis of a proposed four-factor authentication protocol designed for the Internet of Medical Things (IoMT), aiming to enhance security by integrating knowledge, possession, inherence, and device uniqueness factors. Theoretical Framework: This research is underpinned by security principles related to multi-factor authentication, focusing on the strengths and weaknesses of different authentication factors. The inherent vulnerabilities of IoMT devices, often resource-constrained, also form a critical part of the theoretical framework. Existing cryptographic techniques and their applicability within resource-constrained environments are considered. Method: This study employs a comprehensive analysis approach, examining the proposed four-factor authentication protocol for potential vulnerabilities. This includes a detailed review of the protocol's design, focusing on its implementation of biometric data protection, key management, session handling, and resource utilization. Potential attack vectors, such as session hijacking and data breaches, are considered. Results and Discussion: The analysis identified several vulnerabilities in the proposed protocol, including risks associated with biometric data protection, weaknesses in key management, susceptibility to session hijacking, and challenges in resource-constrained environments. These findings are discussed in the context of existing security best practices and the specific requirements of IoMT systems. Research Implications: This research has implications for the design and implementation of secure authentication protocols for IoMT. The identified vulnerabilities highlight the need for robust security measures, including advanced encryption methods, decentralized key management using blockchain, and the adoption of lightweight cryptographic algorithms. These improvements aim to fortify the protocol's security framework, ensuring the protection of sensitive medical data. Originality/Value: This study contributes to the literature by providing a comprehensive analysis of a novel four-factor authentication protocol for IoMT. The identification of specific vulnerabilities and the proposal of targeted enhancements offer valuable insights for researchers and practitioners in the field of IoMT security. The research also highlights future research directions, including exploring quantum-resistant cryptographic algorithms and developing adaptive security policies leveraging artificial intelligence, which are crucial for maintaining the protocol's resilience against evolving threats and ensuring the secure operation of IoMT systems.