[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126400-en":3,"doc-seo-126400-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126400,962085571259,"Theodora","https://ap-avatar.wpscdn.com/davatar_29158cc5080c5b710cf443261637dec0",8,"Research & Report","LSAP-IoHT - Lightweight Secure Authentication Protocol for the Internet of Healthcare Things","The Internet of Healthcare Things (IoHT) enables real-time, continuous, personalized monitoring, but exposed connectivity and wireless communication increase the risk to sensitive patient data. Common threats include unauthorized access, device compromise, data breaches, and data alteration, threatening confidentiality and integrity. The work analyzes LAP-IoHT, identifying vulnerabilities to impersonation and privileged insider threats, then proposes LSAP-IoHT using ECC, PUFs, and three-factor authentication. Security is validated via Scyther and the ROR model with low computation and communication overhead.","Tech Science Press  \nDoi:10.32604/cmc.2025.067641  \nARTICLE  \nLSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things  \nMarwa Ahmim1, Nour Ouafi1, Insaf Ullah2, *, Ahmed Ahmim3, Djalel Chefrour3 and Reham Almukhlifi4  \n1 Networks and Systems Laboratory, Department of Computer Science, Badji Mokhtar University, Annaba, 23000, Algeria 2 Institute for Analytics and Data Science, University of Essex, Colchester, CO4 3SQ, UK  \n3 Department of Computer Science, University of Souk-Ahras, Souk-Ahras, 41000, Algeria  \n4 Cybersecurity Department, College of Computer Science and Engineering, Taibah University, Medina, 42353, Saudi Arabia  \n*Corresponding Author: Insaf Ullah. Email: [Insaf.ullah@essex.ac.uk](Insaf.ullah@essex.ac.uk)  \nReceived: 08 May 2025; Accepted: 15 July 2025; Published: 23 October 2025  \nABSTRACT: The Internet of Healthcare Things (IoHT) marks a significant breakthrough in modern medicine by enabling a new era of healthcare services. IoHT supports real-time, continuous, and personalized monitoring of patients’ health conditions. However, the security of sensitive data exchanged within IoHT remains a major concern, as the widespread connectivity and wireless nature of these systems expose them to various vulnerabilities. Potential threats include unauthorized access, device compromise, data breaches, and data alteration, all of which may compromise the confidentiality and integrity of patient information. In this paper, we provide an in-depth security analysis of LAP-IoHT, an authentication scheme designed to ensure secure communication in Internet of Healthcare Things environments. This analysis reveals several vulnerabilities in the LAP-IoHT protocol, namely its inability to resist various attacks, including user impersonation and privileged insider threats. To address these issues, we introduce LSAP-IoHT, a secure and lightweight authentication protocol for the Internet of Healthcare Things (IoHT) . This protocol leverages Elliptic Curve Cryptography (ECC), Physical Unclonable Functions (PUFs), and Three-Factor Authentication (3FA) . Its security is validated through both informal analysis and formal verification using the Scyther tool and the Real-Or-Random (ROR) model. The results demonstrate strong resistance against man-in-the-middle (MITM) attacks, replay attacks, identity spoofing, stolen smart device attacks, and insider threats, while maintaining low computational and communication costs.  \nKEYWORDS: Internet of healthcare things (IoHT); authentication protocol; cryptanalysis; attacks  \n1 Introduction  \nThe Internet of Health Things (IoHT) represents a major innovation that integrates information technologies with medical care, forming an intelligent ecosystem of connected devices dedicated to health monitoring and management [1,2] . It encompasses a broad spectrum of technologies and application domains, ranging from biometric sensors and wearable devices to remote health monitoring platforms and connected medical equipment. IoHT is actively deployed in scenarios such as chronic disease management, emergency response, elderly care, postoperative recovery, and telemedicine. As illustrated in Fig. 1, these systems interact through wireless communication technologies, including Wi-Fi, Bluetooth, and cellular networks to collect, transmit, and analyze health data in real time [3,4] . By enabling continuous tracking of  \nCopyright © 2025 The Authors. Published by Tech Science Press.  \nThis work is licensed under a Creative Commons Attribution 4.0 International License, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.  \nvital parameters like heart rate, blood pressure, glucose levels, and respiratory signals, IoHT supports mobile health (mHealth), intelligent drug delivery, and personalized healthcare services.  \nShort-range communication Long-range communication  \nFigure 1: Internet of health things  \n","cbCainpFRFpvgfh3","https://ap.wps.com/l/cbCainpFRFpvgfh3","pdf",4766727,6,1,24,"English","en",105,"# Introduction\n## Motivation and Contribution","[{\"question\":\"What security issues does LAP-IoHT have in IoHT environments?\",\"answer\":\"LAP-IoHT cannot resist multiple attacks, including user impersonation and privileged insider threats, exposing IoHT authentication to serious compromise risks.\"},{\"question\":\"What is LSAP-IoHT and what technologies does it use?\",\"answer\":\"LSAP-IoHT is a lightweight, secure authentication protocol for IoHT. It leverages Elliptic Curve Cryptography (ECC), Physical Unclonable Functions (PUFs), and three-factor authentication (3FA).\"},{\"question\":\"How is the security of LSAP-IoHT validated?\",\"answer\":\"Security is validated through informal analysis and formal verification using the Scyther tool, supported by the Real-Or-Random (ROR) model.\"}]","LSAP-IoHT - Lightweight Secure Authentication Protocol for the Internet of Healthcare Things | PDF",1785904857,60,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"lsap-ioht-lightweight-secure-authentication-protocol-for-the-internet-of-healthcare-things","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/lsap-ioht-lightweight-secure-authentication-protocol-for-the-internet-of-healthcare-things/126400/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"What security issues does LAP-IoHT have in IoHT environments?","Question",{"text":77,"@type":78},"LAP-IoHT cannot resist multiple attacks, including user impersonation and privileged insider threats, exposing IoHT authentication to serious compromise risks.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"What is LSAP-IoHT and what technologies does it use?",{"text":82,"@type":78},"LSAP-IoHT is a lightweight, secure authentication protocol for IoHT. It leverages Elliptic Curve Cryptography (ECC), Physical Unclonable Functions (PUFs), and three-factor authentication (3FA).",{"name":84,"@type":75,"acceptedAnswer":85},"How is the security of LSAP-IoHT validated?",{"text":86,"@type":78},"Security is validated through informal analysis and formal verification using the Scyther tool, supported by the Real-Or-Random (ROR) model.","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,111,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":108,"doc_module":4,"doc_module_name":47,"category_name":109,"show_sort_weight":30,"slug":110},5,"Comic","comic",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":112,"show_sort_weight":113,"slug":114},"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":47,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":47,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":47,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":47,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":47,"category_name":137,"show_sort_weight":108,"slug":138},19,"General","general"]