
Lightweight IoT Authentication Protocols: A Comparative Review | IJCT Volume 13 – Issue 4 | IJCT-V13I4P25
IJCT
International Journal of Computer Techniques
ISSN 2394-2231 · Peer-Reviewed · Open Access
📚 Volume 13, Issue 4
📅 August 24, 2026
📄 Pages 244–252
🔖 ID: IJCT-V13I4P25
Table of Contents
ToggleLightweight IoT Authentication Protocols: A Comparative Review
Author(s)
Jamal M. Al-Abdi, Adnan H. Al-Helali
Abstract
The Internet of Things (IoT) is expected to interconnect more than 75 billion devices worldwide, yet device authenticity remains one of the most pressing unsolved security challenges in the IoT space. Typical IoT nodes have limited computing power, memory, and battery capacity, making traditional public-key-based authentication difficult to implement without compromising either security or resource conservation. This paper presents a structured narrative review and quantitative comparison of lightweight authentication protocols for IoT environments published between 2024 and 2026, spanning seven families: Elliptic Curve Cryptography (ECC)-based, ECC for Radio Frequency Identification (RFID), hash-based, Physical Unclonable Function (PUF)-based, biometric and behavioural, blockchain-assisted, and machine-learning-augmented protocols. The review adds message-level protocol-flow comparisons for representative ECC- and PUF-based schemes, a benchmarking table of published latency, message-size, and energy indicators, and five sector-specific case studies. Reported findings include dynamic-credential ECC schemes reducing communication and computational overhead by more than 37% over prior ECC schemes; PUF-based techniques using machine learning to improve modelling-attack resistance by more than 35% over earlier techniques; blockchain-assisted authentication for fog-enabled IoT; and multi-sector schemes such as SELAP, reducing computation and communication cost to 422 ms and 960 bits respectively, against 548 ms and 2048 bits for the earlier ELWSCAS protocol. Protocols are also examined against ephemeral information leakage, modelling attacks on PUFs, node cloning, and physical tampering. No protocol category is universally optimal; selection depends on a deployment’s constraints, threat model, and sector. Research is converging on hybrid designs combining hardware-rooted trust, efficient public-key primitives, decentralised trust, and intelligent anomaly detection.
Keywords
blockchain-assisted authentication; elliptic curve cryptography; Internet of Things (IoT); lightweight authentication protocols; physical unclonable function (PUF); resource-constrained devices
Conclusion
Lightweight authentication protocols address a foundational security requirement for IoT ecosystems: verifying device and user identity without exceeding the processing, memory, and energy budgets of constrained hardware. The 2024–2026 literature reflects a maturing and diversifying landscape spanning dynamic-credential ECC schemes, RFID-specific ECC protocols, timestamp-synchronised hash-based methods, neural-network-hardened PUF protocols, biometric and behavioural authentication, blockchain-assisted decentralised-trust architectures, and multi-sector validated frameworks such as SELAP. The protocol-flow analysis and quantitative benchmarking added in this revision show that computational cost concentrates at structurally different points across protocol families, and that only a minority of published studies report figures that are directly comparable across schemes. As IoT deployments continue to expand into smart cities, industrial manufacturing, agriculture, healthcare, and critical infrastructure — and as attackers increasingly weaponise automated and AI-assisted tools against poorly authenticated devices — continued refinement of lightweight authentication protocols, validated through formal security analysis, standardised real-world benchmarking, and independent replication across comparable testbeds, will remain essential to securing the expanding IoT attack surface through 2027 and beyond.
References
[1] Nozomi Networks Labs, “OT/IoT cybersecurity trends and insights, February 2026,” Feb. 2026. [Online]. Available: https://www.nozominetworks.com/ot-iot-cybersecurity-trends-insights-february-2026
[2] GlobalSign, “The future of IoT security is regulation, standards and trust,” Feb. 25, 2026. [Online]. Available: https://www.globalsign.com/en/blog/will-iot-security-finally-grow-up-in-2026
[3] A. N. Alsheavi, A. Hawbani, X. Wang, W. Othman, L. Zhao, Z. Liu, S. H. Alsamhi, and M. A. A. Al-Qaness, “Internet of Things (IoT) authentication protocols: Classification, trend and opportunities,” IEEE Trans. Sustainable Comput., vol. 10, no. 3, pp. 515–533, 2025, doi: 10.1109/TSUSC.2024.3492152.
