Rapid expansion of wireless body area networks (WBANs) has advanced the healthcare services. However, open communication channels pose significant security challenges. This study presents a lightweight mutual authentication and key agreement protocol for blockchain-enabled internet-of-medical-things (IoMT) systems. The scheme integrates biometric-based sensor management and employs smart contracts with system revocation lists to ensure the timely exclusion of compromised entities. By combining fog computing with blockchain, the framework offloads intensive computations from IoMT devices, thereby enhancing their scalability and efficiency. Security is strengthened through elliptic curve cryptography, cryptographic hash functions, and lightweight primitives, while formal validation using Burrows-Abadi-Needham (BAN) logic and the automated-validation-of-internet-security (AVISPA) tools confirms resistance to adversarial attacks. Moreover, it was implemented using the Ethereum platform and evaluated using Hyperledger-Caliper, demonstrating lower latency and higher throughput. A comparative analysis with relevant recent works in terms of performance and security requirements also proves its reliability and robustness.
Hireche et al. (Thu,) studied this question.