A LIGHTWEIGHT ECC-BASED AUTHENTICATION AND KEY AGREEMENT PROTOCOL FOR RESOURCE-CONSTRAINED IOT

Authors

DOI:

https://doi.org/10.35631/JISTM.1143016

Keywords:

Authentication And Key Agreement, AVISPA, Elliptic Curve Cryptography (ECC), Formal Verification, Internet of Things (IoT), Lightweight Security, Mutual Authentication, Perfect Forward Secrecy

Abstract

The rapid proliferation of the Internet of Things (IoT) has connected billions of devices that continuously exchange sensitive data over public wireless channels, making secure authentication a critical requirement. However, most IoT end devices are severely resource-constrained, which renders conventional public-key infrastructures based on RSA, bilinear pairings, or digital certificates impractical. Although many authentication and key agreement schemes have been proposed, recent cryptanalytic studies show that they often either omit essential security properties such as perfect forward secrecy or resistance to ephemeral secret leakage or incur overhead that is unacceptable for low-power nodes. To address this gap, this paper proposes a lightweight Elliptic Curve Cryptography (ECC)-based authentication and key agreement protocol for a three-tier IoT architecture consisting of a user, a semi-trusted gateway server, and an IoT sensor. The protocol relies solely on elliptic-curve scalar multiplication, one-way hash functions, and bitwise XOR operations, avoiding bilinear pairings and certificate management. It achieves mutual authentication among all three parties through timestamped, hash-based authenticators and establishes a contributory session-key derived from fresh ephemeral keys, ensuring perfect forward secrecy. The security of the protocol is established through a detailed informal analysis, demonstrating resistance to major attacks, and is formally verified using the AVISPA tool, where both the OFMC and CL-AtSe back-ends report the protocol as SAFE under the Dolev–Yao adversary model. A comparative performance evaluation against several recent ECC-based authentication schemes shows that the proposed protocol maintains low cost requirements suitable for constrained IoT devices, and resulting in a communication overhead of 1828 bits, which is competitive with most recent ECC-based schemes evaluated, and imposing a minimal storage burden on end devices. The results demonstrate that the proposed protocol achieves a favorable balance between security and efficiency, making it well suited to resource-constrained IoT environments.

Downloads

Download data is not yet available.

References

Abdussami, M., Dwivedi, S. K., Al-Shehari, T., Saravanan, P., & Alghamdi, S. A. (2024). DEAC-IoT: Design of lightweight authenticated key agreement protocol for intra and inter-IoT device communication using ECC with FPGA implementation. Computers & Electrical Engineering, 120, 109696. https://doi.org/10.1016/j.compeleceng.2024.109696

Alzahrani, N. (2025). Security importance of edge-IoT ecosystem: An ECC-based authentication scheme. PLOS ONE, 20(6), e0322131. https://doi.org/10.1371/journal.pone.0322131

Armando, A., Basin, D., Compagna, L., Cuéllar, J., Hankes Drielsma, P., Heinemann, B., & Sasse, R. (2005). The AVISPA tool for the automated validation of Internet security protocols and applications. In Computer Aided Verification (CAV 2005) (Lecture Notes in Computer Science, Vol. 3576, pp. 281–285). Springer.

Baccouri, S., Farhat, H., Azzabi, T., & Attia, R. (2024). Lightweight authentication scheme based on elliptic curve ElGamal. Journal of Information and Telecommunication, 8(2), 231–261.

Braeken, A. (2022). Authenticated key agreement protocols for dew-assisted IoT systems. The Journal of Supercomputing, 78(11), 12093–12113. https://doi.org/10.1007/s11227-022-04364-z

Dolev, D., & Yao, A. C. (1983). On the security of public key protocols. IEEE Transactions on Information Theory, 29(2), 198–208. https://doi.org/10.1109/TIT.1983.1056650

Gautam, D., Rana, A., Obaidat, M. S., Kumar, P., & Prajapat, S. (2024). A provably secure biometric-based authentication and key agreement scheme for Internet of Drones. Transactions on Emerging Telecommunications Technologies, 35, e4893. https://doi.org/10.1002/ett.4893

Hammi, B., Fayad, A., Khatoun, R., Zeadally, S., & Begriche, Y. (2020). A lightweight ECC-based authentication scheme for Internet of Things (IoT). IEEE Systems Journal, 14(3), 3440–3450. https://doi.org/10.1109/JSYST.2019.2938540

Hankerson, D., Menezes, A. J., & Vanstone, S. A. (2004). Guide to elliptic curve cryptography. Springer.

