Abstract
Wireless sensor networks (WSNs) are pervasively employed in critical domains such as smart healthcare, industrial automation, and environmental surveillance, where secure access control is essential. User authentication protocols are vital for thwarting unauthorized intrusions, yet the vast majority of existing schemes rely on conventional public-key cryptography (such as ECC, RSA), which is provably insecure in the post-quantum era due to Shor’s algorithm. This motivates the design of post-quantum authentication that is also lightweight for resource-limited sensors. To address this challenge, we propose an efficient authentication and key agreement protocol based on Number Theory Research Unit (NTRU), a lattice-based cryptosystem offering proven resistance to quantum attacks. We have proven the correctness and security of our scheme through BAN logic and random oracle model and demonstrated through informal analysis that our scheme can resist various attack methods and possesses high security features. Moreover, we thoroughly evaluate our protocol against the most recent state-of-the-art schemes. The results indicate that our scheme has the lowest computational cost, and its communication cost is superior to that of most other schemes. Overall, our proposed protocol provides a robust, efficient, and future-proof authentication solution for WSNs, well-suited for deploying WSNs environments.
1. Introduction
Wireless sensor networks (WSNs) consist of numerous low-power resource-constrained sensor nodes deployed for environmental monitoring, industrial control, smart medical care and IoT systems [1]. The architecture of WSNs is shown in Figure 1. In WSNs, the sensors continuously collect sensitive data and transmit them to a user via a gateway node over wireless channels. However, the inherent openness of wireless channels makes user real-time access in WSNs vulnerable to various security and privacy threats [2]. User authentication acts as the core defense line to verify the legitimacy of communication entities. Without authentication mechanisms, attackers can forge sensor identities to inject false data or steal private monitoring information, which may lead to industrial system failures and leakage of patients’ private medical data [3]. Wireless sensor nodes within WSNs suffer from constrained energy supplies, limited computing capacity and narrow communication bandwidth, and they are generally deployed in unattended harsh field surroundings. These circumstances render traditional security mechanisms inapplicable to WSNs. In addition, the unprecedented progress of quantum computers has drastically undermined the security guarantees of traditional security frameworks, necessitating urgent countermeasures. Therefore, lightweight post-quantum secure authentication protocols are indispensable for the secure communication of WSNs.
Figure 1.
The architecture of WSNs.
1.1. Related Works
In WSNs environments, the sensitivity of transmitted data imposes stringent security requirements alongside severe resource limitations on sensor nodes. To tackle these conflicting challenges, numerous hash-function-based user authentication schemes have been developed in the literature [4,5,6,7,8,9,10,11]. Despite their computational efficiency, these protocols are not immune to adversarial threats—offline password guessing attacks in particular. Such vulnerabilities can either expose the established session key or cause it to fall short of the required security criteria, thereby undermining the assurance of secure key negotiation between the two communicating parties.
To overcome the inherent weaknesses of hash-based authentication schemes, Wang et al. advocated the adoption of public-key cryptographic operations as a more robust foundation for protocol design in general scenarios [12]. Among the available public-key alternatives, elliptic curve cryptography (ECC) stands out for its shorter key lengths and superior computational speed relative to RSA and other conventional systems, which has led to its extensive deployment in numerous authentication frameworks. In 2023, Sahoo et al. [13] proposed an improved three-factor wireless sensor authentication scheme based on ECC in a 5G environment to address the flaws present in previous schemes. However, we found that if the smartcard and biometric information are obtained by an attacker, the adversary can guess the user’s password, thus failing to provide three-factor security. Additionally, the scheme’s users use the same pseudo-identity UID for each login, allowing attackers to track user behavior, thus failing to provide anonymity. Meanwhile, Xie et al. [14] also pointed out that the Sahoo’s scheme was vulnerable to attacks, such as no data transmission security, transmitted data can be forged, user impersonation attack, and simultaneous impersonation attacks on gateway and sensor node, and proposed some improvement suggestions. In 2024, Saini et al. [15] proposed a three-factor security scheme to enhance the security of health data communication between doctors and patients in wireless healthcare sensor networks and believed their scheme to be efficient. However, since their scheme employs the computationally expensive ECC point multiplication for mutual authentication not only at the user and sensor ends but also at the gateway end, we believe their scheme is not as efficient as they claimed. To address issues such as impersonation attack, password guessing attacks, and internal attack in WSNs authentication protocol schemes, Huang [16] proposed a three-factor user authentication and key agreement scheme based on ECC. After analyzing this scheme, we believe that, similar to Sahoo et al.’s scheme, anonymity cannot be achieved because users use the same TIDi for each login; similar to Saini et al.’s scheme, it is not efficient due to the extensive use of ECC point multiplication operations at the user end, gateway end, and sensor end. In 2025, Xu et al. [17] conducted a comprehensive cryptographic analysis of two authentication protocols [18,19] and demonstrated that they share four major vulnerabilities: offline password guessing attacks, node capture attacks, DoS service hijacking attacks, and the inability to achieve genuine multi-factor security and forward security. They also proposed an improvement scheme that employs a fuzzy verifier to compress the verification matching space to resist offline dictionary attacks and utilizes ECC to decouple the session key using public and private keys to circumvent node capture, thereby achieving forward security. In 2026, Yu et al. [20] proposed a lightweight authentication and key agreement protocol for resource-constrained IoT WSNs, utilizing ECC and PUF (physically unclonable function) to defend against common attacks and employing the Chinese Remainder Theorem to enable password recovery when users forget their passwords. However, we found that in their scheme, if the smartcard is obtained by the attacker, and the attacker also eavesdrops on the user login request messages on the public channel, by combining the secret parameters on the smartcard, the attacker can guess the user’s identity identifier and password, thereby being able to impersonate the user to log in to the system.
Due to its capability to produce seemingly random and unpredictable keys that effectively resist brute-force attacks, chaotic mapping is leveraged as a cryptographic primitive for building secure authentication schemes for WSNs in environments with stringent security requirements. Feng et al. [21] addressed the two core pain points in WSNs, namely the limited resources (computing, storage, and energy) of sensor nodes and the insecure public nature of communication channels. They proposed a lightweight two-factor authentication scheme based on Chebyshev chaotic mapping. However, this scheme claimed to be resistant to replay attacks and DoS attacks, but it did not use timestamps because it was actually impossible to achieve resistance to replay attack and DoS attack. According to our analysis, this scheme has the risk of desynchronization attack. In step 4 of the authentication stage, after the GW verifies the sensor successfully, it will update the temporary identity PIDi in the database to the new alias AIDi. At this time, if the last message is lost in the public channel (or intercepted and discarded by the attacker), then the user side still holds the old PIDi, while the GW side has already replaced the old value with a new one. Then, when the user attempts to log in next time, he sends PIDi to the GW, but the GW cannot match this identity in the database and will directly deny the service. Mo et al. [22] proposed a two-factor authentication protocol that combines the PUF and the Chebyshev chaotic mapping to address the overlooked physical cloning attack and node capture attacks in distributed wireless sensor networks. Wang et al. [23] proposed an authentication and key agreement protocol based on PUF, Chebyshev chaotic mapping, and three factors: biometric features, password, and smartcard, addressing the shortcomings of existing WSNs such as man-in-the-middle attack, replay attack, and physical cloning attacks.
