Capability-Aware Authentication Mechanisms in the Internet of Medical Things (IoMT): A Systematic Literature Review
DOI:
https://doi.org/10.65204/djes.v3i3.957Abstract
The Internet of Medical Things (IoMT) has become an important component of modern healthcare systems by enabling continuous patient monitoring, remote healthcare services, and real-time medical data exchange. Despite these benefits, securing communications among interconnected medical devices remains a significant challenge due to the sensitive nature of healthcare information and the resource limitations of many IoMT devices. Authentication plays a central role in addressing these challenges by preventing unauthorized access and establishing trust among communicating entities. This paper presents a systematic literature review of authentication mechanisms developed for IoMT environments. Following the PRISMA 2020 methodology, relevant studies were collected from major scientific databases and analyzed according to their authentication techniques, security characteristics, and resource requirements. Unlike many existing reviews, this study adopts a capability-aware perspective by classifying authentication mechanisms according to the resource characteristics of the target devices, including ultra-constrained devices, resource-constrained devices, and resource-rich systems.The review shows that hash-based and physically unclonable function (PUF)-based approaches are generally suitable for highly constrained medical devices due to their low computational and energy requirements. For wearable and smart sensing devices, elliptic curve cryptography (ECC) and lightweight mutual authentication schemes provide a practical balance between security and efficiency. In contrast, resource-rich environments such as edge gateways and healthcare servers can support more sophisticated mechanisms, including public key infrastructure (PKI), blockchain-based authentication, and hybrid approaches. The findings indicate that no single authentication mechanism can satisfy the requirements of all IoMT environments. Instead, authentication design should consider both security requirements and device capabilities. The review also highlights current challenges related to scalability, heterogeneity, adaptive authentication, and post-quantum security, while identifying emerging opportunities for future IoMT authentication frameworks.
References
N. Alsaeed and F. Nadeem, “Authentication in the Internet of Medical Things: Taxonomy, Review, and Open Issues,” Appl. Sci., vol. 12, no. 15, p. 7487, Jul. 2022, doi: 10.3390/app12157487.
S. M. Riazul Islam, Daehan Kwak, M. Humaun Kabir, M. Hossain, and Kyung-Sup Kwak, “The Internet of Things for Health Care: A Comprehensive Survey,” IEEE Access, vol. 3, pp. 678–708, 2015, doi: 10.1109/ACCESS.2015.2437951.
F. Alsubaei, A. Abuhussein, and S. Shiva, “Security and Privacy in the Internet of Medical Things: Taxonomy and Risk Assessment,” in 2017 IEEE 42nd Conference on Local Computer Networks Workshops (LCN Workshops), Singapore: IEEE, Oct. 2017, pp. 112–120. doi: 10.1109/LCN.Workshops.2017.72.
L. Dzamesi and N. Elsayed, “A Review on the Security Vulnerabilities of the IoMT against Malware Attacks and DDoS”.
M. A. Khan, I. U. Din, T. Majali, and B.-S. Kim, “A Survey of Authentication in Internet of Things-Enabled Healthcare Systems,” Sensors, vol. 22, no. 23, p. 9089, Nov. 2022, doi: 10.3390/s22239089.
K. Kim, J. Ryu, Y. Lee, and D. Won, “An Improved Lightweight User Authentication Scheme for the Internet of Medical Things,” Sensors, vol. 23, no. 3, p. 1122, Jan. 2023, doi: 10.3390/s23031122.
A. Merchant, V. Panchami, S. Justine, and S. Eswaran, “An efficient lightweight authentication scheme for smart healthcare in IoMT applications,” Discov. Comput., vol. 28, no. 1, p. 261, Nov. 2025, doi: 10.1007/s10791-025-09779-9.
M. Tanveer, S. A. Chelloug, M. Alabdulhafith, and A. A. A. El-Latif, “Lightweight authentication protocol for connected medical IoT through privacy-preserving access,” Egypt. Inform. J., vol. 26, p. 100474, Jun. 2024, doi: 10.1016/j.eij.2024.100474.
A. S. Rajasekaran, A. Maria, M. Rajagopal, and J. Lorincz, “Blockchain Enabled Anonymous Privacy-Preserving Authentication Scheme for Internet of Health Things,” Sensors, vol. 23, no. 1, p. 240, Dec. 2022, doi: 10.3390/s23010240.
M. J. Page et al., “The PRISMA 2020 statement: an updated guideline for reporting systematic reviews,” BMJ, p. n71, Mar. 2021, doi: 10.1136/bmj.n71.
H. Geng, Ed., “Front Matter,” in Internet of Things and Data Analytics Handbook, 1st ed., Wiley, 2017. doi: 10.1002/9781119173601.fmatter.
S. Razdan and S. Sharma, “Internet of Medical Things (IoMT): Overview, Emerging Technologies, and Case Studies,” IETE Tech. Rev., vol. 39, no. 4, pp. 775–788, Jul. 2022, doi: 10.1080/02564602.2021.1927863.
A. Gatouillat, Y. Badr, B. Massot, and E. Sejdic, “Internet of Medical Things: A Review of Recent Contributions Dealing With Cyber-Physical Systems in Medicine,” IEEE Internet Things J., vol. 5, no. 5, pp. 3810–3822, Oct. 2018, doi: 10.1109/JIOT.2018.2849014.
