Next Article in Journal
Application of the Two-Layer Regularized Gated Recurrent Unit (TLR-GRU) Model Enhanced by Sliding Window Features in Water Quality Parameter Prediction
Previous Article in Journal
Template-Based Catalysis and the Emergence of Collectively Autocatalytic Systems
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Privacy-Preserving ECC-Based AKA for Resource-Constrained IoT Sensor Networks with Forgotten Password Reset

1
School of Electronic and Communication Engineering, Shenzhen Polytechnic University, Shenzhen 518055, China
2
School of Computer Science, University of Liverpool, Liverpool L69 3DR, UK
*
Authors to whom correspondence should be addressed.
Entropy 2026, 28(2), 185; https://doi.org/10.3390/e28020185
Submission received: 8 January 2026 / Revised: 30 January 2026 / Accepted: 5 February 2026 / Published: 6 February 2026
(This article belongs to the Special Issue Advances in IoT Security and Privacy)

Abstract

Wireless sensor networks ( W S N s ) are extensively used in I o T applications. Secure access control and data protection are essential. Nonetheless, the wireless environment has an open nature. The limited resources of sensor devices render W S N s susceptible to a variety of security attacks, causing significant difficulties in the design phase of efficient authentication and key agreement ( A K A ) protocols. This study proposes a physically unclonable function ( P U F )-based lightweight and secure A K A protocol for W S N s based on elliptic curve cryptography ( E C C ). A secure password update scheme is offered, which would allow legitimate users to reset forgotten passwords without re-registration. According to formal security analysis using B A N logic and P r o V e r i f , the proposed protocol is secure against common attacks. Moreover, from an entropy perspective, the use of dynamic pseudonyms and fresh session randomness increase an adversary’s uncertainty about user identities, thereby limiting identity-related information leakage. Performance evaluation shows that the proposed protocol achieves lower computational and communication overhead than the existing ones, making it suitable for W S N s with resource constraints.

1. Introduction

WSNs are used in many scenarios, for example, monitoring the environment, enabling healthcare-related services, supporting automated industrial processes, and improving transportation intelligence [1,2]. In this case, a large number of sensor nodes are used for collecting sensitive data and sending those data to authentic users using wireless communication channels. The open nature of wireless transmission, the unattended deployment at the sensor node’s end, and the limited physical resources or capabilities of the sensor nodes make W S N a prime target of various security issues like spoofing of node identities, replay-based intrusion, communication hijacking, and offline guessing of authentication secrets, etc. [3,4,5,6].
Authentication and Key Agreement ( A K A ) protocols are therefore indispensable components for securing W S N communications. A well-designed A K A protocol which guarantees that only legitimate users and sensor nodes are able to access the network service and fresh session keys are established to secure the transmission of further packets. Nonetheless, the task of designing efficient and secure A K A protocols for W S N s is challenging. On the one hand, sensor nodes have limited computation capability, memory, and battery power, which restricts the adoption of heavyweight cryptographic techniques. On the other hand, A K A protocols are required to provide strong security properties, which not only offer mutual authentication but also privacy preservation, perfect forward secrecy, and robustness against known attacks under powerful adversaries [7,8]. In particular, privacy in IoT-based authentication can be intuitively understood from an entropy perspective, where higher uncertainty of user identities given the observed protocol messages implies stronger resistance to tracing and identity leakage.
In recent years, several A K A schemes have been suggested to tackle these issues. Due to their ability to offer high security levels while using relatively small key sizes, elliptic curve cryptography ( E C C ) has become increasingly popular in recent years. This makes E C C suitable for W S N s , which often operate under severe resource constraints [3]. Moreover, hardware security mechanisms which use techniques such as P U F s (Physically Unclonable Functions) have been deployed to protect sensor node secrets from hardware cloning attacks [8]. The development of quantum computing has led to the emergence of post-quantum secure A K A protocols which can potentially offer long-term security of W S N s against a quantum gains adversary [4].
Figure 1 illustrates a typical W S N application. Three main components are involved: users, gateway nodes, and sensor nodes. Within such a framework, the sensed data are accessed by the users through gateway nodes that connect the users with the sensor nodes. Sensor nodes cooperatively perform data sensing and forwarding tasks, while the gateway node assists in authentication, access control, and key establishment. A practical W S N deployment basically follows this interaction pattern that also shows the importance of using secure and lightweight A K A protocols to protect the communications between various entities.
In light of these observations, we present a secure and efficient A K A protocol for W S N s using E C C -based cryptographic techniques, smart-card-assisted user authentication, and P U F -based security of sensor nodes. We aim for strong security properties alongside lightweight computation and modest communication overhead. By combining B A N logic analysis, P r o V e r i f security verification, and efficiency evaluation, we confirm that the proposed scheme can be applied effectively in practical W S N environments.
The major contributions are as follows:
  • We present a lightweight A K A protocol for W S N s which achieves mutual authentication and establishes a secure session key.
  • A P U F -based mechanism is deployed to enhance resistance of sensor nodes against physical attacks.
  • The proposed protocol and its security properties are analyzed using B A N logic and P r o V e r i f .
  • We evaluate the computational and communication costs and demonstrate the efficiency of the proposed scheme compared with existing related protocols.
  • We design a secure and user-friendly password update mechanism that allows legitimate users to reset forgotten passwords without requiring re-registration [9], while ensuring the overall security of the system remains intact.

