Acta Informatica Pragensia X:X | DOI: 10.18267/j.aip.32161
PQAC–BIoMT: Post-Quantum Authentication and Access Control Framework for Blockchain-Enabled IoMT Systems
- 1 Networks and Distributed Systems Laboratory, Ferhat Abbas University Setif 1, Setif, Algeria
- 2 Computer Science and Engineering Department, United International University, Dhaka, People's Republic of Bangladesh
- 3 Department of Computer Science, University of Sharjah, Sharjah, United Arab Emirates
Background: In recent years, the Internet of Medical Things (IoMT) has transformed the healthcare sector through real-time patient monitoring and continuous data collection. However, transmitting sensitive medical information over public networks exposes IoMT systems to significant security threats, while emerging quantum computing technologies challenge the reliability of traditional cryptographic systems.
Objective: The objective of this study is to propose PQAC-BIoMT, a secure and robust model for remote user authentication and access control in IoMT environments, capable of withstanding both conventional and quantum attacks.
Methods: This article proposes a decentralized authentication framework that integrates post-quantum cryptography using Kyber Public–Key Encryption (Kyber-PKE) into blockchain-based smart contracts. Fog computing nodes are used to reduce the authentication latency and improve the system scalability. A role-based authorization mechanism is integrated to link user identities to functional roles and enforce authorization to medical data and system resource access. Formal security verification is conducted using Burrows–Abadi–Needham (BAN) logic to validate the correctness of authentication, and the Automated Validation of Internet Security Protocols and Applications (AVISPA) tool is used to assess resistance to known attacks. PQAC-BIoMT is further evaluated through a comparative analysis of the computational load, energy consumption and security properties.
Results: Our security analysis demonstrates that PQAC-BIoMT effectively resists common attacks while providing quantum-resistant protection against them. The performance evaluation shows that the proposed scheme achieves relatively lower computational and energy overhead compared to existing approaches, making it suitable for resource-constrained IoMT devices.
Conclusion: The proposed PQAC-BIoMT scheme delivers a secure, quantum-resilient authentication and authorization mechanism for IoMT systems, enhancing both data protection and operational efficiency, which can support practical deployment in real-world IoMT applications.
Keywords: E-healthcare; Internet of medical things; Security; Key management; Authentication; Authorization; Blockchain; Post-quantum cryptography.
Received: February 8, 2026; Revised: May 19, 2026; Accepted: July 1, 2026; Prepublished online: August 27, 2026
References
- Ahmad, A., & Jagatheswari, S. (2026). PQ-ABS: Post-Quantum Aggregate Blind Signature-Based Anonymous Authentication for Blockchain-Enabled IOMT. IEEE Transactions on Information Forensics and Security, 21, 1542-1551. https://doi.org/10.1109/tifs.2026.3657031
Go to original source... - Alzoubi, Y. I., Al-Ahmad, A., & Kahtan, H. (2022). Blockchain technology as a Fog computing security and privacy solution: An overview. Computer Communications, 182, 129-152. https://doi.org/10.1016/j.comcom.2021.11.005
Go to original source... - Ashwini, D. Y., & Puneeth, R. P. (2026). Blockchain-Based framework for enhancing interoperability and security in EHR Exchange using lightweight ECC Proxy Re-Encryption. Acta Informatica Pragensia, 15(1), 90-108. https://doi.org/10.18267/j.aip.290
Go to original source... - Armando, A., Basin, D., Boichut, Y., Chevalier, Y., Compagna, L., Cuellar, J., Drielsma, P. H., Heám, P. C., Kouchnarenko, O., Mantovani, J., Mödersheim, S., Von Oheimb, D., Rusinowitch, M., Santiago, J., Turuani, M., Viganò, L., & Vigneron, L. (2005). The AVISPA tool for the automated validation of internet security protocols and applications. In Computer Aided Verification, CAV 2005, (pp. 281-285). Springer. https://doi.org/10.1007/11513988_27