With the development of quantum computing, cryptosystems capable of resisting quantum computer cracking are becoming increasingly important. Lattice-based cryptography is a new generation of cryptosystem designed to withstand this threat, and it is considered to be the most promising and fastest-standardizing anti-quantum cryptographic scheme at present. Currently, some authentication protocols have adopted lattice-based cryptosystems to achieve the authentication process and resist quantum attacks. Singh et al. [24] proposed a quantum-resistant authenticated key agreement protocol for WSNs. The core idea is to replace traditional discrete logarithm or large integer factorization problems with Ring Learning with Errors (RLWE) problems, aiming to resist the threat posed by future quantum computers to classical cryptosystems such as RSA and ECC. However, we have identified a significant logical error in their scheme, namely the misuse of the reconciliation function ψ2(,), which renders the scheme inoperable. In 2025, Jiang et al. [25] proposed a novel authentication protocol based on the NTRU cryptosystem to address two core challenges faced by underwater wireless sensor networks (UWSNs)—resource constraints (limited computation, storage, and energy of nodes) and the threat of quantum computing attacks. NTRU is a lattice-based lightweight public-key cryptosystem with security relying on the worst-case shortest vector problem (SVP) and closest vector problem (CVP) on lattices, offering fast encryption/decryption and low resource overhead [26]. Traditional authentication protocols, which either incur excessive computational overhead or fail to resist quantum attacks, struggle to balance security and efficiency in UWSNs. However, we find that the proposed scheme cannot resist an offline password guessing attack, and the use of NTRU encryption and decryption at the gateway side also makes the scheme computationally inefficient overall. Ahmad et al. [27] addressed the issue that existing post-quantum authentication schemes for the Internet of medical things (IoMT) environment, although quantum-resistant, incur excessive computational overhead and are thus unsuitable for resource-constrained IoMT devices. To this end, they proposed a lightweight quantum-resistant user authentication protocol based on the RLWE algorithm. However, upon analysis, we find that the scheme suffers from a fundamental flaw in mathematical and logical terms that makes it infeasible to execute. Specifically, in step 3 of the login and authentication phase, the sensor node does not possess sidi and mi, and consequently cannot recover νi′ and idi′, thereby preventing the subsequent steps from being executed. Chaotic cryptography has also been explored for lightweight IoT sensing security [28,29]. Its attractive features include high sensitivity to initial conditions, pseudorandom keystreams, large key space, and resistance to statistical and differential attacks. However, inherent drawbacks remain: classical chaotic maps often have narrow chaotic parameter ranges, non-uniform dynamics, and periodic windows, which make keystreams predictable and vulnerable to known plaintext attacks. They also require abundant keystreams and complex key management, and they are symmetric primitives that cannot provide mutual authentication or key agreement under quantum attacks. Memristive-neuron models improve complexity and randomness but do not remove these limitations. In contrast, NTRU bases its security on hard lattice problems (SVP/CVP), offering quantum-resistant authentication and key agreement for WSNs.
1.2. Motivation and Contribution
From the previous analysis, it can be seen that currently a considerable number of authentication protocols are based on public key cryptography systems (such as ECC). A more fundamental concern is that the security of all traditional public-key primitives relies on the intractability of the integer factorization problem and the discrete logarithm problem, which have been proven by Shor to be easily broken by polynomial-time quantum algorithms [30]. Moreover, the current solution still has several security flaws, such as being unable to resist quantum attacks, offline password guessing attacks, and user impersonation attacks. Additionally, the computational cost and communication cost are relatively high, which imposes a significant burden on resource-constrained sensors. To address these issues, this paper proposes a lightweight security authentication protocol based on the NTRU algorithm for WSNs, which boasts low computation and communication costs, is capable of defending against common attacks, and is suitable for deploying on resource-constrained wireless sensors.
Our contributions are threefold:
- (1)
- We propose an NTRU-based authentication scheme for WSNs, which not only resists quantum attack but also achieves low computation and communication costs.
- (2)
- We have demonstrated that our scheme meets the security requirements through formal security proofs under BAN logic and random oracle model, as well as informal security analysis.
- (3)
- We compare our scheme with the latest state-of-the-art related schemes in terms of computational and communication costs. The results show that our scheme is not only feasible but also efficient.
2. Preliminaries
2.1. Lattice
A lattice L is a discrete additive subgroup of Rn. Given m linearly independent basis vectors b1, b2, …, be ∈ Rn, the lattice is formally defined as: v ∈ L, and
where m is the lattice rank, and n denotes the ambient dimension. All lattice points are integer linear combinations of basis vectors. Lattices possess a rich geometric structure, which gives rise to several computationally hard problems that form the foundation of post-quantum cryptography. Two of the most critical foundational problems are SVP and CVP—the Shortest Vector Problem and the Closest Vector Problem, respectively. SVP asks, given a lattice basis, to find a non-zero lattice vector v ∈ L that minimizes the Euclidean norm ||v||. CVP, given a basis of a lattice L and a target point t (not necessarily in the lattice), finds a lattice vector closest to t. Neither SVP nor CVP can be solved in polynomial time by classical or quantum algorithms, which distinguishes lattice cryptography from quantum-vulnerable ECC and chaotic maps cryptosystems for WSNs.
2.2. NTRU Cryptosystem
The lattice-based public-key cryptosystem NTRU was originally proposed by Hoffstein, Pipher, and Silverman back in 1998 [26]. Unlike RSA or ECC, whose security relies on integer factorization or discrete logarithms (vulnerable to Shor’s algorithm), NTRU’s security reduces to solving SVP (or CVP) in a convolutional polynomial ring. NTRU is renowned for its high efficiency and low resource consumption, making it ideal for WSNs.
The scheme operates in the ring R = ℤ[x]/(xn − 1), where n is a positive integer (typically a prime). Three parameters define an instantiation: n, a small modulus p (usually 2 or 3), and a large modulus q with gcd(p,q) = 1 and q ≫ p. Polynomial sets Lf, Lg, Lᵣ, and Lm restrict coefficient ranges (e.g., {−1, 0, 1}) to ensure security and correctness.