2. Related Works

Due to various constraints such as limited computational power, energy constraints, and open wireless channels, the establishment of a secure session is very challenging. To overcome the challenges, A K A protocols are applied. Many lightweight and robust A K A schemes with strong security characteristics like mutual authentication, anonymity, forward secrecy, low computation, and communication overhead have been proposed over recent years.
A significant piece of work explores the use of Elliptic Curve Cryptography for efficient authentication. Huang et al. developed a three-factor E C C -based A K A protocol which uses biometrics, smart card, and password with formal security verification and attack resistance, which is ideally suited to resource-constrained environments [3]. To reduce overhead and improve anonymity, Li and Hu’s lightweight E C C -based A K A protocol resists ephemeral secret leakage attack [7]. Many E C C -based designs have also been proposed which can withstand offline guessing or replay attack during the session key negotiation [10]. Simultaneously, protocol proposals for lightweight two-factor A K A have occurred that are based on chaotic and symmetric which are provably secure and lightweight [11].
Hybrid approaches that combine symmetric and asymmetric mechanisms to optimize energy consumption and throughput have also been explored. For instance, secure hybrid data transmission protocols integrate key management and message authentication to support efficient node authentication and data integrity [12]. Broader surveys of I o T security and authentication mechanisms highlight the limitations of existing A K A protocols and underscore the ongoing need for lightweight schemes that maintain strong security features in diverse deployment contexts [13].
Architectural innovations such as multi-gateway A K A schemes seek to improve scalability and flexibility in W S N s . Yang et al. present a multi-gateway structure that allows dynamic access for sensors and users across network regions with reduced computation and communication costs relative to earlier schemes [14]. Beyond structural enhancements, hardware-assisted authentication mechanisms using Physically Unclonable Functions ( P U F s ) have been investigated. Tyagi and Kumar introduce P U F -based A K A protocols combined with E C C to bolster resistance against smart card loss and physical attacks [8], and further work integrates P U F with chaotic maps to achieve dynamic pseudonym generation and resistance to modeling attacks [15].
The emergence of post-quantum secure A K A schemes is due to quantum computing threats. Singh and Mishra suggest an A K A protocol for resisting a quantum attacker that relies on the security of Ring Learning With Errors (RLWE) [4]. Advanced frameworks combine lightweight cryptography with context-aware key management to adapt AKA to both classical and post-quantum threat environments [16].
Aside from these particular designs, smart-card based authentication and fuzzy-extractor-based authentication schemes defend against card loss and impersonation attacks with minimal overhead to sensor nodes [17]. Together, these works demonstrate the recent diversity of W S N   A K A research on E C C -based multi-factor schemes, lightweight symmetric and chaotic protocols, multi-gateway structures, P U F -assisted schemes, and post-quantum view.

3. Preliminaries

3.1. System Model

The system model of the proposed A K A protocol is illustrated in Figure 2. The wireless sensor network consists of three types of entities: users U i , a gateway node G W , and multiple sensor nodes S j .
The trusted authority is the gateway node responsible for initializing the network, registering users, and registering sensor nodes. In the registration stage, the user as well as sensor nodes submit their identity-related information to the gateway in a secure manner which provides and distributes the corresponding credentials. Once deployed, the gateway facilitates the authentication and key agreement between the users and sensor nodes but not in data transmission.
A user can access the sensed data via the gateway after performing mutual authentication and session key establishment of target sensor nodes. On successful authentication, a session key is established between the user and the sensor node for designated secure communication, as shown in Figure 2.

3.2. Threat Model

The protocol’s security analysis follows the Dolev–Yao adversarial model [18]. The adversary is assumed to have complete control of the public communication channel, where they can eavesdrop, intercept, modify, replay, and forge messages. However, the adversary cannot break standard cryptographic primitives, such as one-way hash functions and elliptic curve cryptographic operations.
Moreover, the adversary can physically take over the sensor nodes or steal user smart cards to get the stored data. Nonetheless, it is assumed that it is infeasible for malicious parties to extract sensitive secrets from cryptographic primitives, P U F s or solve the elliptic curve discrete logarithm problem.

3.3. Cryptographic Primitives

  • One-way hash function: We adopt a cryptographic h ( · ) to derive authentication values and maintain message integrity. It is assumed to be collision-resistant and pre-image-resistant.
  • Elliptic Curve Cryptography ( ECC ): Consider an elliptic curve E ( F p ) over the finite field F p . Let G denote a cyclic additive group of prime order q generated by P. The security of the E C C -based computations is grounded on the intractability of the elliptic-curve discrete logarithm problem ( E C D L P ).
  • Physical Unclonable Function ( PUF ): A P U F [19] is a hardware-rooted primitive that outputs device-unique, hard-to-predict responses for supplied challenges. It is utilized to protect sensor node secrets against physical attacks and cloning.

4. Proposed Protocol

The proposed protocol comprises six main phases: the initialization phase, the user registration phase, the sensor node registration phase, the mutual authentication phase, the password update phase, and the forgotten password reset phase. The gateway node executes the operations required in the first three phases. The mutual authentication phase is designed to achieve bidirectional identity verification between the user and the sensor node, and to negotiate a secure session key for ensuring the confidentiality and integrity of subsequent communications. If a password change is needed, the password update phase allows the password to be modified securely. In addition, for scenarios where a user forgets the password, the protocol provides a forgotten password reset phase, allowing the user to reset the password without providing the original one.

4.1. Initialization Phase

During the system initialization phase, the gateway node G W performs the offline setup of relevant parameters and selects security functions. G W selects an elliptic curve E defined over a finite field F p , and chooses an additive group G on E of order q, where P denotes a generator of G. Then, G W generates a private key x and computes the corresponding public key X = x P . Finally, G W chooses a master key K and a secure cryptographic hash function h ( . ) : { 0 , 1 } * { 0 , 1 } 256 . The public parameters E ( F p ) , G , P , X , h ( . ) are subsequently published.

4.2. User Registration Phase

Before obtaining sensor-collected data, a user is required to enroll with the gateway. The registration steps are outlined below. When a user needs to access data collected by sensor nodes in the system, they must first complete registration with the gateway node. The process of the user registration phase is shown in Figure 3 and outlined below:
  • Credential Setup. User U i chooses an identity I D i and a corresponding password P W i , and generates a random number a i . U i then computes H P W i = h ( P W i | | a i ) and sends the parameter { I D i , H P W i } to the gateway G W over a secure channel. After obtaining { I D i , H P W i } , G W verifies whether I D i is already registered. If it exists, U i is requested to choose a different identity; otherwise, G W computes K G U = h ( I D i | | K ) and A i = K G U H P W i , stores I D i in the user table, writes A i into a smart card S C , and delivers S C securely to U i .
  • Local Verification Setup. After receiving S C , U i computes B i = a i h ( I D i | | P W i ) and C i = h ( I D i | | H P W i ) mod M . M is chosen as a sufficiently large integer (e.g., M = 2 k , where 64 k 128 ) to prevent efficient offline verification of guessed ( I D i , P W i ) pairs.
  • Forgotten Password Reset Support. To support scenarios where the user forgets the password, the protocol further provides a forgotten password reset initialization based on security questions. User U i selects N pairwise coprime positive integers m 1 , m 2 , …, m N , and N security questions Q u e 1 , Q u e 2 , …, Q u e N , then provides the corresponding answers A n s 1 , A n s 2 , …, A n s N . Subsequently, a secret S is constructed based on the Chinese Remainder Theorem such that it satisfies: S h ( A n s n ) mod m n , 1 n N . Finally, U i computes P W S i = P W i S and writes the parameters { B i , C i , P W S i , Q u e n , m n , 1 n N } into S C .