[4] I. Cetintav, “Lightweight IoT authentication protocols — review from the cryptographic engineering perspective,” IEEE Access, 2025. [Online]. Available: https://ieeexplore.ieee.org/iel8/6287639/10820123/10904450.pdf
[5] M. Li and S. Hu, “An IoT lightweight authentication and key agreement protocol using dynamic authentication credentials based on ECC,” Sensors, vol. 24, no. 24, art. no. 7967, 2024, doi: 10.3390/s24247967.
[6] A. Khalique, “Lightweight authentication for Internet of Things (IoT) devices in sustainable smart city,” Sci. Rep., vol. 15, 2025. [Online]. Available: https://www.nature.com/articles/s41598-025-10181-0
[7] M. Li, “An efficient identity authentication protocol for IoT devices employing Schnorr signature,” Procedia Comput. Sci., 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S1877050925011226
[8] A. Javadi, S. Sadeghi, P. Pahlevani, N. Bagheri, S. Rostampour, and Y. Bendavid, “Secure and efficient lightweight authentication protocol for multi-sector IoT applications,” Internet of Things, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S2542660525000125
[9] H. Timouhin et al., “Survey of RFID mutual authentication protocols based on ECC in resource-constrained environments in IoT,” in Lecture Notes in Networks and Systems. Berlin, Germany: Springer, 2024, pp. 195–200, doi: 10.1007/978-3-031-48573-2_28.
[10] Elaoudi et al., “[Full author list, title, and venue as cited in the source manuscript — incomplete; to be completed by the authors before submission],” 2025.
[11] B. Mefgouda, R. Khan, O. Alhussein, H. Saleh, H. B. Eldeeb, A. Pandey, and S. Muhaidat, “LPUF-AuthNet: Low-power and lightweight authentication for IoT using split learning and tandem neural network based PUFs,” in Proc. IEEE Global Communications Conf. (GLOBECOM), 2024. [Online]. Available: https://arxiv.org/abs/2410.12190
[12] A. M. Alharthi, “Authentications for Internet of Things (IoT) in smart manufacturing with lightweight protocol based on PUFs,” Electronics, vol. 14, no. 9, art. no. 1788, 2025. [Online]. Available: https://www.mdpi.com/2079-9292/14/9/1788
[13] S. Li, Y. Huang, and B. Yu, “Flexible and practical anonymous end-to-end authentication protocol to the PUF,” Comput. Netw., vol. 247, art. no. 110426, 2024. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S1389128624002585
[14] S. Dargaoui, M. Azrour, A. El Allaoui, A. Guezzaz, and M. A. A. Hammoudeh, “Novel efficient PUF-based authentication protocol for IoT-based smart agriculture applications,” J. Adv. Inf. Technol., vol. 16, no. 4, pp. 582–593, 2025, doi: 10.12720/jait.16.4.582-593.
[15] “State-of-the-art and future research directions of AI-enabled smart interfaces for secure biometric authentication in IoT ecosystems,” in Proc. Int. Conf. on Smart Computing (ICSC), 2026, pp. 312–319, doi: 10.1109/ICSC67292.2026.00052.
[16] S. Kanagamalliga, “Integration of biometrics and IoT for door access control and security in the distant future,” in E3S Web of Conferences (ICSGET 2025), 2025. [Online]. Available: https://www.e3s-conferences.org/articles/e3sconf/pdf/2025/19/e3sconf_icsget2025_03013.pdf
[17] Ponnuru et al., “BAAP-FIoT: Blockchain-assisted authentication protocol for fog-enabled IoT,” 2025. [Reference details absent from the source manuscript — full author list, venue, volume, pages, and DOI to be completed by the authors before submission.]
[18] “Authenticating and cost-saving IoT device authentication key management system,” in Proc. IHCSP 2024, 2024, doi: 10.1109/ihcsp63227.2024.10960153. [Individual author list not independently verifiable.]
[2] GlobalSign, “The future of IoT security is regulation, standards and trust,” Feb. 25, 2026. [Online]. Available: https://www.globalsign.com/en/blog/will-iot-security-finally-grow-up-in-2026
[3] A. N. Alsheavi, A. Hawbani, X. Wang, W. Othman, L. Zhao, Z. Liu, S. H. Alsamhi, and M. A. A. Al-Qaness, “Internet of Things (IoT) authentication protocols: Classification, trend and opportunities,” IEEE Trans. Sustainable Comput., vol. 10, no. 3, pp. 515–533, 2025, doi: 10.1109/TSUSC.2024.3492152.
