METHODOLOGICAL PRINCIPLES FOR BUILDING A SECURE OPERATING PLATFORM FOR THE INTERNET OF MEDICAL THINGS
DOI:
https://doi.org/10.28925/2663-4023.2026.34.1338Keywords:
intellectualisation, methodology, Internet of Medical Things, sensors, sensor networks, cloud infrastructure, users, external accidental and targeted threats, security systems, message encryptionAbstract
Processes aimed at the secure digitalisation of Ukraine’s social infrastructure are ongoing. Medical infrastructure is a key area within the context of Industry 4.0 and Ukraine’s Cybersecurity Strategy. One of the key modern tools for the digitalisation of medicine is secure cyber-physical technology, particularly in relation to the secure Internet of Medical Things (IoMT). Effective mechanisms for implementing intelligent diagnosis of a person’s health status include secure processes such as: the collection of biophysical parameters relating to the functioning of a patient’s organs and systems; transmission of medical information via wireless communication channels; processing and analysis of data on the body’s condition; and the making of clinical decisions regarding diagnosis and, on this basis, the prescription of treatment, which form the basis of the functional architecture of the Internet of Medical Things. This paper proposes a methodology for constructing a secure IoT architecture platform based on the ‘sensors – sensor networks – cloud infrastructure – user – privacy and security’ model, which implements the functional algorithm ‘collection – exchange – processing – analysis – decision-making’ in accordance with the ‘object – threat – protection’ concept and potential external accidental and targeted threats. Security systems for IoT components—sensors, sensor networks and cloud infrastructure components—are presented in accordance with the STRIDE threat model and the OSI model. The practical implementation of secure medical data exchange in a Bluetooth sensor network is examined, specifically with regard to the cryptographic protection of information at the level of algorithmic and software-based message encryption using AES-256-GCM and Python.
Downloads
References
Association of Industrial Automation Enterprises of Ukraine. (2018). Industry 4.0 development strategy [In Ukrainian].
National Security and Defense Council of Ukraine. (2021). Cybersecurity strategy of Ukraine for 2021–2025 [In Ukrainian].
Vasylyshyn, S., Opirskyy, I., Susukailo, V., Mykhaylova, O., Harasymchuk, O., Sovyn, Y., Tyshyk, I., Dudykevych, V., Mykytyn, H., Bobalo, Y., & Stosyk, T. (2025). Advancements in cybersecurity next-generation systems and applications: Collective monograph. CRC Press.
Mathkor, D. M., Mathkor, N., Bassfar, Z., Bantun, F., Slama, P., Ahmad, F., & Haque, S. (2024). Multirole of the internet of medical things (IoMT) in biomedical systems for managing smart healthcare systems: An overview of current and future innovative trends. Journal of Infection and Public Health, 17(4), 559–572. https://doi.org/10.1016/j.jiph.2024.01.013
Nadhir, A. M., Mounir, B., Abdelkader, L., & Hammoudeh, M. (2025). Enhancing cybersecurity in healthcare IoT systems using reinforcement learning. Transportation Research Procedia, 84, 113–120. https://doi.org/10.1016/j.trpro.2025.03.053
Maksymovych, V., Nyemkova, E., Justice, C., Shabatura, M., Harasymchuk, O., Lakh, Y., & Rusynko, M. (2022). Simulation of authentication in information-processing electronic devices based on Poisson pulse sequence generators. Electronics, 11(13), Article 2039. https://doi.org/10.3390/electronics11132039
Shevchuk, D., Harasymchuk, O., Partyka, A., & Korshun, N. (2023). Designing secured services for authentication, authorization, and accounting of users. CEUR Workshop Proceedings, 207–225.
Bhushan, B., Kumar, A., Agarwal, A. K., Kumar, A., Bhattacharya, P., & Kumar, A. (2023). Towards a secure and sustainable internet of medical things (IoMT): Requirements, design challenges, security techniques, and future trends. Sustainability, 15(7), Article 6177. https://doi.org/10.3390/su15076177
Harasymchuk, O., Opirskyy, I., et al. (2025). Modern methods of ensuring information protection in cybersecurity systems using artificial intelligence and blockchain technology: Collective monograph. Technology Center PC. https://doi.org/10.15587/978-617-8360-12-2
Mintser, O. P., Romanov, V. O., Haleliuka, I. B., & Voronenko, O. V. (2020). Artificial intelligence technologies in medical practice [In Ukrainian]. Medical Informatics and Engineering, (2), 17–27. https://doi.org/10.11603/mie.1996-1960.2020.2.11171
Hupalo, & Melnyk, A. (2021). Acquisition and processing of data in CPS for remote monitoring of the human functional state. Advances in Cyber-Physical Systems, 6(1), 14–20. https://doi.org/10.23939/acps2021.01.014
Jabeen, T., Jabeen, I., Ashraf, H., Ullah, A., Jhanjhi, N. Z., Ghoniem, R. M., & Ray, S. K. (2023). Smart wireless sensor technology for healthcare monitoring system using cognitive radio networks. Sensors, 23(13), Article 6104. https://doi.org/10.3390/s23136104
Bobalo, Yu. Ya., Dudykevych, V. B., & Mykytyn, H. V. (2020). Strategic security of the “object–information technology” system: Monograph [In Ukrainian]. Lviv Polytechnic Publishing House.