4.3. Sensor Node Registration Phase

Prior to deployment in the operational area, a new sensor node S j must also complete registration with G W . The sensor registration phase binds each sensor node to the gateway and establishes a long-term credential protected by the PUF, which prevents physical cloning attacks. The sensor node registration process is shown in Figure 4, and the specific steps are described below:
  • Registration request. The sensor node S j picks an identity S I D j and a random challenge C h j , then generates the corresponding response R e j via a Physical Unclonable Function ( P U F ). Subsequently, S j transmits S I D j and C h j to G W over a secure channel.
  • Gateway credential assignment. Upon receiving S I D j and C h j , G W first verifies whether the same S I D j is already present in the sensor node information table. If a duplicate is found, S I D j is notified to regenerate its identity information. Otherwise, G W computes the key K G S = h ( S I D j | | K ) , records S I D j and C h j in the sensor node information table, and finally sends K G S back to S j through the secure channel. With K G S , S j computes its local key K j and stores it securely.

4.4. Mutual Authentication Phase

When a user needs to access data collected by sensor nodes, both the user and the sensor node must perform bidirectional authentication with the assistance of the gateway node. A shared session key is also negotiated to ensure the confidentiality of subsequent communications. Since the long-term credentials are established during registration, mutual authentication is completed through four message exchanges ( M s g 1 M s g 4 ), as follows:
  • Msg 1 : User ⇒ Gateway (Login request). The user U i inputs the identity I D i and corresponding password P W i , and inserts the smart card into the terminal. The terminal first performs local password verification by computing:
    a i * = B i h ( I D i | | P W i ) , H P W i * = h ( P W i | | a i * ) , C i * = h ( I D i | | H P W i * ) mod M ,
    and verifies whether C i * matches C i . If they do not match, the terminal rejects the login request. Otherwise, the terminal obtains the current timestamp T 1 , generates random numbers w and r i , selects the identity S I D j of the sensor node to be accessed. It successively computes:
    K G U = A i H P W i , D i = w · P ,   E i = w · X ,   R i = r i · P , P I D i = I D i E i , M 1 = ( R i | | S I D j ) K G U , M U G = h ( I D i | | R i | | K G U | | M 1 | | T 1 ) .
    Finally, the terminal sends:
    M s g 1 = { P I D i , D i , M 1 , M U G , T 1 }
    to the gateway node G W .
  • Msg 2 : Gateway ⇒ Sensor (Authentication challenge). Upon receiving M s g 1 , G W first verifies the validity of timestamp T 1 , then uses its private key x to compute:
    E i * = x · D i , I D i * = P I D i E i * .
    G W checks the validity of I D i * by querying the user information table, then computes:
    K G U = h ( I D i * | | K ) , ( R i * | | S I D j ) = M 1 K G U , M U G * = h ( I D i * | | R i * | | K G U | | M 1 | | T 1 ) .
    G W compares whether M U G * equals M U G . If they are not equal, G W terminates the session. Otherwise, G W generates timestamp T 2 , set I D i = I D i * , R i = R i * , and computes:
    K G S = h ( S I D j | | K ) , M 2 = ( I D i | | R i ) K G S , M G S = h ( I D i | | S I D j | | R i | | K G S | | T 2 ) .
    G W retrieves the challenge C h j and sends:
    M s g 2 = { M 2 , M G S , C h j , T 2 }
    to S j .
  • Msg 3 : Sensor ⇒ Gateway (Sensor response). After receiving M s g 2 , sensor node S j first checks the validity of timestamp T 2 . Then, it generates its P U F response and computes:
    K G S = K j P U F ( C h j ) , ( I D i | | R i ) = M 2 K G S , M G S * = h ( I D i | | S I D j | | R i | | K G S | | T 2 ) .
    If M G S * M G S the authentication session is terminated. Otherwise, S j generates random number r j and computes:
    R j = r j · P , S K j i = h ( R i | | R j | | r j · R i ) , M 3 = ( R j | | I D i | | S I D j ) K G S , M S G = h ( S I D j | | I D i | | R j | | T 3 )
    where T 3 is the current timestamp and S K j i is the session key. Finally, S j returns
    M s g 3 = { M 3 , M S G , T 3 }
    to G W .
  • Msg 4 : Gateway ⇒ User (Session confirmation). Upon receiving M s g 3 , G W checks the validity of timestamp T 3 and computes:
    ( R j | | I D i | | S I D j ) = M 3 K G S , M S G * = h ( S I D j | | I D i | | R j | | T 3 ) .
    If M S G * matches M S G , G W obtains the current timestamp T 4 and computes:
    M 4 = ( R j | | S I D j ) K G U , M G U = h ( I D i | | R j | | K G U | | T 4 ) ,
    and returns the message:
    M s g 4 = { M 4 , M G U , T 4 }
    to user U i . After receiving M s g 4 , U i checks the validity of timestamp T 4 , and computes:
    ( R j | | S I D j ) = M 4 K G U , M G U * = h ( I D i | | R j | | K G U | | T 4 ) .
    If M G U * is verified to match M G U , U i generates the session key:
    S K i j = h ( R i | | R j | | r i · R j ) ,
    thereby completing mutual authentication with sensor node S j .
The process of the mutual authentication phase described above is illustrated in Figure 5.

4.5. Password Update Phase

During the password update phase, the user can modify their password offline without interacting with the gateway node. Figure 6 is a flowchart of the process, and the specific steps are as follows:
  • User U i inserts S C into a terminal and enters the identity I D i , the original password P W i , and the new password P W i n e w .
  • The terminal computes a i * = B i h ( I D i | | P W i ) , H P W i * = h ( P W i | | a i * ) , and C i * = h ( I D i | | H P W i * ) mod M , and verifies whether the stored C i in the smart card matches the computed C i * . If they do not match, the password update request is rejected. Otherwise, the terminal successively computes K G U = A i H P W i * , H P W i n e w = h ( P W i n e w | | a i * ) , A i n e w = K G U H P W i n e w , B i n e w = a i * h ( I D i | | P W i n e w ) , C i n e w = h ( I D i | | H P W i n e w ) mod M , and P W S i n e w = P W S i P W i P W i n e w , and updates the original parameters A i , B i , C i , and P W S i in the smart card to A i n e w , B i n e w , C i n e w and P W S i n e w , respectively.