Hu, S., Zhang, Y., Guo, Y., Zhong, W., Chen, Y., & Chen, L. (2025). Efficient IoT user authentication protocol with semi-trusted servers. Sensors, 25(7), 2013. https://doi.org/10.3390/s25072013

IoT Analytics. (2025). State of IoT 2025: Number of connected IoT devices growing 14% to 21.1 billion globally. https://iot-analytics.com

Keshta, I. (2024). A CRC-based authentication model and ECC-based authentication protocol for resource-constrained IoT applications. IEEE Access, 12, 156765–156784. https://doi.org/10.1109/ACCESS.2024.3482991

Koblitz, N. (1987). Elliptic curve cryptosystems. Mathematics of Computation, 48(177), 203–209. https://doi.org/10.1090/S0025-5718-1987-0866109-5

Li, M., & Hu, S. (2024). A lightweight ECC-based authentication and key agreement protocol for IoT with dynamic authentication credentials. Sensors, 24(24), 7967. https://doi.org/10.3390/s24247967

Lightweight authentication and key agreement protocol for IoT based on ECC. (2023). IEEE Conference Paper.

Miller, V. S. (1986). Use of elliptic curves in cryptography. In A. M. Odlyzko (Ed.), Advances in cryptology — CRYPTO ’85 (Lecture Notes in Computer Science, Vol. 218, pp. 417–426). Springer.

Park, K., Kim, M., & Park, Y. (2025). Security evaluation of provably secure ECC-based anonymous authentication and key agreement scheme for IoT. Sensors, 25(1), 237. https://doi.org/10.3390/s25010237

Pirmoradian, F., Safkhani, M., & Dakhilalian, S. M. (2023). ECCPWS: An ECC-based protocol for WBAN systems. Computer Networks, 224, 109598. https://doi.org/10.1016/j.comnet.2023.109598

Servati, M. R., & Safkhani, M. (2023). ECCbAS: An ECC-based authentication scheme for healthcare IoT systems. Pervasive and Mobile Computing, 90, 101753. https://doi.org/10.1016/j.pmcj.2023.101753

Shah, N. H., Ismail, S. A., Azizan, A., Anoop, A., Khan, D. T., & Ahamed, S. B. (2025). Lightweight authentication protocols in Internet of Things – A review. International Journal of Engineering Trends and Technology, 73(3), 104–119. https://doi.org/10.14445/22315381/IJETT-V73I3P108

Shah, N. H., Khan, D. T., Banu, A. A., & Shah, L. H. (2023). Symmetric and asymmetric encryption schemes for Internet of Things: A survey. International Journal of Intelligent Systems and Applications in Engineering, 11, 254–260.

Shunfang, H., Jiang, S., Miao, Q., Yang, F., Zhou, W., & Duan, P. (2024). Provably secure ECC-based anonymous authentication and key agreement for IoT. Applied Sciences, 14(8), 3187. https://doi.org/10.3390/app14083187

Tedeschi, P., Sciancalepore, S., Eliyan, A., & Di Pietro, R. (2020). LiKe: Lightweight certificateless key agreement for secure IoT communications. IEEE Internet of Things Journal, 7(1), 621–638. https://doi.org/10.1109/JIOT.2019.2942823

Thakur, G., Kumar, P., Chen, C.-M., et al. (2023). A robust privacy-preserving ECC-based three-factor authentication scheme for metaverse environment. Computer Communications, 211, 271–285. https://doi.org/10.1016/j.comcom.2023.05.012

Thakur, G., Kumar, P., et al. (2024). A provably secure authenticated key agreement protocol for industrial sensor network system. Concurrency and Computation: Practice and Experience, 36, e8250. https://doi.org/10.1002/cpe.8250

Transforma Insights & Exploding Topics. (2025). Number of Internet of Things (IoT) connections worldwide from 2022 to 2034. Statista. https://www.statista.com

Vangala, A., Das, A. K., Mitra, A., Das, S. K., & Park, Y. (2023). Blockchain-enabled authenticated key agreement scheme for mobile vehicles-assisted precision agricultural IoT networks. IEEE Transactions on Information Forensics and Security, 18, 904–919. https://doi.org/10.1109/TIFS.2022.3201234

Wang, D., & Wang, P. (2018). Two birds with one stone: Two-factor authentication with security beyond conventional bound. IEEE Transactions on Dependable and Secure Computing, 15(4), 708–722. https://doi.org/10.1109/TDSC.2016.26023

Downloads

Published

2026-06-30

How to Cite

Shah, N. H., Ismail, S. A., & Azizan, A. (2026). A LIGHTWEIGHT ECC-BASED AUTHENTICATION AND KEY AGREEMENT PROTOCOL FOR RESOURCE-CONSTRAINED IOT. JOURNAL INFORMATION AND TECHNOLOGY MANAGEMENT (JISTM), 11(43), 276–300. https://doi.org/10.35631/JISTM.1143016