Go to original source... - Bahache, A. N., Chikouche, N., & Akleylek, S. (2024). Securing Cloud-based Healthcare Applications with a Quantum-resistant Authentication and Key Agreement Framework. Internet of Things, 26, 101200. https://doi.org/10.1016/j.iot.2024.101200
Go to original source... - Boudgoust, K., Jeudy, C., Roux-Langlois, A., & Wen, W. (2022). On the Hardness of Module Learning with Errors with Short Distributions. Journal of Cryptology, 36(1), Article 1. https://doi.org/10.1007/s00145-022-09441-3
Go to original source... - Canetti, R., & Krawczyk, H. (2001). Analysis of key-exchange protocols and their use for building secure channels. In EUROCRYPT 2001, (pp. 453-474). Springer-Verlag. https://doi.org/10.1007/3-540-44987-6_28
Go to original source... - Chandrakar, P., Sinha, S., & Ali, R. (2020). Cloud-based authenticated protocol for healthcare monitoring system. Journal of Ambient Intelligence and Humanized Computing, 11(8), 3431-3447. https://doi.org/10.1007/s12652-019-01537-2
Go to original source... - Cui, Z., Xue, F., Zhang, S., Cai, X., Cao, Y., Zhang, W., & Chen, J. (2020). A hybrid BlockChain-Based identity authentication scheme for Multi-WSN. IEEE Transactions on Services Computing, 13(2), 241-251. https://doi.org/10.1109/tsc.2020.2964537
Go to original source... - Deebak, B. D., Al-Turjman, F., Aloqaily, M., & Alfandi, O. (2019). An Authentic-Based Privacy Preservation Protocol for smart e-Healthcare systems in IoT. IEEE Access, 7, 135632-135649. https://doi.org/10.1109/access.2019.2941575
Go to original source... - Dodis, Y., Reyzin, L., & Smith, A. (2004). Fuzzy Extractors: How to Generate Strong Keys from Biometrics and Other Noisy Data. In EUROCRYPT 2004, (pp. 523-540). Springer. https://doi.org/10.1007/978-3-540-24676-3_31
Go to original source... - Dolev, D., & Yao, A. (1983). On the security of public key protocols. IEEE Transactions on Information Theory, 29(2), 198-208. https://doi.org/10.1109/tit.1983.1056650
Go to original source... - Gautham, G. K., R, P. K., Rajan, A. A., V, V., & M, M. I. P. (2025). Healthchain: protecting healthcare data through blockchain with zero-knowledge proof and biometric-based access control. Journal of Cyber Security Technology, 10(1), 1-26. https://doi.org/10.1080/23742917.2025.2523760
Go to original source... - Hireche, R., Mansouri, H., & Pathan, A. K. (2022). Security and Privacy Management in Internet of Medical Things (IOMT): a synthesis. Journal of Cybersecurity and Privacy, 2(3), 640-661. https://doi.org/10.3390/jcp2030033
Go to original source... - Hireche, R., Mansouri, H., Harbi, Y., & Pathan, A. K. (2024). Robust Group Authentication Using Quantum Cryptography and Smart Contract for IoMT. In 2024 International Conference on Information and Communication Technologies for Disaster Management (ICT-DM). IEEE. https://doi.org/10.1109/ICT-DM62768.2024.10798936
Go to original source... - Hireche, R., Mansouri, H., Harbi, Y., Pathan, A. K., & Harous, S. (2025). Secure Post-Quantum Cryptography-based Authentication for Blockchain-Enabled IoMT Systems. In International Conference on Recent Advances in Mathematics and Informatics, (ICRAMI 2025). IEEE. https://doi.org/10.1109/ICRAMI64946.2025.11472719
Go to original source... - Hireche, R., Mansouri, H., Harbi, Y., & Pathan, A. S. K. (2026). Lightweight and resilient blockchain-enabled mutual authentication and key establishment protocol for smart health devices in IoMT. International Journal of Ad Hoc and Ubiquitous Computing, 51(3), 159-187. https://doi.org/10.1504/ijahuc.2026.152540
Go to original source... - Manolache, M. A., Manolache, S., & Tapus, N. (2022). Decision Making using the Blockchain Proof of Authority Consensus. Procedia Computer Science, 199, 580-588. https://doi.org/10.1016/j.procs.2022.01.071
Go to original source... - Hao, L., Wang, R., Wang, X., Yue, X., Tariq, N., & Sajid, A. (2025). Post-quantum-inspired scalable blockchain architecture for internet hospital systems with lightweight privacy-preserving access control. PLoS ONE, 20(12), e0332887. https://doi.org/10.1371/journal.pone.0332887
Go to original source... - Harbi, Y., Aliouat, Z., Harous, S., & Gueroui, A. M. (2024). Lightweight blockchain-based remote user authentication for fog-enabled IoT deployment. Computer Communications, 221, 90-105. https://doi.org/10.1016/j.comcom.2024.04.019