4.6. Forgotten Password Reset Phase

When a user forgets their password and needs to log in, they can securely restore access through the following procedure, as shown in Figure 6.
  • The user U i inserts S C into a terminal, enters the correct identity I D i , and provides accurate answers A n s n to all preset security questions Q u e n , 1 n N , thereby recovering the secret value S based on the Chinese Remainder Theorem ( C R T ).
  • Subsequently, U i computes the original password P W i = P W S i S and the parameter a i = B i h ( I D i | | P W i ) , inputs the new password P W i n e w , and successively calculates A i n e w = A i h ( P W i | | a i ) h ( P W i n e w | | a i ) , B i n e w = a i h ( I D i | | P W i n e w ) , C i n e w = h ( I D i | | h ( P W i n e w | | a i ) ) mod M , and P W S i n e w = P W S i P W i P W i n e w . Finally, the stored values A i , B i , C i and P W S i in S C are updated to the newly computed A i n e w , B i n e w , C i n e w , and P W S i n e w , respectively, thereby completing the secure reset of the forgotten password to P W i n e w .

5. Security Analysis

5.1. Formal Security Analysis

We evaluate the proposed A K A protocol through two widely used formal methods: B A N logic and P r o V e r i f . Using BAN logic, we prove that mutual authentication holds and that a session key is successfully set up. Essential security requirements (e.g., session-key confidentiality and authentication) are then machine-checked in P r o V e r i f under the Dolev–Yao adversary model. The two complementary approaches provide a formal assessment of the protocol’s security that is comprehensive and rigorous.

5.1.1. BAN Logic-Based Security Analysis

B A N logic is a belief-based reasoning framework that is commonly adopted to analyze authentication protocols [20]. A set of inference rules abstract actual protocol messages into their idealized form and derive the principals’ beliefs. For convenience, the notation set and the main inference rules are listed in Table 1 and Table 2 separately. Likewise, the idealized messages, assumptions, and step-by-step derivations allowing the authentication goal to be realized are summarized in Table 3. This reasoning shows that U i and S j each accept a newly generated session key and also accept that the other party accepts it, which implies mutual authentication and a secure key-agreement outcome.

5.1.2. ProVerif-Based Formal Verification

To strengthen the security claims, we employ P r o V e r i f [21] to perform automated formal verification under the Dolev–Yao adversary model, where the adversary can fully manipulate the public channel. The P r o V e r i f code of the protocol is publicly available at [22].
In the P r o V e r i f model, the user, gateway, and sensor node are specified as concurrent processes communicating over a public channel. Fresh nonces and session-related parameters are generated using new, while cryptographic operations are abstracted as symbolic functions. To model authentication behavior, event statements are inserted at key protocol stages, where UGbegin(t), UGend(t), GUbegin(t), and GUend(t) denote the initiation and completion of the user–gateway authentication, and GSbegin(t), GSend(t), SGbegin(t), and SGend(t) represent the corresponding gateway–sensor interactions. These events enable P r o V e r i f to reason about agreement between protocol participants.
Authentication is verified using injective correspondence queries, such as query inj-event(UGend(t)) ==> inj-event(UGbegin(t)), which assert that whenever a party completes a session, there exists a unique matching session initiation by the peer, thereby providing strong resistance against replay and impersonation attacks. In addition, secrecy properties are specified using confidentiality queries of the form query not attacker(x).
As shown in Figure 7, all authentication and secrecy queries are successfully verified by P r o V e r i f . Specifically, the results confirm injective authentication between the user, gateway, and sensor node in all protocol phases, as each end event is associated with a unique corresponding begin event. Moreover, the secrecy queries not attacker(svalueA[]) and not attacker(svalueB[]) are satisfied, indicating that the attacker cannot derive the modeled sensitive values from protocol executions. Therefore, the P r o V e r i f verification results in Figure 7 provide formal evidence that the scheme achieves mutual authentication and preserves the confidentiality of critical security parameters under an active adversary model.

5.2. Informal Security Analysis

In this part, we present an informal security discussion for the proposed authentication scheme. The analysis demonstrates that the protocol achieves the desired security goals and withstands various well-known attacks under the Dolev–Yao adversarial model, where an adversary can observe, intercept, alter, replay, or forge public-channel messages, but is assumed unable to compromise standard cryptographic primitives.

5.2.1. User Anonymity

The actual identity I D i of the user U i is never transmitted in plaintext on the public channel. Instead, we set a dynamic pseudonym P I D i = I D i E i , where E i = w · X is a random number (dependent on the session) with the public key (system) X. Since w is freshly chosen in each authentication session, the value of P I D i changes dynamically even for the same user. An external adversary cannot derive E i or decipher the real identity I D i without knowledge of the private key x of G W . Thus, the proposed protocol preserves user anonymity against both passive eavesdroppers and active adversaries.

5.2.2. Untraceability

The protocol achieves untraceability by making sure that all user-related authentication parameters are not the same for different sessions. In particular, the messages that are transmitted include session-specific random elliptic curve points R i = r i · P and dynamic pseudonyms P I D i using fresh random values r i and w. Moreover, authentication messages such as M U G = h ( I D i | | R i | | K G U | | M 1 | | T 1 ) bind the identity-related information with timestamps and ephemeral randomness. Since these parameters are statistically independent across sessions, an adversary cannot correlate multiple executions of the protocol to trace a specific user even if all communication messages are recorded.

5.2.3. Mutual Authentication

Through the chained checking of authentication messages, protected by system master key derivatives, the protocol enables mutual authentication among the user, the gateway, and the sensor node. The gateway authenticates the user by validating M U G , where K G U = h ( I D i | | K ) and K is the gateway’s master key. Only the holder of K must have an ability to generate a valid M U G . The sensor node validates the gateway by evaluating M G S = h ( I D i | | S I D j | | R i | | K G S | | T 2 ) . Here, K G S = h ( S I D j | | K ) , which was securely recovered using the sensor’s secret key and P U F response. Lastly, the user authenticates the gateway by verifying the message M G U , which includes the fresh sensor-generated value R j . As a result, strong mutual authentication will be established among all entities, which will detect any forged and/or modified authentication message.

5.2.4. Session Key Agreement

Once mutual authentication completes, the user and the sensor node independently compute a shared session key. The user computes S K i j = h ( R i | | R j | | r i · R j ) , while the sensor computes S K j i = h ( R i | | R j | | r j · R i ) . Due to the properties of elliptic curve scalar multiplication, r i · R j = r j · R i . Since the ephemeral secrets r i and r j are never transmitted over the public channel, an adversary cannot derive the session key even with full access to all exchanged messages.

5.2.5. Perfect Forward Secrecy

The proposed protocol offers perfect forward secrecy: each session key is derived from ephemeral random values r i and r j , which never get reused in different protocol executions. Even if long-term secrets of the user, sensor node or gateway (i.e., K, x, or stored credentials) are compromised at some stage, session keys established prior are secure, as recovering those would necessitate solving the E C D L P to extract ephemeral secrets from the past.

