Skip to content
Open access

An ECC- and OT-based privacy-preserving authentication scheme for smart home systems

Aug 2026 · Journal of King Saud University: Computer and Information Sciences · Vol 38 · 1 citation · 59 references

TL;DR

A lightweight identity authentication and key agreement scheme integrating Oblivious Transfer and Elliptic Curve Cryptography is proposed, which adopts multi-factor authentication based on fingerprints, passwords, and hardware identifiers to enable mutual authentication, while timestamps, counters, and dynamic identity updates are employed to resist replay attacks and ensure forward secrecy and user privacy.

Abstract

Although the integration of 5G and AIoT technologies has created new opportunities for smart home systems, security issues remain a major barrier to their sustainable development and widespread adoption. Traditional identity authentication methods in smart home systems suffer from high computational complexity, complicated key management, and poor scalability, making them unsuitable for smart home environments with stringent storage and energy constraints. In addition, users’ private data face serious threats during the processes of collection, transmission, and storage. To address these challenges, this paper proposes a lightweight identity authentication and key agreement scheme integrating Oblivious Transfer (OT) and Elliptic Curve Cryptography (ECC). The proposed scheme adopts multi-factor authentication based on fingerprints, passwords, and hardware identifiers to enable mutual authentication, while timestamps, counters, and dynamic identity updates are employed to resist replay attacks and ensure forward secrecy and user privacy. Comprehensive security analysis and performance evaluation demonstrate that the proposed scheme reduces communication overhead by 10.93%–63.46%, computational cost by 0.07%–91.70%, and energy overhead by 27.54%–52.05% over existing schemes, thereby providing a secure and efficient authentication solution for resource-constrained smart home environments.

Read PDF

Similar papers

Open access 2026

Scalable and Robust Multi-Factor Authentication Mechanism Based on ECC for IoT Devices

In today's digital landscape, devices seamlessly integrate across a wide range of domains, including smart cities, industry and smart healthcare. Authentication of these entities has become a paramount concern and remains one of the most significant security challenges in Internet of Things (IoT) networks. Most IoT aut...

A. Benqassmi, S. Bendaoud, F. Amounas et al. · 0 citations
Open access Aug 2026

Achieving Security and Efficiency with a Signcryption-Based Key Agreement Scheme and Location Privacy in FANETs

Flying Ad Hoc Networks (FANETs) composed of highly mobile Unmanned Aerial Vehicles (UAVs) are increasingly employed in mission-critical applications. However, the open wireless medium, high mobility, and resource constraints of UAVs expose FANETs to severe security and privacy threats, particularly at the Medium Access...

Sufian Al Majmaie, Ghazal Ghajari, A. Aldujaili et al. · 0 citations
Open access Sep 2026

A Security-Enhanced Certificateless Aggregate Signature-Based Conditional Privacy-Preserving Authentication Scheme for VANETs

Vehicular ad hoc networks (VANETs) have become a vital component of intelligent transport systems, with their security concerns increasingly drawing attention. To safeguard user privacy and ensure data authenticity and integrity, researchers have devised numerous certificateless conditional privacy-preserving authentic...

Rui-Min Wang, Can Liu, Han-Bing Zhang et al. · 0 citations
Open access Sep 2026

Hardware-assisted zero-knowledge authentication scheme for resource-constrained IoT terminals: USBKEY implementation and evaluation based on GSVOLE-2DLC

When resource-constrained Internet of Things (IoT) terminals connect to industrial control, sensing, and edge systems, it is necessary to balance low-overhead authentication, credential privacy protection, and cross-platform deployment. Traditional password and USBKEY authentication methods rely on static credentials a...

Jian-Xin Wang, Zi-Fan Xu, Run-Ze Zhou et al. · 0 citations
Open access Aug 2026

Behavioural biometric authentication and secure key agreement for smart networks using machine learning and lightweight elliptic curve cryptography

The fast integration of Internet of Things (IoT) into smart environments, introduces significant security challenges, especially in user authentication and secure data exchanges. These security challenges increase unauthorized access, information leakage, and disruption of services. Traditional user authentication mech...

Durvasi Gudivada, M. K. Rao · 0 citations
Open access Aug 2026

A Lightweight 2-factor Authentication Scheme for Smart Homes

Smart home technology provides the ability for homeowners to remotely monitor and control home appliances by connecting them to the internet. Despite its benefits, many people around the world are reluctant to adopt smart devices into their home for security reasons. Namely, connecting smart homes to the internet opens...

Ali T. Al-Hachami, M. F. Al-Gailani · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.