SKAP: secure blockchain-based key agreement protocol for healthcare environment
摘要
The rapid advancement of wireless technology and cloud computing has significantly transformed various sectors, including healthcare, where security remains a critical concern. In the Internet of Things (IoT)-enabled healthcare systems, ensuring privacy, security, and trust remains a persistent challenge. Over the years, numerous approaches have been proposed to establish secure communication in IoT-driven healthcare applications. However, many of these solutions exhibit design flaws, vulnerabilities to various cyber threats, and dependence on trusted third parties or centralized storage, which pose risks to system integrity and data confidentiality. Rani and Tripathi recently introduced a blockchain-based authentication and key agreement protocol for securing healthcare systems to address these challenges. However, this paper demonstrates that their protocol remains vulnerable to several attacks, including insecure session key establishment, man-in-the-middle (MIM) attacks, forward secrecy violations, and critical flaws in the password and biometric update phases. To mitigate these weaknesses, we propose a modified authentication protocol (SKAP) that enhances security through informal and formal verification techniques. Our protocol provides better resilience against adversarial threats while maintaining low communication and storage overhead. Performance evaluation indicates that the proposed protocol significantly reduces storage overhead and communication cost with an average of