5.2.6. Forgotten Password Reset

A secure forgotten password reset mechanism is supported by the protocol. After successfully reconstructing the secret using the pre-selected security credential, the user can reset the password. Also, a password-related verifier is not revealed over the public channel. The reset process does not recover the old password; it does not destroy long-lived secrets or previous session keys. Consequently, the suggested scheme offers a secure approach for resetting forgotten passwords.

5.2.7. Resistance to Impersonation Attack

An adversary generates a valid authentication value M U G to impersonate a legitimate user. This requires knowing K G U , along with a fresh random value. It is impossible if the gateway’s master key is inaccessible. In a similar context, the impersonation of a sensor node needs the generation of valid M G S and M S G . These values depend on K G S that can be recovered with the help of a sensor’s P U F and its secret key. In conclusion, the protocol efficiently safeguards against impersonation attempts.

5.2.8. Resistance to Stolen Smart Card Attack

The adversary cannot get any other information from the stolen smart card other than some hashed and masked parameters. Credential verification must pass local verification with the correct password; it is also necessary to execute the protocol successfully to generate valid gateway-authenticated messages. This means that having a smart card by itself may not impersonate the user. Thus, it may resist stolen smart card attacks.

5.2.9. Resistance to Offline Password Guessing Attack

The scheme prevents offline password-guessing attacks. Even when an adversary obtains smart-card–stored data through a physical access attack or a side-channel attack, it is still not feasible to uniquely verify guessed identity–password pairs ( I D i , P W i ) offline. The local verification value C i is obtained using the modular operator, preventing an adversary from efficiently verifying guessed identity–password pairs offline. As a result, an adversary must try online login attempts to find out if a guess pair is correct. The gateway can easily detect and restrict such online attempts through monitoring and access control mechanisms. As a consequence, the proposed scheme effectively prevents offline password guessing attacks and confines the adversary to detectable online attacks.

5.2.10. Resistance to Known Session-Specific Temporary Information Attack

Even if all session-specific temporary data (including r i and r j ) are revealed, the impact is limited to that session only. The session key S K = h ( R i | | R j | | r i · R j ) is created from session-dependent values beside the long-term secrets K, x, K j , which include the gateway master key, gateway private key, and sensor secret, respectively, which remain secured. Because new random values are generated with every session, one session’s compromise does not compromise the security of any other session. As such, the designed protocol withstands attacks that rely on exposure of session-only temporary information.

5.2.11. Resistance to Replay Attack

Every authentication message contains timestamps ( T 1 , T 2 , T 3 , T 4 ) and fresh random numbers. Before processing received messages, the gateway, sensor, and user validate their freshness. Any replayed messages will fail to satisfy the timestamp verification or the authentication hash check, so replay attacks are prevented.

6. Performance Analysis

We assess the protocol’s performance in terms of computational complexity and communication overhead. Since the initialization, registration, and password update phases are executed infrequently, the performance evaluation primarily focuses on the mutual authentication phase, which represents the most critical operation in practical deployments. Furthermore, we compare our protocol with the ECC-based three-factor AKA scheme by Huang et al. [3], the industrial IoT authentication protocol by Zhao et al. [23], the anonymous signature-based scheme of Vangala et al. [24], and the privacy-controlled ECC protocol REPACA proposed by Kumar et al. [25].

6.1. Computational Performance Analysis

During the mutual authentication phase, three entities are involved: the user U i , the gateway node G W , and the sensor node S j . The dominant cryptographic operations performed by these entities include: One-way hash operation, and elliptic curve scalar point multiplication, denoted as T h and T M , respectively. Other operations, such as XOR, concatenation, and timestamp comparison, incur negligible computational cost compared to T h and T M and are therefore excluded from the analysis.
During the authentication phase, the user performs the following operations:
  • Three elliptic curve point multiplications to compute D i = w · P , E i = w · X and R i = r i · P .
  • Seven hash operations for message authentication and session key generation, including the computation of a i * , H P W i * , C i * , M 1 , M U G , M G U * , and S K i j .
Hence, the total user-side computational cost is: 3 T M + 7 T h ;
The gateway node is responsible for identity recovery, authentication verification, and message forwarding. During the authentication phase, it performs:
  • One elliptic curve point multiplication to compute E i * = x · D i .
  • Eight hash operations to verify message integrity and authenticity, including K G U , M U G * , K G S , M 2 , M G S , M S G * , M 4 , and M G U .
Thus, the computational cost at the gateway node is: T M + 8 T h .
Given the limited computational capability of sensor nodes, the proposed scheme is designed to minimize their cryptographic burden. During the authentication phase, the sensor node performs:
  • Two elliptic curve point multiplications to compute R j = r j · P and the shared secret component r j · R i .
  • Three hash operations for message authentication and session key derivation.
Hence, the computational cost at the sensor node is: 2 T M + 3 T h .
The computational performance evaluation in this work follows the standard analytical cost estimation methodology widely adopted in lightweight A K A studies. Specifically, the execution times of basic cryptographic primitives are taken from the benchmark results reported in Srinivas et al. [26], obtained on a platform equipped with a 2.4 GHz CPU and 4 GB RAM: the time required for symmetric encryption/decryption T s 8.7 ms, the execution time of a one-way hash function T h 0.32 ms, the time for E C C point multiplication T M 17.1 ms, the time for E C C point addition T A 4.4 ms, and the execution time of the fuzzy extractor Gen/Rep function T f , which is assumed to be approximately equal to T M .
In our system model, the gateway node is assumed to be a relatively resource-rich entity (e.g., an edge server or base station), whereas sensor nodes are resource-constrained devices. Although E C C operations are still required at the sensor side, the proposed protocol is designed to keep the sensor-side computational workload at a minimal level compared with existing schemes, thereby ensuring feasibility in practical W S N environments.
User–gateway–sensor interactions are simulated analytically by sequentially following the authentication message flow ( M s g 1 M s g 4 ) and counting the dominant operations executed by each participant. The total protocol cost is obtained by multiplying the operation counts by the corresponding benchmark execution times, providing a fair and reproducible comparison with related protocols.
Table 4 summarizes the computational cost comparison for the authentication phase, contrasting our scheme with four representative related protocols. As shown in Table 4, the proposed protocol exhibits the lowest overall computational cost among the compared schemes, achieving 108.4 ms per authentication session. The computational workload distribution of the proposed protocol is balanced: the gateway performs lightweight verification and forwarding, while the sensor node avoids excessive public-key operations. Such a design is particularly suitable for practical W S N deployments, where sensor-side energy consumption and latency are critical. Overall, the comparison indicates that the proposed scheme achieves competitive efficiency while retaining strong security properties.

