Implementation of an Advanced Secure Scheme for Rapidly Growing Internet of Things (IoT) Based Healthcare Monitoring
DOI:
https://doi.org/10.51483/IJAIML.6.9s.2026.181-193Keywords:
Internet of Things, IoT Healthcare, ESP32, Paillier Encryption, Homomorphic Encryption, AES-256-GCM, Kyber-768, Post-Quantum Cryptography, Edge Computing, Healthcare Security, Disease Detection.Abstract
The rapid growth of the Internet of Things (IoT) in healthcare has enabled continuous monitoring of patients through resource-constrained sensing devices. However, the transmission and storage of sensitive physiological information introduce significant security, privacy, authentication, and computational challenges. This research presents an advanced secure IoT healthcare architecture that integrates lightweight edge computing, post-quantum key exchange, authenticated encryption, homomorphic encryption, replay protection, and artificial intelligence-based disease detection. The proposed system uses an ESP32 microcontroller integrated with ECG, SpO2, heart-rate, and temperature sensors for patient-side data acquisition. Paillier-3072 homomorphic encryption is applied to individual vital signs, while AES-256-GCM provides authenticated transport encryption. Kyber-768, corresponding to ML-KEM-768, is employed for secure session-key establishment with mutual device authentication.
To overcome the computational limitations of the ESP32, the proposed implementation introduces encrypted NVS flash storage for the precomputed Paillier (r^N) value. This optimization reduces the device boot time from approximately 662 seconds to 7.7 seconds, representing a 98.8% reduction. The server-side architecture is migrated from Raspberry Pi to an NVIDIA Jetson Orin Nano Super, providing substantially greater computing capability and GPU acceleration. Secure remote access is implemented through a Cloudflare tunnel using WSS/HTTPS. The system also incorporates nonce-based replay protection, NTP time synchronization, authenticated administrative endpoints, device registration limits, restricted CORS policies, secret validation, and rate limiting.
A security assessment identified ten vulnerabilities in the earlier implementation, including encryption-oracle attacks, device-session hijacking, replay attacks, unauthorized database exports, device-flooding attacks, weak secret configuration, unrestricted CORS, plaintext logging, and unrestricted request rates. All ten vulnerabilities were addressed in the improved implementation. In addition, an AI-based disease-detection layer consisting of threshold-based detection, machine-learning classification, LSTM-based analysis, and ensemble decision-making was incorporated for monitoring five health conditions. The resulting architecture demonstrates the feasibility of combining privacy-preserving cryptography, post-quantum security, embedded optimization, and AI-based healthcare intelligence in a practical IoT platform.





