Skip to main navigation Skip to search Skip to main content

LFAP: Lightweight and Flexible Authentication Protocol for Comprehensive Key Security in Wireless Body Area Networks

  • Jiayin Wang
  • , Chang Xu*
  • , Liehuang Zhu
  • , Yi Xu
  • , Hanqi Zhang
  • , Xinyue Ke
  • *Corresponding author for this work
  • Beijing Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

Wireless Body Area Networks (WBANs) have become an important component of modern healthcare systems. However, their broader deployment remains constrained by persistent security weaknesses in authentication and key management, particularly those related to private-key compromise. Existing schemes often fail to provide sufficient protection for cryptographic keys throughout their lifecycle, including both static storage and protocol execution. In this paper, we present LFAP, a lightweight authentication and key-agreement protocol for WBANs that explicitly prioritizes private-key security. LFAP integrates two complementary techniques. First, it employs Physical Unclonable Function (PUF) technology to provide tamper-resistant protection for private keys in static storage. Second, we improve the NAXOS mechanism to strengthen session-key establishment and prevent private-key leakage during dynamic protocol execution. Together, these mechanisms mitigate key-extraction and information-leakage risks across the entire key lifecycle. To further support the dynamic nature of WBAN environments, we propose a Modified Elastic Bloom Filter (MEBF) with efficient deletion capability, which enables lightweight authorized-MN selection and timely revocation. In addition, we introduce a new set of security evaluation criteria for WBAN authentication protocols, with particular emphasis on private-key protection. Under these criteria, rigorous security analysis shows that LFAP resists replay, impersonation, and key-compromise attacks while preserving private-key confidentiality. Experimental results further demonstrate that LFAP incurs low computational overhead and that the proposed MEBF operates efficiently, making the overall design well suited to resource-constrained WBAN devices. Compared with state-of-the-art schemes, LFAP achieves clear advantages in scalability and end-to-end latency.

Original languageEnglish
JournalIEEE Transactions on Mobile Computing
DOIs
Publication statusAccepted/In press - 2026
Externally publishedYes

Keywords

  • Authentication and key agreement protocol
  • Bloom filter
  • Physical unclonable function
  • Private-key confidentiality
  • WBANs

Fingerprint

Dive into the research topics of 'LFAP: Lightweight and Flexible Authentication Protocol for Comprehensive Key Security in Wireless Body Area Networks'. Together they form a unique fingerprint.

Cite this