S. E. El-deep, A. A. Abohany, K. M. Sallam, and A. A. A. El-Mageed, “A comprehensive survey on impact of applying various technologies on the internet of medical things,” Artif. Intell. Rev., vol. 58, no. 3, p. 86, Jan. 2025, doi: 10.1007/s10462-024-11063-z.
M. K. Patra, A. Kumari, B. Sahoo, and A. K. Turuk, “Smart Healthcare System Using Cloud-Integrated Internet of Medical Things:,” in Advances in Medical Technologies and Clinical Practice, R. Queirós, B. Cunha, and X. Fonseca, Eds., IGI Global, 2022, pp. 60–83. doi: 10.4018/978-1-6684-5260-8.ch004.
P. Matthew et al., “A Review of the State of the Art for the Internet of Medical Things,” Sci, vol. 7, no. 2, p. 36, Mar. 2025, doi: 10.3390/sci7020036.
M. A. G. Hazber et al., “Securing IoMT-Based Healthcare Systems with Meta-Heuristic Quantum Cryptography and Honeybee Optimization,” Dec. 12, 2024, In Review. doi: 10.21203/rs.3.rs-5447617/v1.
P. Verma, R. Tiwari, and W.-C. Hong, “Secure Authentication in IoT Based Healthcare Management Environment Using Integrated Fog Computing Enabled Blockchain System,” in Image Based Computing for Food and Health Analytics: Requirements, Challenges, Solutions and Practices, R. Tiwari, D. Koundal, and S. Upadhyay, Eds., Cham: Springer International Publishing, 2023, pp. 137–146. doi: 10.1007/978-3-031-22959-6_8.
M. Wazid, A. K. Das, S. Shetty, P. Gope, and J. J. P. C. Rodrigues, “Security in 5G-Enabled Internet of Things Communication: Issues, Challenges, and Future Research Roadmap,” IEEE Access, vol. 9, pp. 4466–4489, 2021, doi: 10.1109/ACCESS.2020.3047895.
R. Roman, J. Zhou, and J. Lopez, “On the features and challenges of security and privacy in distributed internet of things,” Comput. Netw., vol. 57, no. 10, pp. 2266–2279, Jul. 2013, doi: 10.1016/j.comnet.2012.12.018.
T.-Y. Wu, Q. Meng, S. Kumari, and P. Zhang, “Rotating behind Security: A Lightweight Authentication Protocol Based on IoT-Enabled Cloud Computing Environments,” Sensors, vol. 22, no. 10, p. 3858, May 2022, doi: 10.3390/s22103858.
P. K. Sadhu, V. P. Yanambaka, and A. Abdelgawad, “Internet of Things: Security and Solutions Survey,” Sensors, vol. 22, no. 19, p. 7433, Sep. 2022, doi: 10.3390/s22197433.
P. Gope and T. Hwang, “BSN-Care: A Secure IoT-Based Modern Healthcare System Using Body Sensor Network,” IEEE Sens. J., vol. 16, no. 5, pp. 1368–1376, Mar. 2016, doi: 10.1109/JSEN.2015.2502401.
M. S. Hossain and G. Muhammad, “Cloud-assisted Industrial Internet of Things (IIoT) – Enabled framework for health monitoring,” Comput. Netw., vol. 101, pp. 192–202, Jun. 2016, doi: 10.1016/j.comnet.2016.01.009.
M. Wazid, A. K. Das, V. Odelu, N. Kumar, M. Conti, and M. Jo, “Design of Secure User Authenticated Key Management Protocol for Generic IoT Networks,” IEEE Internet Things J., vol. 5, no. 1, pp. 269–282, Feb. 2018, doi: 10.1109/JIOT.2017.2780232.
M. A. Khan, I. U. Din, T. Majali, and B.-S. Kim, “A Survey of Authentication in Internet of Things-Enabled Healthcare Systems,” Sensors, vol. 22, no. 23, p. 9089, Nov. 2022, doi: 10.3390/s22239089.
Y. Gao, D. C. Ranasinghe, S. F. Al-Sarawi, O. Kavehei, and D. Abbott, “Emerging Physical Unclonable Functions With Nanotechnology,” IEEE Access, vol. 4, pp. 61–80, 2016, doi: 10.1109/ACCESS.2015.2503432.
A. H. Koblitz, N. Koblitz, and A. Menezes, “Elliptic curve cryptography: The serpentine course of a paradigm shift,” J. Number Theory, vol. 131, no. 5, pp. 781–814, May 2011, doi: 10.1016/j.jnt.2009.01.006.
S. Das and S. Namasudra, “Lightweight and efficient PRIVACY‐PRESERVING mutual authentication scheme to secure INTERNET OF THINGS ‐based smart healthcare,” Trans. Emerg. Telecommun. Technol., vol. 34, no. 11, p. e4716, Nov. 2023, doi: 10.1002/ett.4716.
W. Stallings, Cryptography and network security: principles and practice, 4th ed. Upper Saddle River, N.J: Pearson/Prentice Hall, 2006.
B. Alotaibi and M. Alotaibi, “Hybrid Deep Learning Framework for Continuous User Authentication Based on Smartphone Sensors,” Sensors, vol. 25, no. 9, p. 2817, Apr. 2025, doi: 10.3390/s25092817.