Security Vulnerability Analysis and Enhancement of a Lightweight Authentication Protocol for Cloud-Based Healthcare Cyber-Physical Systems
Medical Cyber-Physical Systems (MCPS) integrate IoT and cloud technologies for patient monitoring, requiring lightweight authentication. Nikkhah and Safkhani proposed LAPCHS, claiming formal security validation. This study re-examines LAPCHS, identifying three unresolved weaknesses: anonymity leakage via SID-MT1 dependency, desynchronization attacks by blocking AT4 updates, and tag impersonation risks from weak x'⊕y' masking. Equation-based attack traces explain each vulnerability. To mitigate these, we propose a redesigned MT1 with session randomness, a commit-and-confirm update procedure, and strengthened dual-masking for x'. Simulations confirm the improved protocol preserves lightweight costs while enhancing anonymity, synchronization resilience, and impersonation resistance. Keywords: RFID Authentication; MCPS; Cloud Healthcare; Lightweight Protocol; Vulnerability Analysis.