[4] I. Cetintav, “Lightweight IoT authentication protocols — review from the cryptographic engineering perspective,” IEEE Access, 2025. [Online]. Available: https://ieeexplore.ieee.org/iel8/6287639/10820123/10904450.pdf
[5] M. Li and S. Hu, “An IoT lightweight authentication and key agreement protocol using dynamic authentication credentials based on ECC,” Sensors, vol. 24, no. 24, art. no. 7967, 2024, doi: 10.3390/s24247967.
[6] A. Khalique, “Lightweight authentication for Internet of Things (IoT) devices in sustainable smart city,” Sci. Rep., vol. 15, 2025. [Online]. Available: https://www.nature.com/articles/s41598-025-10181-0
[7] M. Li, “An efficient identity authentication protocol for IoT devices employing Schnorr signature,” Procedia Comput. Sci., 2025. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S1877050925011226
[8] A. Javadi, S. Sadeghi, P. Pahlevani, N. Bagheri, S. Rostampour, and Y. Bendavid, “Secure and efficient lightweight authentication protocol for multi-sector IoT applications,” Internet of Things, 2025. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S2542660525000125
[9] H. Timouhin et al., “Survey of RFID mutual authentication protocols based on ECC in resource-constrained environments in IoT,” in Lecture Notes in Networks and Systems. Berlin, Germany: Springer, 2024, pp. 195–200, doi: 10.1007/978-3-031-48573-2_28.
[10] Elaoudi et al., “[Full author list, title, and venue as cited in the source manuscript — incomplete; to be completed by the authors before submission],” 2025.
[11] B. Mefgouda, R. Khan, O. Alhussein, H. Saleh, H. B. Eldeeb, A. Pandey, and S. Muhaidat, “LPUF-AuthNet: Low-power and lightweight authentication for IoT using split learning and tandem neural network based PUFs,” in Proc. IEEE Global Communications Conf. (GLOBECOM), 2024. [Online]. Available: https://arxiv.org/abs/2410.12190
[12] A. M. Alharthi, “Authentications for Internet of Things (IoT) in smart manufacturing with lightweight protocol based on PUFs,” Electronics, vol. 14, no. 9, art. no. 1788, 2025. [Online]. Available: https://www.mdpi.com/2079-9292/14/9/1788
[13] S. Li, Y. Huang, and B. Yu, “Flexible and practical anonymous end-to-end authentication protocol to the PUF,” Comput. Netw., vol. 247, art. no. 110426, 2024. [Online]. Available: https://www.sciencedirect.com/science/article/abs/pii/S1389128624002585
[14] S. Dargaoui, M. Azrour, A. El Allaoui, A. Guezzaz, and M. A. A. Hammoudeh, “Novel efficient PUF-based authentication protocol for IoT-based smart agriculture applications,” J. Adv. Inf. Technol., vol. 16, no. 4, pp. 582–593, 2025, doi: 10.12720/jait.16.4.582-593.
[15] “State-of-the-art and future research directions of AI-enabled smart interfaces for secure biometric authentication in IoT ecosystems,” in Proc. Int. Conf. on Smart Computing (ICSC), 2026, pp. 312–319, doi: 10.1109/ICSC67292.2026.00052.
[16] S. Kanagamalliga, “Integration of biometrics and IoT for door access control and security in the distant future,” in E3S Web of Conferences (ICSGET 2025), 2025. [Online]. Available: https://www.e3s-conferences.org/articles/e3sconf/pdf/2025/19/e3sconf_icsget2025_03013.pdf
[17] Ponnuru et al., “BAAP-FIoT: Blockchain-assisted authentication protocol for fog-enabled IoT,” 2025. [Reference details absent from the source manuscript — full author list, venue, volume, pages, and DOI to be completed by the authors before submission.]
[18] “Authenticating and cost-saving IoT device authentication key management system,” in Proc. IHCSP 2024, 2024, doi: 10.1109/ihcsp63227.2024.10960153. [Individual author list not independently verifiable.]
📋 How to Cite This Paper
Jamal M. Al-Abdi, Adnan H. Al-Helali (2026). Lightweight IoT Authentication Protocols: A Comparative Review. International Journal of Computer Techniques, 13(4), 244–252. ISSN: 2394-2231. DOI: https://doi.org/10.5281/zenodo.22076194









