Quantum-Based Two-Factor Authentication Protocol for Blockchain-Aided Internet-of-Medical-Things
Abstract
The rapid growth of the Internet-of-Medical-Things (IoMT) and quantum computing presents significant security risks. Quantum algorithms efficiently break traditional public-key encryption, exposing sensitive patient data to long-term threat. Consequently, ensuring robust authentication and long-term security under quantum threats remains a critical challenge, particularly in decentralized environments. This article proposes a decentralized two-factor authentication (2FA) protocol for IoMT. Our protocol integrates blockchain, biometric fuzzy extractors, and the BB84 quantum key distribution (QKD) protocol. We utilize the biometric fuzzy extractor to protect user identities. A public blockchain manages authentication parameters via smart contracts (SCs) to support decentralized identity verification. This mechanism facilitates user revocation and authorized traceability. Session keys establish through QKD to achieve information-theoretic security, and the protocol provides forward and backward secrecy. Formal security analysis under the Canetti–Krawczyk (CK) and real-or-random (ROR) models demonstrates resistance to impersonation, replay, man-in-the-middle, and quantum attacks. Experimental results show that our protocol reduces classical computation overhead by over 56% and classical communication overhead by 10% compared to existing baselines. Furthermore, it achieves lower communication costs while maintaining high efficiency for resource-constrained IoMT environments in the future.