Publications
Sort:
Open Access Article Issue
LSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things
Computers, Materials & Continua 2025, 85(3): 5093-5116
Published: 23 October 2025
Abstract PDF (4.5 MB) Collect
Downloads:11

The Internet of Healthcare Things (IoHT) marks a significant breakthrough in modern medicine by enabling a new era of healthcare services. IoHT supports real-time, continuous, and personalized monitoring of patients’ health conditions. However, the security of sensitive data exchanged within IoHT remains a major concern, as the widespread connectivity and wireless nature of these systems expose them to various vulnerabilities. Potential threats include unauthorized access, device compromise, data breaches, and data alteration, all of which may compromise the confidentiality and integrity of patient information. In this paper, we provide an in-depth security analysis of LAP-IoHT, an authentication scheme designed to ensure secure communication in Internet of Healthcare Things environments. This analysis reveals several vulnerabilities in the LAP-IoHT protocol, namely its inability to resist various attacks, including user impersonation and privileged insider threats. To address these issues, we introduce LSAP-IoHT, a secure and lightweight authentication protocol for the Internet of Healthcare Things (IoHT). This protocol leverages Elliptic Curve Cryptography (ECC), Physical Unclonable Functions (PUFs), and Three-Factor Authentication (3FA). Its security is validated through both informal analysis and formal verification using the Scyther tool and the Real-Or-Random (ROR) model. The results demonstrate strong resistance against man-in-the-middle (MITM) attacks, replay attacks, identity spoofing, stolen smart device attacks, and insider threats, while maintaining low computational and communication costs.

Open Access Issue
A hyperelliptic curve-based authenticated key agreement scheme for unmanned aerial vehicles in cross-domain environments
Chinese Journal of Aeronautics 2025, 38(10)
Published: 19 March 2025
Abstract Collect

Unmanned Aerial Vehicles (UAVs) are increasingly recognized for their pivotal role in military and civilian applications, serving as essential technology for transmitting, evaluating, and gathering information. Unfortunately, this crucial process often occurs through unsecured wireless connections, exposing it to numerous cyber-physical attacks. Furthermore, UAVs’ limited onboard computing resources make it challenging to perform complex cryptographic operations. The main aim of constructing a cryptographic scheme is to provide substantial security while reducing the computation and communication costs. This article introduces an efficient and secure cross-domain Authenticated Key Agreement (AKA) scheme that uses Hyperelliptic Curve Cryptography (HECC). The HECC, a modified version of ECC with a smaller key size of 80 bits, is well-suited for use in UAVs. In addition, the proposed scheme is employed in a cross-domain environment that integrates a Public Key Infrastructure (PKI) at the receiving end and a Certificateless Cryptosystem (CLC) at the sending end. Integrating CLC with PKI improves network security by restricting the exposure of encryption keys only to the message’s sender and subsequent receiver. A security study employing ROM and ROR models, together with a comparative performance analysis, shows that the proposed scheme outperforms comparable existing schemes in terms of both efficiency and security.

Total 2