This paper conducts a security analysis of a biometric and smartcard-based protocol for eHealth clouds, identifying weaknesses in key generation, forward secrecy, and replay attack resilience. An enhanced protocol is proposed, featuring ephemeral key ...
This paper conducts a security analysis of a biometric and smartcard-based protocol for eHealth clouds, identifying weaknesses in key generation, forward secrecy, and replay attack resilience. An enhanced protocol is proposed, featuring ephemeral key exchange, a fuzzy extractor for biometrics, and mutual nonce verification. Evaluation in IoT settings confirms it strengthens security against major threats with low computational overhead, providing a practical and efficient solution for eHealth systems.