Ameen, A. H., Mohammed, M. A., & Rashid, A. N. (2024). Enhancing security in IoMT: A blockchain-based cybersecurity framework for machine learning-driven ECG signal classification. Fusion: Practice & Applications, 14(1), 221–251. https://doi.org/10.54216/FPA.140117
Harasymchuk, O., Opirskyy, I., Banakh, R., et al. (2025). Intelligent cyber defence systems: Detection of ransomware and protection of wireless networks based on artificial intelligence technologies: Collective monograph. Technology Center PC. https://doi.org/10.15587/978-617-8360-22-1
Zubair, M., Ghubaish, A., Unal, D., Al-Ali, A., Reimann, T., Alinier, G., Hammoudeh, M., & Qadir, J. (2022). Secure Bluetooth communication in smart healthcare systems: A novel community dataset and intrusion detection system. Sensors, 22(21), Article 8280. https://doi.org/10.3390/s22218280
Soni, M., & Singh, D. K. (2022). LAKA: Lightweight authentication and key agreement protocol for internet of things based wireless body area network. Wireless Personal Communications, 127, 1067–1084. https://doi.org/10.1007/s11277-021-08565-2
Rezk, N. G., Alshathri, S., Sayed, A., Hemdan, E. E. D., & El-Behery, H. (2025). Secure hybrid deep learning for MRI-based brain tumor detection in smart medical IoT systems. Diagnostics, 15(5), Article 639. https://doi.org/10.3390/diagnostics15050639
Tokar, P. Yu. (2025). Methods for protecting the confidentiality of patient data in medical information systems: An analytical review [In Ukrainian]. Scientific Works of Vinnytsia National Technical University, (3), 133–137. https://doi.org/10.31649/2307-5376-2025-3-133-137
Baryshev, Yu. V., & Lanova, V. S. (2023). A method for secure storage of medical data based on a relational database and blockchain [In Ukrainian]. Scientific Works of Vinnytsia National Technical University, (3), 9–17. https://doi.org/10.31649/2307-5376-2023-3-9-17
Havrysh, B. M., Tymchenko, O. V., & Kustra, N. O. (2023). Methods for anonymizing medical databases [In Ukrainian]. Scientific Papers, 1(66), 68–79. https://doi.org/10.32403/1998-6912-2023-1-66-68-79
Petriv, P., Opirskyy, I., & Mazur, N. (2024). Modern technologies of decentralized databases, authentication, and authorization methods. In Proceedings of the Workshop “Cybersecurity Providing in Information and Telecommunication Systems II” (Vol. 3826, pp. 60–71). CEUR-WS.
Opirskyy, I., Lys, S., & Shakh, V. (2026). Analysis and testing of systems countering phishing and social engineering attacks at the corporate level. International Journal of Information Security, 25(2), Article 69.
Drozdova, Ye., & Kozel, V. (2025). Modern methods of database protection under cyber threats and wartime conditions [In Ukrainian]. Bulletin of Kherson National Technical University, 2(3), 177–185. https://doi.org/10.35546/kntu2078-4481.2025.3.2.22
Dzamesi, L., & Elsayed, N. (2025). A review on the security vulnerabilities of the IoMT against malware attacks and DDoS. In Proceedings of the 2025 IEEE 4th International Conference on Computing and Machine Intelligence (ICMI) (pp. 1–8). IEEE. https://doi.org/10.48550/arXiv.2501.07703
Gosálvez-White, I., Rodríguez-Martín, N., Barajas-García, N., Mena-Gallardo, C., & García-Teodoro, P. (2025). MEDIotWALL: Securing smart healthcare environments through IoT firewalls. Sensors, 25(19), Article 6235. https://doi.org/10.3390/s25196235
Dudykevych, V. B., Mykytyn, H. V., Nasylevskyi, V. P., & Fihurniak, V. R. (2023). On the issue of secure authentication in web applications [In Ukrainian]. Information Protection, 25(2), 76–82.
Boskin, O. O., Kornilovska, N. V., Polishchuk, V. M., & Sarafannikova, N. V. (2023). Web application security and hacker attacks [In Ukrainian]. Bulletin of Kherson National Technical University, 3(86), 83–92. https://doi.org/10.35546/kntu2078-4481.2023.3.11
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Валерій Дудикевич, Галина Микитин, Андрій Мозоль

This work is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 4.0 International License.