6.2. Communication Performance Analysis

The communication performance is evaluated by comparing the total number of transmitted bits exchanged during the authentication phase. To ensure a fair comparison, the following assumptions are adopted for data length:
  • Timestamp: 32 bits.
  • Random number: 256 bits.
  • Hash output: 256 bits.
  • Identity (ID): 128 bits.
  • Elliptic curve point: 256 bits.
  • P U F challenge: 128 bits.
During the authentication phase, four rounds of message exchanges are involved:
  • M s g 1 = { P I D i , D i , M 1 , M U G , T 1 } from U i to G W .
  • M s g 2 = { M 2 , M G S , C h j , T 2 } from G W to S j .
  • M s g 3 = { M 3 , M S G , T 3 } from S j to G W .
  • M s g 4 = { M 4 , M G U , T 4 } from G W to U i .
In these messages, M U G , M G S , M S G , and M G U denote hash values, while T 1 , T 2 , T 3 , and T 4 represent timestamps. In addition, D i corresponds to a point on the elliptic curve, and C h j denotes the P U F challenge. The values P I D i , M 1 , M 2 , M 3 , and M 4 are obtained through XOR operations, whose lengths are determined by the longer operands involved, resulting in bit-lengths of 256 bits, 384 bits, 384 bits, 512 bits, and 384 bits, respectively. Consequently, the total communication cost of the authentication phase amounts to 256 4 + 32 4 + 256 + 128 + 256 + 384 + 384 + 512 + 384 = 3456 bits.
The communication cost comparison between the proposed scheme and the related schemes is summarized in Table 5. As summarized in Table 5, the proposed protocol requires four message rounds, which is consistent with the compared schemes and is generally regarded as a reasonable trade-off between security and latency in W S N scenarios. Although Kumar et al. [25] report a slightly lower communication cost (3200 bits), the proposed protocol achieves substantially lower computational cost and supports richer security functionality. Therefore, from a system-level perspective, the proposed protocol offers a favorable performance trade-off.

7. Discussion

The proposed A K A protocol presents a flexible security and efficiency trade-off for wireless sensor networks. The security of the cryptographic techniques is based on the well-established mathematics of elliptic curves. In particular, the sensor node only requires a few elliptic curve operations and hash computations during the authentication phase, which effectively reduces energy consumption.
The storage of long-term secrets in memory is avoided and physical capture and key extraction attacks are prevented to enhance the security of the sensor nodes using Physical Unclonable Functions. Furthermore, in the context of W S N s , dynamic pseudonyms and session-dependent randomness achieve user anonymity and untraceability.
The proposed protocol enhances its features with secure password update function and forgotten password reset. This is different from existing related ones. At the same time, it keeps competitive computational and communication efficiency. The design strikes a good balance among security, usability, and efficiency.
In addition to the analytical performance evaluation, it is important to consider parameter configuration in real deployment scenarios. The gateway node may adopt the widely used elliptic curve secp256r1 to balance security and computational efficiency. Since sensor nodes only perform two E C C scalar multiplications per authentication session, the proposed protocol remains feasible for resource-constrained environments. Furthermore, the timestamp tolerance window Δ T can be set to 2–5 s depending on network latency conditions. A 128-bit P U F challenge length is recommended to enhance resistance against modeling attacks while maintaining low storage overhead. These deployment-oriented considerations further support the applicability of the proposed scheme in practical W S N -based I o T systems.
The proposed protocol is built on E C C , whose security relies on the elliptic curve discrete logarithm problem. It is known that large-scale quantum computers running Shor’s algorithm may threaten E C C -based schemes. Therefore, the current design mainly targets classical security in resource-constrained W S N environments. Nevertheless, the protocol framework is modular, and E C C -based key establishment can be replaced by post-quantum primitives (e.g., lattice-based approaches) in future extensions. This will be considered as an important direction for long-term I o T security.

8. Conclusions

In this study, we proposed a secure and efficient A K A protocol for W S N s . The proposed protocol guarantees secure mutual authentication as well as session key establishment. It also offers strong privacy protection. This was achieved through E C C -based smart card user authentication and P U F -assisted sensor authentication.
The proposed protocol was shown to be secure against impersonation, replay, offline password guessing, and stolen smart card attack through formal verification using B A N logic and P r o V e r i f along with informal security analysis. Performance results show that our protocol reduces computation compared with several prior schemes, while keeping communication overhead at an acceptable level.
Therefore, the protocol is well suited to practical W S N scenarios requiring secure, privacy-preserving, and lightweight authentication. Future work on the scheme will include more complex architectures of the network and further improvement in robustness on deployment.
Future work will extend the proposed scheme in two directions: (i) conducting simulation-based W S N evaluations to measure authentication delay and energy consumption under varying node densities and network scales, and (ii) integrating lightweight post-quantum key agreement primitives to improve long-term security against quantum adversaries.

Author Contributions

Conceptualization, Y.Y. and K.W.; methodology, Y.Y.; software, Y.Y.; validation, K.Q. and W.W.; formal analysis, W.W.; investigation, K.Q.; resources, K.W.; data curation, Y.Y.; writing—original draft preparation, Y.Y.; writing—review and editing, W.W.; visualization, K.Q.; supervision, K.W.; project administration, K.W.; funding acquisition, K.W. All authors have read and agreed to the published version of the manuscript.

Funding

This work was supported by the Scientific Research Startup Fund for Shenzhen High-Caliber Personnel of SZPT, No. 6022310051K, and the Industry-University-Research Innovation Fund for Chinese Universities (No. 2023IT068).

Data Availability Statement

Data are contained within the article.

Conflicts of Interest

The authors declare no conflicts of interest.

