This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
                
                        
            Open AccessArticle
            
                A Secure and Lightweight ECC-Based Authentication Protocol for Wireless Medical Sensors Networks            
            
                                by
                    
    Yu Shang
 Yu Shang
Yu Shang ,
, 
    Junhua Chen
 Junhua Chen
Junhua Chen
    Shenjin Wang
 Shenjin Wang
Shenjin Wang
    Ya Zhang
 Ya Zhang
Ya Zhang
    Kaixuan Ma
 Kaixuan Ma
Kaixuan Ma 
                            
                
                    
                        School of Mathematics and Computer Science, Yunnan Minzu University, Kunming 650504, China
         
    
    
            
            *
            Author to whom correspondence should be addressed. 
         
    
    
    
 
             
            
                Sensors 2025, 25(21), 6567; https://doi.org/10.3390/s25216567 (registering DOI)
            
            
                    
    Submission received: 12 September 2025
    /
    Revised: 12 October 2025
    /
    Accepted: 21 October 2025
    /
    Published: 24 October 2025
            
                
    
            
            
                        
            
            
            
        
                        
        
                        
        
                        
        
        
                        
        
                        
                                                                            
                                                                            
            
                            Abstract
            
            
                                                            Wireless Medical Sensor Networks (WMSNs) collect and transmit patients’ physiological data in real time through various sensors, playing an increasingly important role in intelligent healthcare. Authentication protocols in WMSNs ensure that users can securely access real-time data from sensor nodes. Although many researchers have proposed authentication schemes to resist common attacks, insufficient attention has been paid to insider attacks and ephemeral secret leakage (ESL) attacks. Moreover, existing adversary models still have limitations in accurately characterizing an attacker’s capabilities. To address these issues, this paper extends the traditional adversary model to better reflect practical deployment scenarios, assuming a semi-trusted server and allowing adversaries to obtain users’ temporary secrets. Based on this enhanced model, we design an efficient ECC-based authentication and key agreement protocol that ensures the confidentiality of users’ passwords, biometric data, and long-term private keys during the registration phase, thereby mitigating insider threats. The proposed protocol combines anonymous authentication and elliptic curve cryptography (ECC) key exchange to satisfy security requirements. Performance analysis demonstrates that the proposed protocol achieves lower computational and communication costs compared with existing schemes. Furthermore, the protocol’s security is formally proven under the Random Oracle (ROR) model and verified using the ProVerif tool, confirming its security and reliability. Therefore, the proposed protocol can be effectively applied to secure data transmission and user authentication in wireless medical sensor networks and other IoT environments.
                    
                            
            
                            
            
                        
                        
                        
                    
                        
            
            
    
        
     
            
                Share and Cite
                
                
                    
MDPI and ACS Style
                    Shang, Y.;                     Chen, J.;                     Wang, S.;                     Zhang, Y.;                     Ma, K.    
        A Secure and Lightweight ECC-Based Authentication Protocol for Wireless Medical Sensors Networks. Sensors 2025, 25, 6567.
    https://doi.org/10.3390/s25216567
    AMA Style
    
                                Shang Y,                                 Chen J,                                 Wang S,                                 Zhang Y,                                 Ma K.        
                A Secure and Lightweight ECC-Based Authentication Protocol for Wireless Medical Sensors Networks. Sensors. 2025; 25(21):6567.
        https://doi.org/10.3390/s25216567
    
    Chicago/Turabian Style
    
                                Shang, Yu,                                 Junhua Chen,                                 Shenjin Wang,                                 Ya Zhang,                                 and Kaixuan Ma.        
                2025. "A Secure and Lightweight ECC-Based Authentication Protocol for Wireless Medical Sensors Networks" Sensors 25, no. 21: 6567.
        https://doi.org/10.3390/s25216567
    
    APA Style
    
                                Shang, Y.,                                 Chen, J.,                                 Wang, S.,                                 Zhang, Y.,                                 & Ma, K.        
        
        (2025). A Secure and Lightweight ECC-Based Authentication Protocol for Wireless Medical Sensors Networks. Sensors, 25(21), 6567.
        https://doi.org/10.3390/s25216567
    
 
                 
                                    
                        Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details 
here.
                    
Article Metrics
                
                    
            
            Article Access Statistics
            
                            For more information on the journal statistics, click 
here.
            
            
                Multiple requests from the same IP address are counted as one view.