Go to original source... - Khajehzadeh, L., Barati, H., & Barati, A. (2025). L2AI: lightweight three-factor authentication and authorization in an IoMT blockchain-based environment with unsecure channel communication. Cluster Computing, 28(13), 865. https://doi.org/10.1007/s10586-025-05569-6
Go to original source... - Kumari, A., Kumar, V., Abbasi, M. Y., Kumari, S., Chaudhary, P., & Chen, C. (2020). CSEF: Cloud-Based Secure and Efficient Framework for Smart Medical System Using ECC. IEEE Access, 8, 107838-107852. https://doi.org/10.1109/access.2020.3001152
Go to original source... - Li, Y. (2023). A secure and efficient three-factor authentication protocol for IoT environments. Journal of Parallel and Distributed Computing, 179, 104714. https://doi.org/10.1016/j.jpdc.2023.104714
Go to original source... - Mahor, V., Padmavathy, R., & Chatterjee, S. (2024). Secure and lightweight authentication protocol for anonymous data access in cloud assisted IoT system. Peer-to-Peer Networking and Applications, 17(1), 321-336. https://doi.org/10.1007/s12083-023-01590-x
Go to original source... - Mansoor, K., Afzal, M., Iqbal, W., Abbas, Y., Mussiraliyeva, S., & Chehri, A. (2024). PQCAIE: Post quantum cryptographic authentication scheme for IoT-based e-health systems. Internet of Things, 27, 101228. https://doi.org/10.1016/j.iot.2024.101228
Go to original source... - Mansouri, H., Hireche, R., Benrebbouh, C., & Pathan, A. K. (2024). A review of blockchain in internet of Medical Things. In Cryptology and Network Security with Machine Learning, (pp. 397-412). Springer. https://doi.org/10.1007/978-981-97-0641-9_28
Go to original source... - Mikić, M., Srbakoski, M., & Praška, S. (2026). Post-quantum stealth address protocols. Journal of Cyber Security Technology, (in press). https://doi.org/10.1080/23742917.2025.2611820
Go to original source... - Mirsaraei, A. G., Barati, A., & Barati, H. (2022). A secure three-factor authentication scheme for IoT environments. Journal of Parallel and Distributed Computing, 169, 87-105. https://doi.org/10.1016/j.jpdc.2022.06.011
Go to original source... - Nguyen, H., Huda, S., Nogami, Y., & Nguyen, T. T. (2025). Security in Post-Quantum Era: A Comprehensive Survey on Lattice-Based Algorithms. IEEE Access, 13, 89003-89024. https://doi.org/10.1109/access.2025.3571307
Go to original source... - Papaioannou, M., Karageorgou, M., Mantas, G., Sucasas, V., Essop, I., Rodriguez, J., & Lymberopoulos, D. (2022). A survey on Security Threats and Countermeasures in Internet of Medical Things (IOMT). Transactions on Emerging Telecommunications Technologies, 33(6), e4049. https://doi.org/10.1002/ett.4049
Go to original source... - Puneeth, R. P., & Parthasarathy, G. (2024). Blockchain-Based Framework for Privacy Preservation and Securing EHR with Patient-Centric Access Control. Acta Informatica Pragensia, 13(1), 1-23. https://doi.org/10.18267/j.aip.225
Go to original source... - Regev, O. (2009). On lattices, learning with errors, random linear codes, and cryptography. Journal of the ACM, 56(6), 1-40. https://doi.org/10.1145/1568318.1568324
Go to original source... - Satpathy, S. P., Mohanty, S., & Pradhan, M. (2025). A sustainable mutual authentication protocol for IoT-Fog-Cloud environment. Peer-to-Peer Networking and Applications, 18(1), Article 35. https://doi.org/10.1007/s12083-024-01843-3
Go to original source... - Shetty, S., S, A. V., & Mahale, A. (2022). Comprehensive Review of Multimodal Medical data Analysis: open issues and future research Directions. Acta Informatica Pragensia, 11(3), 423-457. https://doi.org/10.18267/j.aip.202
Go to original source... - Tasopoulos, G., Dimopoulos, C., Fournaris, A. P., Zhao, R.K., Sakzad, A., & Steinfeld, R. (2023). Energy consumption evaluation of post-quantum TLS 1.3 for resource-constrained embedded devices. In Proceedings of the 20th ACM International Conference on Computing Frontiers, (pp. 366-374). https://doi.org/10.1145/3587135.3592821
Go to original source...
This is an open access article distributed under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits use, distribution, and reproduction in any medium, provided the original publication is properly cited. No use, distribution or reproduction is permitted which does not comply with these terms.

ORCID...