Key Generation: Randomly choose f ∈ Lf and g ∈ Lg such that f is invertible modulo p and q. Compute Fp ≡ f−1 (mod p) and Fq ≡ f−1 (mod q). The public key is h ≡ Fq · g (mod q), and the private key is (f, Fq).
Encryption: For a plaintext m ∈ Lm, select a random blinding polynomial r ∈ Lᵣ and compute
e = p · r · h + m (mod q)
Decryption: The recipient computes a = f · e (mod q), reduces its coefficients to (−q/2, q/2], and recovers
m′ = Fp · a (mod p).
NTRU leverages fast cyclic polynomial multiplication to cut computation and memory overhead, perfectly matching the strict power and storage limits of low-power WSNs sensors, and serves as the post-quantum core of the proposed authentication protocol.
The NTRU ring-dimension n yields a critical security-performance trade-off. A larger n improves post-quantum resilience against SVP/CVP lattice attacks, yet raises polynomial-multiplication latency and memory consumption for constrained sensors. A smaller n accelerates NTRU encryption/decryption but reduces lattice security margins. This paper adopts a moderate-n setting balancing both metrics for WSN scenarios. Designers may adjust n for use-cases prioritizing either stronger security or lower latency.
3. Proposed Scheme
The scheme we propose includes system initialization phase, sensor registration phase, user registration phase, authentication phase, and password update phase. We will detail the specifics of each phase in this section, with the symbols and their meanings listed in Table 1.
Table 1.
Notation and its meaning.
3.1. System Initialization Phase
The system comprises three types of participants: Ui, GW, SNj.
- (1)
- GW publishes the public parameters {p, q, n, n0}, where {p, q, n, n0} is defined as required in Section 2.2, and n0 ∈ [24, 28] to all participating entities.
- (2)
- Ui selects polynomials fu ∈ Lf and gu ∈ Lg satisfying the condition of being invertible both modulo q and modulo p; that is, fu · ≡ 1 (mod p), fu · ≡ 1 (mod q), with the inverse element denoted by and , respectively. Ui’s public key is computed as hu = p· · gu (mod q), and the corresponding private key is the pair (fu, ).
- (3)
- SNj selects polynomials fs ∈ Lf and gs ∈ Lg satisfying fs · ≡ 1 (mod p), fs · ≡ 1 (mod q). SNj’s public key is computed as hs = p· · gs (mod q), and the corresponding private key is (fs, ).
3.2. Sensor Registration Phase
The sensor SNj registers with the gateway GW before being deployed to the network. This phase establishes the necessary credentials for the sensor to participate in subsequent authentication operations.
- (1)
- The sensor SNj chooses its identity SIDj and transmits a registration request message {SIDj, hs}to GW via a secure channel.
- (2)
- Upon receiving the registration request, GW checks whether the identity SIDj already exists in its database. If SIDj is found, GW aborts the registration process. Otherwise, GW computes a secret key specifically for SNj as Kj = H(SIDj||Kg), where Kg is GW’s master secret key. GW stores the tuple {SIDj, Kj, hs} in its local database and transmits the message {Kj, hs} to SNj through the secure channel.
- (3)
- SNj stores {Kj, hs} in its memory.
This phase is summarized in Figure 2.
Figure 2.
The sensor registration phase.
3.3. User Registration Phase
The user Ui registers with the gateway GW to obtain a personalized smartcard that will be used for subsequent authenticated access to sensors.
- (1)
- Ui keys their identity UIDi and password UPWi, selects a nonce x and computes RIDi = H(UIDi||x), Fi = H(UPWi||x) mod n0, and transmits a registration request message {UIDi, RIDi} to GW via a secure channel.
- (2)
- Upon receiving the registration request, GW verifies whether UIDi already exists in its user database. If the identity is already registered, the gateway aborts the registration. Otherwise, GW computes Ki = H(RIDi||Kg) and stores {UIDi Ki, hu} in its database. Finally, GW sends a smartcard containing {Ki, hs} to the user via a secure channel.
During registration over the secure channel, GW validates by checking that , all coefficients lie in , , and conforms to the NTRU public-key format. Any malformed or maliciously constructed key causes GW to abort registration; thus, external adversaries cannot upload forged NTRU public keys. The function of deg() is to return the exponent of the highest non-zero degree term of a polynomial.
- (3)
- Upon receiving the smartcard, Ui computes Bi = H(UIDi||UPWi) ⊕ x, ⊕ Fi mod n0, deletes the Ki from the smartcard, and then stores {Bi, Ci, Fi} onto the smartcard.This phase is summarized in Figure 3.Figure 3. The user registration phase.
3.4. Authentication Phase
This phase enables the user Ui to establish mutual authentication with the sensor SNj through the mediation of the gateway GW, culminating in the establishment of a shared session key. The phase proceeds in five sequential steps.
- (1)
- Ui inserts the smartcard into a card reader and inputs UIDi and UPWi. The smartcard performs the following computations: x = Bi ⊕ H(UIDi||UPWi), Fi’ = H(UPWi||x) mod n0 and then verifies whether Fi′ equals the stored value Fi. If the equality does not hold, the session is terminated immediately. Otherwise, the card computes Ki = Ci ⊕ Fi’ mod n0, selects a random nonce ai and generates a current timestamp TS1 and ru ∈ Lᵣ, computes V1 = H(sug) ⊕ (UIDi||SIDj||TS1), V2 = p·hs·ru + (ai||UIDi||hu), m1 = H(UIDi||Ki||hu||TS1), and transmits the login request message {V1, V2, m1, TS1} to the GW over the public channel.
- (2)
- Upon receiving the login request, GW checks the freshness of timestamp TS1 using the current time TS1*. If |TS1* − TS1| > ΔT, GW aborts the session; otherwise, GW extracts the identities by computing (UIDi||SIDj||TS1) = H(sug) ⊕ V1, retrieves the stored parameters {Ki, hu} from the database using the extracted UIDi, and verifies whether m1 == H(UIDi||Ki||hu||TS1). If the verification fails, GW terminates the session. Otherwise, GW retrieves Kj from the database using the extracted SIDj and computes m2 = H(UIDi||Kj||TS2), where TS2 is the current timestamp. Finally, GW transmits the message {V2, m2, TS2} to SNj over the public channel.
- (3)
- Upon receiving the message from the gateway, SNj checks the freshness of timestamp TS2 using the current time TS2*. If |TS2* − TS2| > ΔT, SNj terminates the session; otherwise, SNj decrypts V2 using the NTRU private key (fs, ) to recover ai||UIDi||hu and verifies whether m2′ == H(UIDi||Kj||TS2). If the verification fails, SNj aborts the session; otherwise, SNj selects a random nonce bj and generates a current timestamp TS3 and rs ∈ Lᵣ, computes SKu−s = H(ai||bj||UIDi||SIDj), V4 = p · hu · rs + bj, m3 = H(Kj||SIDj||UIDi||TS3), m4 = H(bj||SIDj||UIDi||TS3), and transmits the message {V4, m3, m4, TS3} to GW.
