Mitigating Privacy Risks in IoT Healthcare Wearables: Simulated Side-Channel Attacks and Defense via Lightweight Encryption Techniques

Amaka Ngozi Obibueze · TRAP@NCI (National College of Ireland) · 2025

As internet-connected IoT healthcare devices increase, there is a need for robust ways to protect patient data and privacy. These IoT healthcare devices, such as wearables, often face security challenges due to limited battery life, processing power, and storage. While lightweight encryption methods like Simeck32/64 offer efficient alternatives, these devices remain vulnerable to side-channel attacks that exploit physical information leakage during cryptographic operations, potentially compromising patient privacy. This research evaluates the effectiveness of the lightweight Simeck32/64 cipher against Differential Power Analysis (DPA) attacks and examines masking countermeasures for healthcare IoT environments. Three implementations were developed and tested: unmasked, first-order Boolean masked, and second-order masked. The study collected 3,000 synthetic power traces from these implementations to assess their resistance to side-channel attacks and employed Welch's t-tests, Signal-to-Noise Ratio (SNR) measurements, and Guessing Entropy calculations. Results show that the unmasked implementation is highly vulnerable to DPA attacks, achieving a 98.7% success rate. This contrasts with both masked implementations, which lower attack success rates to 2.3% and 1.8% respectively. However, these security improvements impose substantial performance costs. First-order masking increased encryption time by 4.9× and energy consumption by 4.8×, while second-order masking resulted in 21.4× and 26.6× increases, respectively. Despite these overheads, the research demonstrates that lightweight masking techniques can effectively restore the security of Simeck32/64 from a compromised 2^32 search complexity to the full 2^64 complexity of key recovery. The findings suggest that first-order masking offers an optimal balance between security and performance for most healthcare applications, while second-order masking suits the most security-critical IoT healthcare wearables. This work establishes a comprehensive framework for implementing side-channel countermeasures in resource-constrained healthcare environments.

Read the paper · More papers on PaperTik