A robust and lightweight ECC-based authentication protocol for IoT-driven e-healthcare systems with provable security analysis
Ali Delham Algarni, Fahad Algarni, Ismail Mohamed Keshta, Saeed Ullah Jan · Journal of the Chinese Institute of Engineers · 2026
The Internet of Things (IoT), sensors, and wearables collect real-time physiological vitals from the patient’s body and transmit them to their destination through a wireless channel prone to several threats, including replay, denial-of-service (DoS) attacks, and pose privacy issues. However, if all the involved entities become securely authenticated, this, in turn, can minimize the mentioned threats and ensure the confidentiality, integrity, and privacy of patient-sensitive information. Therefore, this article presents a robust and lightweight authentication protocol for the IoT-driven e-healthcare system by utilizing Elliptic Curve Cryptographic (ECC) technique in which all the sensors/wearables or IoT devices that are operationalized in the e-healthcare system for real-time patient monitoring can be securely connected to the gateway to show strong resistance to all the known cyber-threats in such hostile environments and maintain patient privacy, confidentiality, integrity, and authorization. The security analysis was conducted using the well-known and widely used BAN (Burrows – Abadi – Needham) logic, ProVerif simulation, AVISPA validation, and ROM analysis. While the performance evaluation of the proposed protocol has been conducted by considering computation and communication costs, an 81.01% improvement has been recorded in terms of communication cost, and a 92.26% improvement in computation overhead, when compared with prior works.