- (4)
- Upon receiving SNj’s response, GW checks the freshness of timestamp TS3 using the current time TS3*. If |TS3* − TS3| > ΔT, the gateway aborts the session; otherwise, GW verifies whether m3′ == H(Kj||SIDj||UIDi||TS3). If the verification fails, the gateway terminates the session; otherwise, GW picks up the current timestamp TS4, computes m5 == H(Ki||UIDi||TS4), and transmits the message {V4, m4, m5, TS4} to Ui over the public channel.
- (5)
- Upon receiving the final message from GW, Ui checks the freshness of timestamp TS4 using the current time TS4*. If |TS4* − TS4| > ΔT, the user aborts the session; otherwise, Ui verifies whether m5′ == H(Ki||UIDi||TS4). If the verification fails, the user terminates the session; otherwise, the user decrypts V4 to recover the random nonce bj and verifies whether m4′ == H(bj||SIDj||UIDi||TS3). If the verification fails, the user terminates the session; otherwise, Ui computes the session key SKu−s = H(ai||bj||UIDi||SIDj).
At the conclusion of this phase, both Ui and SNj have mutually authenticated each other and established the shared session key , which can be used for subsequent secure communications.
This phase is summarized in Figure 4.
Figure 4.
The authentication phase.
3.5. Password Update Phase
When the user wishes to change their password, the following steps are performed locally on the smartcard without requiring interaction with the gateway.
- (1)
- Ui inserts the smartcard and inputs UIDi and the current password UPWi. The smartcard computes x = Bi ⊕ H(UIDi||UPWi), Fi′ = H(UPWi ||x) mod n0, verifies whether Fi′ equals the stored value . If the verification fails, the session is terminated. Otherwise, the smartcard computes Ki == Ci ⊕ Fi’ mod n0.
- (2)
- Ui is prompted to input the new password . The smartcard performs the following computations: Finew= H(||x) mod n, Binew= H(UIDi||) ⊕ x, Cinew = Ki⊕Finew, replace the stored smartcard parameters (Bi, Ci, Fi) with the new values (Binew, C2new, Finew).
The password update is now complete, and the user may use the new password U new PWi for subsequent login attempts.
4. Security Analysis
In this section, we assess the security of this scheme using BAN logic [31] and the random oracle model. Additionally, we provide heuristic analysis to demonstrate that this scheme can resist a variety of known attacks.
4.1. Formal Security Proof Under the BAN Logic
For brevity, we will not introduce the rules and symbols of BAN logic. Interested readers may refer to [32].
The actual authentication-phase messages are
The relevant computations are
In BAN logic, a hash/MAC authenticated by a shared key can be abstracted as a message encrypted/authenticated with that key. Thus, the idealized messages are
We formulate the following assumptions in accordance with the protocol’s initialization.
The practical prerequisites for A1–A21 and their validity in real-world WSN deployments are listed in Table 2.
Table 2.
The practical prerequisites for A1–A21 and their validity in real-world WSN.
We define the goals of our scheme as follows:
Based on the above definitions and BAN logic rules, we conduct the proof of the protocol’s validity as follows.
Step 1. From M1, receives
Step 2. By Message-Meaning Rule with assumption A1, we obtain
Step 3. By Freshness Rule with A9, we obtain
Step 4. By Nonce-Verification Rule from Steps 2 and 3, we obtain
Step 5. By Belief Rule, we obtain
Step 6. From M2, receives
Step 7. By Message-Meaning Rule with A4, we obtain
Step 8. By Freshness Rule with A10, we obtain
Step 9. By Nonce-Verification Rule, we obtain
Step 10. By Belief Rule, we obtain
Step 11. Since in Step 5 already believes that originated , and is trusted by (A4), the sensor can infer that was indeed generated by . Formally, combining Step 10 and the fact that believes ’s claim, we obtain
Step 12. By A8 and the Jurisdiction Rule, we obtain
Step 13. From M3, receives
Step 14. By Message-Meaning Rule with A2, we obtain
Step 15. By Freshness Rule with A13 and extending freshness to the whole message, we obtain
Step 16. By Nonce-Verification Rule, we obtain
Step 17. By Belief Rule, we obtain
Step 18. From M4, receives
Step 19. By Message-Meaning Rule with A3, we obtain
Step 20. By Freshness Rule with A12, we obtain
Step 21. By Nonce-Verification Rule, we obtain
Step 22. By Belief Rule, we obtain
Step 23. From Step 17, believes that originated . Since trusts ’s judgment (A5), and the message is authenticated by , we can conclude that
Step 24. By A7 and the Jurisdiction Rule, we obtain
The session key is defined as
Step 25. From Step 12, . The sensor also knows its own nonce and the identities Therefore,
Step 26. Since is a deterministic function of these values, the sensor believes that the key is shared with the user:
Thus, G2 holds.
Step 27. From Step 24, The user knows its own nonce and the identities. Hence,
Step 28. By the same reasoning, we obtain
Thus, G1 holds.
Step 29. From Step 5, ; from Step 5, ; GW also knows and . Therefore,
Since SK is a deterministic function of these values,
Step 30. From Step 21, . By A5, trusts ’s jurisdiction over the session key. Combined with Step 29, where believes that believes the session key, can conclude that
Thus, G3 holds.
Step 31. From Step 9,. By A6, trusts ’s jurisdiction over the session key. Combined with Step 29, where believes that believes the session key, can conclude
Thus, G4 holds.
Therefore, the achievement of Goals 1–4 implies that the proposal enables Ui and SNj to mutually authenticate each other, while simultaneously negotiating a shared session key for subsequent communications.
4.2. Formal Security Proof Under Random Oracle Model
The security of the proposed scheme is formally validated in the random oracle model in this subsection. For conciseness, we adopt the adversary model of [33,34] without loss of generality.
Theorem 1.
Let Π denote the proposal, and let the hash function be modeled as a random oracle, where l is the bit-length of hash output. Let the NTRU encryption scheme be instantiated with public parameters , and assume that the NTRU decryption problem (NDP) is hard: for any probabilistic polynomial-time algorithm running in time t, its success probability in inverting an NTRU ciphertext is at most AdvNDP(t), which is a negligible function in the security parameter.
For any probabilistic polynomial-time adversary against the authenticated key exchange (AKE) security of Π, making at most Send queries, Execute queries, and hash queries to the random oracle, the advantage of in winning the Test query (distinguishing the real session key from a random string of equal length) is bounded by
where denotes the advantage of in breaking security of AKE in Π, n0 ∈ [24, 28] denotes the public modulus used in the fuzzy verifier, denotes the size of dictionary space of possible user identities, denotes the size of dictionary of possible user passwords, denotes the time required for one NTRU encryption or decryption operation, and denote the number of Send, Execute, and hash queries, respectively.
The protocol is considered AKE-secure if this advantage is negligible in the security parameter (and in the NTRU dimension ), under the stated hardness assumption.
Proof of Theorem 1.
We prove the theorem by a sequence of games starting from the real execution and ending in an idealized game where the session key is completely independent of the adversary’s view. Let denote the event that correctly guesses the hidden bit in the Test query in game . The advantage in game is , and we bound the differences for each transition.
Game : This is the actual execution of under the random oracle model. All oracles—including the hash function, NTRU encryption/decryption, and timestamp checks—are implemented exactly as specified. Thus, we have
Game : We replace the real hash function by a random oracle that maintains a list of all input–output pairs. Every new hash query is answered with a uniformly random string in , and the answer is recorded for consistency. The NTRU operations are simulated using the actual public/private keys. This game is perfectly indistinguishable from from the adversary’s perspective; hence,
Game : We abort the game if any of the following collisions occur:
- Hash collisions: Two distinct inputs yield the same output. The probability of this event among hash queries is at most .
- Nonce collisions: The random values (drawn from spaces of size at least ) repeat across different sessions. For sessions, the union bound gives at most .
- Transcript collisions: Two different executions produce identical full messages, which could allow the adversary to replay or confuse sessions. This is bounded by the same term .
Summing these probabilities gives
Game : In this game, we rule out the possibility that produces a valid authentication tag or without having queried the corresponding hash input. Each tag involves a secret value (e.g., , , or the nonce ) that is unknown to the adversary. If attempts to guess a tag without querying the oracle, the success probability per attempt is . Across Send queries and hash queries, the total forgery probability is bounded by (assuming , which is typical). Thus,
Game : We now address the two main adversarial strategies that could compromise the session key: (i) recovering the ephemeral nonces and from the NTRU ciphertexts and and (ii) performing an offline dictionary attack against the user’s identity/password using the smartcard data. We analyze these two cases separately.
Case 1: Reduction to NDP
To compute the session key
the adversary must know both and (or at least the hash preimage, which is as hard as inverting . The only way to obtain them without guessing is to decrypt the NTRU ciphertexts:
- requires the sensor’s private key ;
- requires the user’s private key .
We construct a reduction that embeds a challenge NTRU ciphertext (say, targeting ) into the simulation. If correctly guesses the session key, then, with probability at least , it has queried the oracle on the correct (and ). By inspecting the hash list, extracts the plaintext and solves the NDP instance. A symmetric reduction handles the case where is targeted. The total success probability of the reduction is bounded by the adversary’s advantage multiplied by , which yields the term
Case 2: Offline Guessing with Fuzzy Verifier
Suppose compromises the smartcard and obtains . To verify a candidate identity/password pair , it computes
The guess is accepted if . Since the hash output is uniformly distributed, the probability that a wrong pair satisfies this equality is exactly . Thus, for online guesses, the success probability of guessing the correct credentials is at most
where the first two terms correspond to dictionary attacks when one factor (identity or password) is known, and the third is the false-acceptance rate of the fuzzy verifier. Since the adversary may attempt this for each hash query, we multiply by .
Combining both cases gives
Game : In this final game, we consider the adversary’s ability to compromise session keys established before it obtains long-term secrets. Specifically, may issue a Corrupt(GW) query and obtain the gateway’s long-term master secret . From , can derive any gateway-side secret key of the form
Thus, can verify or forge all MACs/tags that are computed with or . However, does not obtain the NTRU private keys
nor the ephemeral nonces , which are assumed to be erased after the session. This is consistent with the standard forward-secrecy threat model: the long-term key of the gateway is leaked, but the per-node private keys and ephemeral session state remain protected.
We claim that even with , cannot compute the historical session key
The reason is that does not depend on , , or . It depends only on the ephemeral nonces and and the public identities . In the transcript, these nonces are protected by NTRU encryption:
Recovering from requires the sensor’s private key . Recovering from requires the user’s private key . Neither private key is derivable from . Therefore, from ’s view, and are hidden by the NDP.
To distinguish the real from a random string of the same length, must query the random oracle on the correct tuple
Without such a query, the value of is uniformly random and independent of ’s view. We now bound the probability that makes this query.
Let be the event that queries on the correct tuple for the Test session. We construct a reduction that solves an NDP instance using . receives an NDP challenge . It guesses
- One session among the executed sessions;
- One hash query among the queries made by .
embeds as (if targeting ) or (if targeting ) in the guessed session. All other values are simulated using and the known protocol logic. If queries on the correct tuple for that session, then reads (or ) from the query input and outputs it as the NDP plaintext.
The probability that ’s guess is correct is at least
Therefore,
If both and must be recovered, a factor of may be included, yielding
In Game , if does not occur, the session key is replaced by a uniformly random string. Hence,
Consequently,
Combining (1)~(7), we have
This completes the proof. □
4.3. Informal Security Analysis
This section provides an informal security evaluation, verifying the proposed scheme’s robustness against diverse attacks and its compliance with essential privacy and security requirements. In addition, we compared our scheme with four latest schemes in terms of security attributes, and the results are presented in Table 3.
Table 3.
Security features comparison among schemes.
4.3.1. User Impersonation Attack
An adversary attempting to impersonate user must forge a valid login request . This requires knowledge of
- The identity and password to recover ,
- The secret ,
- The gateway’s secret to construct ,
- The ephemeral nonce and the NTRU public key to build .
Even if the adversary obtains the smartcard and extracts , he cannot compute without and . The fuzzy verifier ensures that a guessed password/identity pair cannot be verified offline with certainty, as the modulo operation yields approximately false positives. To distinguish the correct pair, the adversary must launch an online login attempt, which is detectable and limited by timestamp checks. Without , forging is infeasible due to the one-way property of . Hence, the scheme resists user impersonation.
4.3.2. GW Impersonation Attack
To impersonate the gateway , the adversary must produce valid messages to and to . These require
- , where is the sensor’s long-term key known only to and ,
- , where is known only to and the legitimate user,
- The NTRU ciphertexts and , which are constructed using the sensor’s public key and the user’s public key , respectively.
An adversary without the master key cannot compute either or . Even if the adversary eavesdrops past messages, the hash function’s collision resistance prevents the derivation of the inputs from the outputs. Moreover, and cannot be correctly regenerated without the corresponding ephemeral random values (, , , ). Thus, forging any gateway message is computationally infeasible, and the scheme resists GW impersonation.
4.3.3. Sensor Node Impersonation Attack
To impersonate a sensor node , the adversary must forge the response to . This requires
- The sensor’s NTRU private key to decrypt and extract ,
- The secret to compute ,
- The ephemeral nonce and blinding factor to construct and .
Without , the adversary cannot forge . Without the private key, they cannot recover (needed to link the response to the ongoing session). Even if a sensor has been previously captured, the captured private key cannot be used to impersonate a different sensor or to forge messages for a session that originated from a legitimate user who has not yet interacted with the captured node. The scheme therefore resists sensor node impersonation.
4.3.4. Forward Secrecy
In the proposed scheme, the session key is computed as , where denote ephemeral one-time random nonces separately generated by the user and sensor in each independent authentication round. The gateway’s long-term master secret only participates in computing static pre-registration secrets and during offline registration, and it is never embedded into the hash derivation formula of the session key. If an adversary fully leaks the gateway’s master key , he can only deduce the permanent static credentials and stored in the gateway database. However, the ephemeral values and are freshly sampled per session and encapsulated inside NTRU ciphertexts and transmitted over public channels. Breaking NTRU polynomial encryption requires solving the hard ring lattice problem, which is computationally infeasible for classical and quantum polynomial-time adversaries. Without recovering and , the adversary cannot reconstruct the historical session key . Therefore, our scheme provides perfect forward secrecy.
4.3.5. Replay Attack
Every authentication message carries a timestamp: in the login request, from to , from to , and from to . Upon receipt, each party verifies that , where is the current time. Any replayed message with a stale timestamp is immediately rejected. Moreover, even if an adversary replays a message within the valid time window, the inclusion of fresh nonces () in the hash computations (e.g., ) and in the NTRU ciphertexts makes the replayed message inconsistent with the current session’s expected values. The receiving entity will detect the mismatch when verifying the authentication tags. Consequently, replay attacks are effectively prevented.
It should be noted that practical WSN nodes suffer inherent clock drift and clock offset. The configurable threshold ΔT can tolerate moderate clock offsets, but overly enlarged ΔT will widen the valid time window and increase the replay-attack surface. Hence, system operators need to balance clock-desynchronization robustness and replay-attack resistance in real deployment.
4.3.6. Privileged Insider Attack
A privileged insider (e.g., a gateway administrator) may have full read access to the gateway’s database, which stores for each user and for each sensor. However, the user’s password is never transmitted to or stored by the gateway; during registration, the user sends only , , and , where is a nonce chosen locally by the user. The smartcard stores , , and . Even if the insider obtains from the database, they cannot recover or because both are protected by the one-way hash . The fuzzy verifier further obstructs offline guessing: any guessed produces a false match with probability , forcing the insider to validate guesses through online interactions, which are limited. Thus, the scheme resists privileged insider attacks.
4.3.7. Sensor Node Capture Attack
Sensor nodes are deployed in unattended and potentially hostile environments, making physical capture a realistic threat. Suppose an adversary captures sensor and extracts its stored secrets, including and the NTRU private key (if stored). The adversary can decrypt past messages for that specific node. However,
- (1)
- The session key depends on the user’s ephemeral nonce , which was encrypted under . Although the captured private key allows decryption of , the adversary still obtains only for sessions involving the captured node. For other sessions with other sensors, is encrypted under different public keys and remains secure.
- (2)
- The gateway’s master key is not stored on the sensor; so, capturing one sensor does not reveal for other sensors (since and is unknown).
- (3)
- The ephemeral blinding factor is discarded after the session; without it, the adversary cannot forge new valid ciphertexts for future sessions.
Consequently, the capture of a single sensor node does not compromise the security of other nodes or past session keys for non-captured nodes. The scheme resists sensor node capture attacks.
4.3.8. User Anonymity
User anonymity comprises two aspects: (a) the adversary cannot learn the real identity , and (b) the adversary cannot determine whether two different protocol runs originate from the same user (untraceability). In our scheme, is never sent in cleartext over the public channel:
- In the login request, masks the identity with the secret , which is known only to the user and the gateway. Without , extraction of is impossible due to the one-wayness of (). In addition, because the timestamp TS1 is embedded in V1, the V1 for each user login to GWN is different, making it impossible for attackers to track users based on the intercepted V1.
- The same identity also appears inside the NTRU ciphertext as part of the plaintext , which is encrypted under the sensor’s public key . Only the sensor (with its private key) can recover it.
- The nonce changes uniformly at random for each session; so, the ciphertext and the masked value are computationally indistinguishable from random values across different sessions. An adversary cannot link two login requests to the same user. Thus, the protocol guarantees both user anonymity and untraceability.
4.3.9. Quantum Attack
Our protocol’s security foundation rests on the NTRU public-key cryptosystem, which is a lattice-based primitive and the security relies on NTRU’s hardness, which is derived from SVP and CVP in ideal lattices. Moreover, the hash function () used throughout the protocol (e.g., SHA-256) is also quantum-resistant. The authentication tags are constructed from with secret inputs (); An adversary would need to invert these hashes or forge them without the secrets, which reduces to breaking the one-wayness or collision resistance of ().
Importantly, the ephemeral nonces and blinding factors are chosen independently of any long-term quantum-vulnerable parameter. Therefore, an adversary equipped with a quantum computer cannot trivially recover past session keys (forward secrecy holds) nor impersonate any party without solving the underlying lattice problem. In summary, the proposed scheme is explicitly designed to be post-quantum secure, offering a distinct advantage over ECC-based and Chebyshev chaotic maps-based counterparts.
5. Performance Analysis
This section evaluates the performance of our proposed NTRU-based two-factor authentication scheme in terms of computational overhead, storage overhead, and communication overhead. A comprehensive comparison with the four state-of-art schemes [16,17,23,25] is presented to demonstrate the efficiency advantages of our protocol.
5.1. Computation Overhead
We analyze the computation cost of our scheme and the related schemes [16,17,23,25] during the authentication phase, focusing on the cryptographic operations performed by the user, the gateway, and the sensor node. Following the benchmark established in [25], we adopt the execution times shown in Table 4. Our scheme mainly involves operations such as NTRU encryption, decryption, hash function, and polynomial multiplication. Operations such as XOR and concatenation are omitted due to their negligible overhead. The comparison results of the computation overhead between our scheme and other schemes [16,17,23,25] are shown in Table 5. To facilitate understanding, we have represented Table 5 graphically in Figure 5.
Table 4.
Cryptographic operations and their execution times.
Table 5.
The comparison results of the computation overhead.
Figure 5.
Comparison of the computation overhead [16,17,23,25].
As shown in Table 5 and Figure 5, the proposed scheme demonstrates superior computational efficiency, achieving the lowest total overhead of 0.4410 ms. It significantly outperforms the ECC-based schemes [16,17] and the chaotic map-based scheme [23]. Compared to the other NTRU-based protocol [25], our design optimizes the gateway’s role by eliminating costly NTRU operations, reducing its workload to only five hash functions. This minimal computational demand makes the protocol exceptionally suitable for resource-constrained WSNs.
Note that the above measured computation overhead is based on our moderate NTRU parameter n. As analyzed in Section 2.2, a larger n for high-security scenarios increases sensor-side cryptographic latency, whereas a smaller n for delay-sensitive IoT applications degrades security margins. Practitioners should tune NTRU parameters following the concrete application security-latency demands.
5.2. Storage Overhead
We analyze the storage overhead incurred by each entity during the authentication phase. Following the benchmark established in Section 5.1 of [25], we assume the following bit lengths: identity (64 bits), timestamp (32 bits), nonce (128 bits), hash value (160 bits), NTRU public/private key (128 bits), ECC point (320 bits), symmetric key (128 bits), and biometric data (160 bits). The storage overhead of our solution at the user end is 480 bits (=160 + 160 + 160), at the gateway end it is 704 bits (=64 + 160 + 128 + 64 + 160 + 128), and at the sensor end it is 352 bits (=64 + 160 + 128). The total storage cost comparison results of our scheme with those of schemes [16,17,23,25] are shown in Table 6 and Figure 6.
Table 6.
Storage overhead.
Figure 6.
Comparison of storage overhead [16,17,23,25].
According to Table 6 and Figure 6, the proposed scheme requires a total storage of 1536 bits, which is the second most efficient among the compared protocols, surpassed only by scheme [17] (1508 bits). It significantly reduces the storage burden compared to schemes [16,23,25]. This analysis highlights that our design achieves a highly competitive storage footprint, effectively balancing the memory requirements across the user, gateway, and sensor nodes for practical implementation on resource-constrained devices.
5.3. Communication Overhead
Based on the benchmark proposed in Section 5.2, we calculated the communication cost of our scheme and compared it with other schemes [16,17,23,25]. The comparison results are shown in Table 7 and Figure 7.
Table 7.
Communication overhead.
Figure 7.
Comparison of communication overhead [16,17,23,25].
Table 7 and Figure 7 show that the communication overhead of the proposed scheme is 1600 bits. While this is slightly higher than schemes [25] (1440 bits) and [23] (1472 bits), it remains substantially more efficient than the ECC-based protocols [16] and [17]. This moderate increase in communication cost is a justifiable trade-off for achieving post-quantum security through the NTRU cryptosystem. The protocol maintains a reasonable level of transmission efficiency while providing robust security against future quantum computing threats.
5.4. Summary
In conclusion, the proposed NTRU-based authentication protocol offers a compelling balance between security and performance. It achieves the lowest computational cost and the most efficient storage overhead among the compared schemes, making it highly suitable for resource-constrained WSNs. Although the communication cost is marginally higher than some existing schemes, this is a reasonable trade-off for achieving post-quantum security. The significant advantages in computation and storage, combined with its robust security foundation, establish the proposed protocol as a highly efficient and future-proof solution for WSNs.
6. Conclusions
In this paper, we propose a novel user authentication protocol for WSNs based on the NTRU lattice cryptosystem. Addressing the security vulnerabilities of traditional schemes and the impending threats posed by quantum computing, our design ensures robust post-quantum security while maintaining high efficiency. We conduct formal security proof under the random oracle model and also verify the security of our scheme through BAN logic. Informal security analysis indicates that the protocol can effectively resist various known attacks. Furthermore, performance evaluations confirm that our scheme achieves the lowest computational cost and superior storage overhead compared to existing alternatives based on ECC, Chebyshev chaotic map, and NTRU. Despite slightly higher communication costs, the significant improvements in computational efficiency and quantum resistance make the proposed protocol a highly practical and secure solution in resource-constrained WSNs environments.
Author Contributions
Conceptualization, W.S.; methodology, W.S.; investigation, J.M. and Y.L.; writing—original draft preparation, J.M.; writing—review and editing, W.S. and Y.L. All authors have read and agreed to the published version of the manuscript.
Funding
This research received no external funding.
Data Availability Statement
All data generated or analyzed through the paper are associated with their references and sources.
Conflicts of Interest
The authors declare no conflicts of interest.
References
- Yick, J.; Mukherjee, B.; Ghosal, D. Wireless sensor network survey. Comput. Netw. 2008, 52, 2292–2330. [Google Scholar] [CrossRef] [Scilit]
- Priya, K.S.; Rajabhushanam, C. Enhancement of data security in wireless sensor networks: Application in internet of things. Int. J. Electron. Secur. Digit. Forensics 2026, 18, 1–11. [Google Scholar] [CrossRef] [Scilit]
- Yuan, J.; Zhao, Y.; Yu, J. A Conditional Privacy-Preserving Efficient Authentication Scheme With Revocability for Wireless Body Area Networks. IEEE Internet Things J. 2025, 12, 49942–49954. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Q.; Zhou, X.; Zhong, H.; Cui, J.; Li, J.; He, D. Device-side lightweight mutual authentication and key agreement scheme based on chameleon hashing for industrial internet of things. IEEE Trans. Inf. Forensics Secur. 2024, 19, 7895–7907. [Google Scholar] [CrossRef] [Scilit]
