Improvements for ECC-Based Three-Factor Authentication Protocols in IoT-Enabled e-Health Cloud Systems
This study critically analyzed a lightweight ECC-based three-factor authentication protocol designed for IoT-enabled e-Health cloud systems. Through adversarial modeling and formal verification, three core vulnerabilities were identified: static identity inference via XOR-cancellation across sessions, ephemeral key reuse leading to session key replay, and insufficient biometric template binding enabling cross-system correlation. Countermeasures proposed include dual-nonce ephemeral key diversification, salted fuzzy extractor-based biometric binding, dual-ephemeral Diffie–Hellman key exchange for forward secrecy, and a permissioned blockchain audit layer. Simulation results on Raspberry Pi 4 and Intel i5 demonstrate 100% replay detection, per-session forward secrecy, eliminated biometric linkability, and end-to-end latency increase within 6.7%, confirming suitability for resource-constrained IoT healthcare deployments.