References

  1. Akyildiz, I.F.; Su, W.; Sankarasubramaniam, Y.; Cayirci, E. Wireless sensor networks: A survey. Comput. Netw. 2002, 38, 393–422. [Google Scholar] [CrossRef]
  2. Ahmim, M.; Ouafi, N.; Ullah, I.; Ahmim, A.; Chefrour, D.; Almukhlifi, R. LSAP-IoHT: Lightweight Secure Authentication Protocol for the Internet of Healthcare Things. Comput. Mater. Contin. 2025, 85, 5093–5116. [Google Scholar] [CrossRef]
  3. Huang, W. ECC-based three-factor authentication and key agreement scheme for wireless sensor networks. Sci. Rep. 2024, 14, 1787. [Google Scholar] [CrossRef] [PubMed]
  4. Singh, M.; Mishra, D. Post-quantum secure authenticated key agreement protocol for wireless sensor networks. Telecommun. Syst. 2023, 84, 101–113. [Google Scholar] [CrossRef]
  5. Roman, R.; Zhou, J.; Lopez, J. On the features and challenges of security and privacy in distributed internet of things. Comput. Netw. 2013, 57, 2266–2279. [Google Scholar] [CrossRef]
  6. Zhou, Y.; Chen, L.; Zhao, X.; Yang, Z. An anonymous authentication scheme with controllable linkability for vehicle sensor networks. Comput. Model. Eng. Sci. 2020, 125, 1101–1118. [Google Scholar] [CrossRef]
  7. Li, M.; Hu, S. A lightweight ECC-based authentication and key agreement protocol for IoT with dynamic authentication credentials. Sensors 2024, 24, 7967. [Google Scholar] [CrossRef]
  8. Tyagi, G.; Kumar, R. An efficient user authentication and key agreement scheme for wireless sensor networks using physically unclonable function. Int. J. Inf. Secur. 2024, 23, 935–962. [Google Scholar] [CrossRef]
  9. Li, Y.; Chen, Z.; Wang, H.; Sun, K.; Jajodia, S. Understanding account recovery in the wild and its security implications. IEEE Trans. Dependable Secur. Comput. 2020, 19, 620–634. [Google Scholar] [CrossRef]
  10. Deng, M.; Ma, Q.; Song, Q.; Zhang, C.; Zuo, Z. Enhanced wireless sensor network authentication key agreement protocol. Comput. Eng. 2025, 51, 186–193. [Google Scholar] [CrossRef]
  11. Feng, H.; Cai, B. A Provably Secure and Lightweight Two-Factor Authentication Protocol for Wireless Sensor Network. Electronics 2024, 13, 4289. [Google Scholar] [CrossRef]
  12. Sharmila, A.; Rishiwal, V.; Kumar, P.; Yadav, M.; Yadav, P. Secure Hybrid Data Transmission Protocol for WSN with Key Management and Message Authentication. SN Comput. Sci. 2025, 6, 401. [Google Scholar] [CrossRef]
  13. Dash, S.; Khan, A.U.; Kar, B.; Swain, S.K.; Kuswiradyo, P.; Tadele, S.B.; Wakgra, F.G. CRAMP: Clustering-based RANs association and MEC placement for delay-sensitive applications. J. Netw. Comput. Appl. 2024, 227, 103893. [Google Scholar] [CrossRef]
  14. Yang, J.H. A multi-gateway authentication and key-agreement scheme on wireless sensor networks for IoT. EURASIP J. Inf. Secur. 2023, 2023, 2. [Google Scholar] [CrossRef]
  15. Wang, L.; Han, C. Multi-factor authentication and key agreement scheme based on PUF and Chebyshev chaotic map for wireless sensor networks. Sci. Rep. 2025, 16, 3311. [Google Scholar] [CrossRef]
  16. Hayouni, H. Adaptive post-quantum security framework for wireless sensor networks using lightweight cryptography and context-aware key management. J. Supercomput. 2025, 81, 1426. [Google Scholar] [CrossRef]
  17. Paul, R.; Rai, S.; Banerjee, S.; Meher, P. A robust smart card based authentication and key agreement scheme for wsn using fuzzy Extractor. Peer-to-Peer Netw. Appl. 2024, 17, 432–450. [Google Scholar] [CrossRef]
  18. Dolev, D.; Yao, A. On the security of public key protocols. IEEE Trans. Inf. Theory 2003, 29, 198–208. [Google Scholar] [CrossRef]
  19. Gassend, B.; Clarke, D.; Van Dijk, M.; Devadas, S. Silicon physical random functions. In Proceedings of the 9th ACM Conference on Computer and Communications Security, Washington, DC, USA, 18–22 November 2002; pp. 148–160. [Google Scholar]
  20. Burrows, M.; Abadi, M.; Needham, R. A logic of authentication. ACM Trans. Comput. Syst. (TOCS) 1990, 8, 18–36. [Google Scholar] [CrossRef]
  21. Blanchet, B. An Efficient Cryptographic Protocol Verifier Based on Prolog Rules. In Proceedings of the 14th IEEE Computer Security Foundations Workshop (CSFW-14), Washington, DC, USA, 11–13 June 2001; pp. 82–96. [Google Scholar]
  22. AKA.pv. Available online: https://github.com/yycitbT/ProVerif/blob/main/AKA.pv (accessed on 26 December 2025).
  23. Zhao, X.; Li, D.; Li, H. Practical three-factor authentication protocol based on elliptic curve cryptography for industrial internet of things. Sensors 2022, 22, 7510. [Google Scholar] [CrossRef]
  24. Vangala, A.; Das, A.K.; Lee, J.H. Provably secure signature-based anonymous user authentication protocol in an Internet of Things-enabled intelligent precision agricultural environment. Concurr. Comput. Pract. Exp. 2023, 35, e6187. [Google Scholar] [CrossRef]
  25. Kumar, C.M.; Dwivedi, S.K.; Brindha, M.; Al-Shehari, T.; Alfakih, T.; Alsalman, H.; Amin, R. REPACA: Robust ECC based privacy-controlled mutual authentication and session key sharing protocol in coalmines application with provable security. Peer-to-Peer Netw. Appl. 2024, 17, 4264–4285. [Google Scholar] [CrossRef]
  26. Srinivas, J.; Das, A.K.; Wazid, M.; Vasilakos, A.V. Designing secure user authentication protocol for big data collection in IoT-based intelligent transportation system. IEEE Internet Things J. 2020, 8, 7727–7744. [Google Scholar] [CrossRef]
Figure 1. A typical W S N scenario.
Figure 1. A typical W S N scenario.
Entropy 28 00185 g001
Figure 2. System model.
Figure 2. System model.
Entropy 28 00185 g002
Figure 3. User registration phase.
Figure 3. User registration phase.
Entropy 28 00185 g003
Figure 4. Sensor node registration phase.