- Kwon, D.K.; Yu, S.J.; Lee, J.Y.; Son, S.H.; Park, Y.H. WSN-SLAP: Secure and Lightweight Mutual Authentication Protocol for Wireless Sensor Networks. Sensors 2021, 21, 936. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Wu, T.-Y.; Yang, L.; Lee, Z.; Chu, S.-C.; Kumari, S.; Kumar, S. A provably secure three-factor Authentication protocol for wireless sensor networks. Wirel. Commun. Mob. Comput. 2021, 2021, 5537018. [Google Scholar] [CrossRef] [Scilit]
- Byun, S.; Ryu, J.; Choi, Y.; Lee, H. Improved secure three-factor-based mutual authentication scheme for wireless sensor networks in internet of things environments. Clust. Comput. 2026, 29, 47, Correction in Clust. Comput. 2026, 29, 130. [Google Scholar] [CrossRef] [Scilit]
- Li, Y.; Tian, Y. A lightweight and secure three-factor authentication protocol with adaptive privacy-preserving property for wireless sensor networks. IEEE Syst. J. 2022, 16, 6197–6208. [Google Scholar] [CrossRef] [Scilit]
- Ali, R.; Pal, A.K.; Kumari, S.; Sangaiah, A.K.; Li, X.; Wu, F. An enhanced three factor based authentication protocol using wireless medical sensor networks for healthcare monitoring. J. Ambient Intell. Humaniz. Comput. 2024, 15, 1165–1186. [Google Scholar] [CrossRef] [Scilit]
- Tyagi, P.; Kumari, S.; Alzahrani, B.A.; Gupta, A.; Yang, M.-H. An enhanced user authentication and key agreement scheme for wireless sensor networks tailored for IoT. Sensors 2022, 22, 8793. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Kumar, D. Cryptanalysis and improvement of an authentication protocol for wireless sensor networks. Trans. Emerg. Telecommun. Technol. 2023, 15, e4747. [Google Scholar] [CrossRef] [Scilit]
- Wang, D.; Wang, P. Two Birds with One Stone: Two-Factor Authentication with Security Beyond Conventional Bound. IEEE Trans. Dependable Secur. Comput. 2018, 15, 708–722. [Google Scholar]
- Sahoo, S.S.; Mohanty, S.; Sahoo, K.S.; Daneshmand, M.; Gandomi, A.H. A three-factor-based authentication scheme of 5G wireless sensor networks for IoT system. IEEE Internet Things J. 2023, 10, 15087–15099. [Google Scholar] [CrossRef] [Scilit]
- Xie, Q.; Xie, Q. Security analysis on a three-factor authentication scheme of 5G wireless sensor networks for IoT system. IEEE Internet Things J. 2024, 11, 15038–15042. [Google Scholar] [CrossRef] [Scilit]
- Saini, K.K.; Kaur, D.; Kumar, D.; Kumar, B. An efficient three-factor authentication protocol for wireless healthcare sensor networks. Multimed. Tools Appl. 2024, 83, 63699–63721. [Google Scholar] [CrossRef] [Scilit]
- Huang, W. ECC-based three-factor authentication and key agreement scheme for wireless sensor networks. Sci. Rep. 2024, 14, 1787. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Xu, M.; Wang, D. Practical two-factor authentication protocol for real-time data access in WSNs. IEEE Trans. Dependable Secur. Comput. 2025, 22, 5215–5230. [Google Scholar] [CrossRef] [Scilit]
- Chaudhry, S.A.; Irshad, A.; Yahya, K.; Kumar, N.V.N.; Alazab, M.; Zikria, Y.B. Rotating behind Privacy: An Improved Lightweight Authentication Scheme for Cloud-based IoT Environment. ACM Trans. Internet Technol. (TOIT) 2021, 21, 78. [Google Scholar] [CrossRef] [Scilit]
- Jabbari, A.; Mohasefi, J.B. A Secure and LoRaWAN Compatible User Authentication Protocol for Critical Applications in the IoT Environment. IEEE Trans. Ind. Inform. 2022, 18, 56–65. [Google Scholar] [CrossRef] [Scilit]
- Yu, Y.; Wei, K.; Qi, K.; Wu, W. Privacy-Preserving ECC-Based AKA for Resource-Constrained IoT Sensor Networks with Forgotten Password Reset. Entropy 2026, 28, 185. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Feng, H.; Cai, B. A Provably Secure and Lightweight Two-Factor Authentication Protocol for Wireless Sensor Network. Electronics 2024, 13, 4289. [Google Scholar] [CrossRef] [Scilit]
- Mo, J.; Zhang, Z.; Lin, Y. A Practically Secure Two-Factor and Mutual Authentication Protocol for Distributed Wireless Sensor Networks Using PUF. Electronics 2024, 14, 10. [Google Scholar] [CrossRef] [Scilit]
- Wang, L.; Han, C. Multi-factor authentication and key agreement scheme based on PUF and Chebyshev chaotic map for wireless sensor networks. Sci. Rep. 2025, 16, 3311. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Singh, M.; Mishra, D. Post-quantum secure authenticated key agreement protocol for wireless sensor networks. Telecommun. Syst. 2023, 84, 101–113. [Google Scholar] [CrossRef] [Scilit]
- Jiang, F.; Xu, M. Security Authentication Protocol for Underwater Sensor Networks Based on NTRU. J. Mar. Sci. Eng. 2025, 13, 742. [Google Scholar] [CrossRef] [Scilit]
- Hoffstein, J.; Pipher, J.; Silverman, J.H. NTRU: A ring-based public key cryptosystem. In Algorithmic Number Theory, Proceedings of the Third International Symposium; Springer: Berlin/Heidelberg Germany, 1998. [Google Scholar]
- Ahmad, A.; Jagatheswari, S.; Praveen, R. Quantum-secure lightweight fuzzy extractor based user authentication scheme for internet of medical things. Soft Comput.—A Fusion Found. Methodol. Appl. 2026, 30, 787–808. [Google Scholar] [CrossRef] [Scilit]
- Gao, S.; Zhang, Z.; Li, Q.; Ding, S.; Iu, H.C.; Cao, Y.; Xu, X.; Wang, C.; Mou, J. Encrypt a Story: A Video Segment Encryption Method Based on the Discrete Sinusoidal Memristive Rulkov Neuron. IEEE Trans. Dependable Secur. Comput. 2025, 22, 8011–8024. [Google Scholar] [CrossRef] [Scilit]
- Liu, P.; Teng, L.; Iu, H.C.; Wang, M.; Li, Q.; Fu, X. High sensitivity image encryption algorithm based on cascaded chaotic system. J. Inf. Secur. Appl. 2025, 93, 104153. [Google Scholar] [CrossRef] [Scilit]
- Shor, P.W. Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings of Proceedings 35th Annual Symposium on Foundations of Computer Science; IEEE: New York, NY, USA, 2002; pp. 124–134. [Google Scholar]
- Burrows, M.; Abadi, M.; Needham, R.M. A logic of authentication. Acm Trans. Comput. Syst. 1990, 8, 18–36. [Google Scholar] [CrossRef] [Scilit]
- Wang, C.; Xu, G.; Sun, J. An Enhanced Three-Factor User Authentication Scheme Using Elliptic Curve Cryptosystem for Wireless Sensor Networks. Sensors 2017, 17, 2946. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Mo, J.; Chen, H. A Lightweight Secure User Authentication and Key Agreement Protocol for Wireless Sensor Networks. Secur. Commun. Netw. 2019, 2019, 2136506. [Google Scholar] [CrossRef] [Scilit]
- Mo, J.; Shen, W.; Pan, W. An Improved Anonymous Authentication Protocol for Wearable Health Monitoring Systems. Wirel. Commun. Mob. Comput. 2020, 2020, 5686498. [Google Scholar] [CrossRef] [Scilit]
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.






