Yangfan Liang, Jingxue Chen, Lina Bu, Tao Liu, Xiaopei Wang, Bin Wang, Guodao Zhang, Hong Sun
The convergence of edge intelligence and networked medical infrastructures in the Artificial Intelligence of Medical Things (AIoMT) is transforming healthcare toward personalization and predictive intervention. In this paradigm, high-resolution physiological data continuously flow between wearable or implantable devices, edge nodes, and cloud analytics platforms. Such connectivity enables advanced diagnostic modeling and real-time decision support. However, it also enlarges the attack surface. AIoMT components are exposed to impersonation, replay, and man-in-the-middle attacks. Therefore, secure data exchange becomes essential. Authentication and key exchange (AKE) schemes address this requirement by enabling mutual authentication and session key establishment over insecure channels. Nevertheless, many existing centralized designs suffer from single points of failure and insider threats. Several blockchain-assisted approaches still retain centralized identity traceability. In addition, most AKE schemes either neglect physical security, lack tolerance to intrinsic physical unclonable function (PUF) noise, or store sensitive PUF challenge–response pairs, which increases the risk of modeling attacks. To address these issues, we propose a fully decentralized authentication and key exchange scheme (FDAKES) for AIoMT. FDAKES adopts a$(t,n)$threshold-based root of trust across multiple registration centers (MRCs) to remove unilateral control in registration and tracing. Its server-independent AKE process combines threshold-protected identities, dynamic nonces, timestamps, and PUF and biometric enhanced credentials to achieve perfect forward secrecy. Decentralized conditional traceability preserves user anonymity while allowing identity recovery only with unanimous MRCs consent. By integrating PUF with a fuzzy extractor, FDAKES enables stable secret regeneration without storing raw challenge–response pairs, thereby mitigating modeling threats. We formally prove protocol correctness for login authentication and mutual key agreement. We further establish semantic security of the session key under the real-or-random model, showing that the adversary advantage is negligible in the random oracle model. An extensive informal analysis demonstrates resistance to impersonation, replay, guessing, modeling, physical, man-in-the-middle, and key compromise attacks. Experimental evaluation demonstrates that FDAKES reduces total computational overhead by up to 40.95% and at least 17.25% percent compared with recent state-of-the-art AKE schemes, while communication cost is reduced by up to 76.73% and at least 5% across representative baselines. This work establishes a robust and fully decentralized trust foundation for next-generation smart healthcare systems.