Figure 4. Sensor node registration phase.
Entropy 28 00185 g004
Figure 5. Mutual authentication phase.
Figure 5. Mutual authentication phase.
Entropy 28 00185 g005
Figure 6. (a) Password update phase. (b) Forgotten password reset phase.
Figure 6. (a) Password update phase. (b) Forgotten password reset phase.
Entropy 28 00185 g006
Figure 7. Formal verification results of the proposed protocol using P r o V e r i f .
Figure 7. Formal verification results of the proposed protocol using P r o V e r i f .
Entropy 28 00185 g007
Table 1. Basic notations of B A N logic.
Table 1. Basic notations of B A N logic.
NotationMeaning
P X Principal P considers X to be true
P X Principal P has received message X
P X At some earlier time, Principal P uttered message X
P X Principal P has jurisdiction over statement X
# ( X ) Message X is fresh (i.e., has not been sent before)
P K Q Principals P and Q share a valid secret key K
{ X } K Message X is encrypted using key K
( X , Y ) The concatenation of messages X and Y
Table 2. Common inference rules of B A N logic.
Table 2. Common inference rules of B A N logic.
RuleFormal ExpressionExplanation
Message Meaning Rule ( M M R ) P P K Q , P { X } K P Q X If P trusts K as a shared secret with Q and observes { X } K , then P concludes that Q previously sent X.
Nonce Verification Rule ( N V R ) P # ( X ) , P Q X P Q X When P regards X as fresh and also believes Q once stated X, P can infer that Q now believes X.
Jurisdiction Rule ( J R ) P Q X , P Q X P X If P accepts Q as an authority on X and believes that Q believes X, then P adopts X as well.
Freshness Rule ( F R ) P # ( X ) P # ( X , Y ) Freshness of X implies freshness of the composite ( X , Y ) .
Belief Rule ( B R ) P Q ( X , Y ) P Q X If P thinks Q believes ( X , Y ) , then P can safely infer that Q believes X.
Table 3. The reasoning process based on B A N logic.
Table 3. The reasoning process based on B A N logic.
Goals
G 1 U i ( U i S K S j ) G 2 U i S j ( U i S K S j )
G 3 S j ( U i S K S j ) G 4 S j U i ( U i S K S j )
Idealizations
M s g 1 U i G W : { ( R i , S I D j ) , T 1 } K G U
M s g 2 G W S j : { ( U i S K S j ) , ( U i ( U i S K S j ) ) , T 2 } K G S
M s g 3 S j G W : { ( R j , I D i , S I D j ) , T 3 } K G S
M s g 4 G W U i : { ( U i S K S j ) , ( S j ( U i S K S j ) ) , T 4 } K G U
Assumptions
A 1 U i ( U i K G U G W ) A 2 G W ( U i K G U G W )
A 3 S j ( S j K G S G W ) A 4 G W ( S j K G S G W )
A 5 U i # ( T 4 ) A 6 S j # ( T 2 )
A 7 U i ( G W ( U i S K S j ) ) A 8 S j ( G W ( U i S K S j ) )
A 9 U i ( G W ( S j ( U i S K S j ) ) ) A 10 S j ( G W ( U i ( U i S K S j ) ) )
Derivation
D 1 From M s g 4 and A 1 , by  M M R : U i G W ( T 4 , ( U i S K S j ) , ( S j ( U i S K S j ) ) )
D 2 From A 5 , by  F R : U i # ( T 4 , ( U i S K S j ) , ( S j ( U i S K S j ) ) )
D 3 From D 1 and D 2 , by  N V R : U i G W ( ( U i S K S j ) , ( S j ( U i S K S j ) ) )
D 4 From D 3 , by  B R : U i G W ( U i S K S j )
D 5 From D 4 and A 7 , by  J R : U i ( U i S K S j )    (Goal G 1 )
D 6 From D 3 , by  B R : U i G W ( S j ( U i S K S j ) )
D 7 From D 6 and A 9 , by  J R : U i S j ( U i S K S j )    (Goal G 2 )
D 8 From M s g 2 and A 3 , by  M M R : S j G W ( T 2 , ( U i S K S j ) , ( U i ( U i S K S j ) ) )
D 9 From A 6 , by  F R : S j # ( T 2 , ( U i S K S j ) , ( U i ( U i S K S j ) ) )
D 10 From D 8 and D 9 , by  N V R : S j G W ( ( U i S K S j ) , ( U i ( U i S K S j ) ) )
D 11 From D 10 , by  B R , and  A 8   J R : S j ( U i S K S j )    (Goal G 3 )
D 12 From D 10 , by  B R and A 10 , by  J R : S j U i ( U i S K S j )    (Goal G 4 )
Table 4. Computational cost comparison in the authentication phase with existing schemes [3,23,24,25].
Table 4. Computational cost comparison in the authentication phase with existing schemes [3,23,24,25].
ProtocolUser U i Gateway Node GW Sensor Node S j Total Cost (in ms)
Zhao et al. [23] 2 T M + 8 T h + T f 2 T M + 8 T h 2 T M + 5 T h 126.4 ms
Vangala et al. [24] 5 T M + 12 T h + T A + T s + T f 6 T M + 12 T h + 2 T A 4 T M + 9 T h + T A 310.5 ms
Huang et al. [3] 4 T M + 17 T h + T f 2 T M + 17 T h 3 T M + 8 T h 180.4 ms
Kumar et al. [25] 2 T M + 4 T h 4 T M + 9 T h 2 T M + 6 T h 142.9 ms
Proposed 3 T M + 7 T h T M + 8 T h 2 T M + 3 T h 108.4 ms
Table 5. Communication cost comparison in the authentication phase with existing schemes [3,23,24,25].
Table 5. Communication cost comparison in the authentication phase with existing schemes [3,23,24,25].
ProtocolNumber of MessagesTotal Communication Cost (bits)
Zhao et al. [23]43456 bits
Vangala et al. [24]45152 bits
Huang et al. [3]45504 bits
Kumar et al. [25]43200 bits
Proposed43456 bits
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content.

Share and Cite

MDPI and ACS Style

Yu, Y.; Wei, K.; Qi, K.; Wu, W. Privacy-Preserving ECC-Based AKA for Resource-Constrained IoT Sensor Networks with Forgotten Password Reset. Entropy 2026, 28, 185. https://doi.org/10.3390/e28020185

AMA Style

Yu Y, Wei K, Qi K, Wu W. Privacy-Preserving ECC-Based AKA for Resource-Constrained IoT Sensor Networks with Forgotten Password Reset. Entropy. 2026; 28(2):185. https://doi.org/10.3390/e28020185

Chicago/Turabian Style

Yu, Yicheng, Kai Wei, Kun Qi, and Wangyu Wu. 2026. "Privacy-Preserving ECC-Based AKA for Resource-Constrained IoT Sensor Networks with Forgotten Password Reset" Entropy 28, no. 2: 185. https://doi.org/10.3390/e28020185

APA Style

Yu, Y., Wei, K., Qi, K., & Wu, W. (2026). Privacy-Preserving ECC-Based AKA for Resource-Constrained IoT Sensor Networks with Forgotten Password Reset. Entropy, 28(2), 185. https://doi.org/10.3390/e28020185

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop