TY - JOUR
T1 - LFAP
T2 - Lightweight and Flexible Authentication Protocol for Comprehensive Key Security in Wireless Body Area Networks
AU - Wang, Jiayin
AU - Xu, Chang
AU - Zhu, Liehuang
AU - Xu, Yi
AU - Zhang, Hanqi
AU - Ke, Xinyue
N1 - Publisher Copyright:
© 2002-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Wireless Body Area Networks (WBANs) have become an important component of modern healthcare systems. However, their broader deployment remains constrained by persistent security weaknesses in authentication and key management, particularly those related to private-key compromise. Existing schemes often fail to provide sufficient protection for cryptographic keys throughout their lifecycle, including both static storage and protocol execution. In this paper, we present LFAP, a lightweight authentication and key-agreement protocol for WBANs that explicitly prioritizes private-key security. LFAP integrates two complementary techniques. First, it employs Physical Unclonable Function (PUF) technology to provide tamper-resistant protection for private keys in static storage. Second, we improve the NAXOS mechanism to strengthen session-key establishment and prevent private-key leakage during dynamic protocol execution. Together, these mechanisms mitigate key-extraction and information-leakage risks across the entire key lifecycle. To further support the dynamic nature of WBAN environments, we propose a Modified Elastic Bloom Filter (MEBF) with efficient deletion capability, which enables lightweight authorized-MN selection and timely revocation. In addition, we introduce a new set of security evaluation criteria for WBAN authentication protocols, with particular emphasis on private-key protection. Under these criteria, rigorous security analysis shows that LFAP resists replay, impersonation, and key-compromise attacks while preserving private-key confidentiality. Experimental results further demonstrate that LFAP incurs low computational overhead and that the proposed MEBF operates efficiently, making the overall design well suited to resource-constrained WBAN devices. Compared with state-of-the-art schemes, LFAP achieves clear advantages in scalability and end-to-end latency.
AB - Wireless Body Area Networks (WBANs) have become an important component of modern healthcare systems. However, their broader deployment remains constrained by persistent security weaknesses in authentication and key management, particularly those related to private-key compromise. Existing schemes often fail to provide sufficient protection for cryptographic keys throughout their lifecycle, including both static storage and protocol execution. In this paper, we present LFAP, a lightweight authentication and key-agreement protocol for WBANs that explicitly prioritizes private-key security. LFAP integrates two complementary techniques. First, it employs Physical Unclonable Function (PUF) technology to provide tamper-resistant protection for private keys in static storage. Second, we improve the NAXOS mechanism to strengthen session-key establishment and prevent private-key leakage during dynamic protocol execution. Together, these mechanisms mitigate key-extraction and information-leakage risks across the entire key lifecycle. To further support the dynamic nature of WBAN environments, we propose a Modified Elastic Bloom Filter (MEBF) with efficient deletion capability, which enables lightweight authorized-MN selection and timely revocation. In addition, we introduce a new set of security evaluation criteria for WBAN authentication protocols, with particular emphasis on private-key protection. Under these criteria, rigorous security analysis shows that LFAP resists replay, impersonation, and key-compromise attacks while preserving private-key confidentiality. Experimental results further demonstrate that LFAP incurs low computational overhead and that the proposed MEBF operates efficiently, making the overall design well suited to resource-constrained WBAN devices. Compared with state-of-the-art schemes, LFAP achieves clear advantages in scalability and end-to-end latency.
KW - Authentication and key agreement protocol
KW - Bloom filter
KW - Physical unclonable function
KW - Private-key confidentiality
KW - WBANs
UR - https://www.scopus.com/pages/publications/105044724249
U2 - 10.1109/TMC.2026.3712265
DO - 10.1109/TMC.2026.3712265
M3 - Article
AN - SCOPUS:105044724249
SN - 1536-1233
JO - IEEE Transactions on Mobile Computing
JF - IEEE Transactions on Mobile Computing
ER -