Lightweight Authentication and Encryption Protocols for Resource-constrained IoT Devices: A Review

Authors

  • Sonam Ashokrao Rewatkar

Keywords:

ASCON, Authentication protocols, IoT security, Lightweight Cryptography, Resource-constrained devices

Abstract

The rapid proliferation of Internet of Things (IoT) devices across healthcare, industrial automation, smart cities, and consumer applications has intensified the need for security mechanisms that operate within tight constraints on memory, computation, and energy. Conventional cryptographic primitives such as AES-256 and RSA, while secure, are frequently unsuitable for microcontrollers, RFID tags, and sensor nodes with kilobyte-scale memory and battery-limited operation. This has driven a distinct research area — lightweight cryptography — dedicated to authentication and encryption schemes tailored to resource-constrained hardware. This review synthesizes recent literature (2014–2025) on lightweight authentication and encryption protocols for IoT, organizing the field into five strands: lightweight block ciphers and authenticated encryption, including the NIST-standardized ASCON family; elliptic-curve-based mutual authentication; physically unclonable function-based schemes; RFID-specific ultra-lightweight protocols; and blockchain-assisted authentication architectures. Across these strands, the review compares reported computational overhead, memory footprint, energy consumption, and resilience against common IoT threats such as impersonation, desynchronization, and modeling attacks. The analysis shows that no single approach dominates across all constraint profiles: block ciphers suit bulk data confidentiality, PUFs suit tamper-evident device identity, and ECC suits scenarios requiring public-key functionality at higher, though still bounded, cost. The review concludes by highlighting persistent gaps, including post-quantum readiness and the recurring cryptanalysis-and-redesign cycle in ultra-lightweight RFID schemes, and proposes directions for future standardization and formal verification efforts.

References

Bogdanov et al., “PRESENT: An Ultra-Lightweight Block Cipher,” Cryptographic Hardware and Embedded Systems - CHES 2007, pp. 450–466, 2007.

R. Beaulieu, D. Shors, J. Smith, S. Treatman-Clark, B. Weeks, and L. Wingers, “S and S: Block Ciphers for the Internet of Things, National Security Agency, Jul. 2015.

C. Dobraunig, M. Eichlseder, F. Mendel, and M. Schläffer, “Ascon V1.2: Lightweight Authenticated Encryption and Hashing,” Journal of Cryptology, vol. 34, no. 3, Jun. 2021.

J. Kaur, A. C. Canto, M. M. Kermani, and R. Azarderakhsh, “A Comprehensive Survey on the Implementations, Attacks, and Countermeasures of the Current NIST Lightweight Cryptography Standard,” arXiv.org. Apr. 2023.

C. A. Lara-Nino, A. Diaz-Perez, and M. Morales-Sandoval, “Elliptic Curve Lightweight Cryptography: A Survey,” IEEE Access, vol. 6, pp. 72514–72550, Nov. 2018.

I. W. Damaj, A.-M. Hadi, and S. Mahmoud, “An Extended Analytical Framework for Heterogeneous Implementations of Light Cryptographic Algorithms,” Future Generation Computer Systems, vol. 141, pp. 154–172, Apr. 2023.

A. Sevin and A. A. O. Mohammed, “A Survey on Software Implementation of Lightweight Block Ciphers for IoT Devices,” Journal of Ambient Intelligence and Humanized Computing, vol. 14, no. 3, pp. 1801–1815, Jul. 2021.

M. El-hajj, H. Mousawi, and A. Fadlallah, “Analysis of Lightweight Cryptographic Algorithms on IoT Hardware Platform,” Future Internet, vol. 15, no. 2, pp. 54, Jan. 2023.

T. Liu, G. Ramachandran, and R. Jurdak, “Post-Quantum Cryptography for Internet of Things: A Survey on Performance and Optimization,” arXiv.org. Jan. 2024.

P. Mall, R. Amin, A. K. Das, M. T. Leung, and K.-K. R. Choo, “PUF-Based Authentication and Key Agreement Protocols for IoT, WSNs, and Smart Grids: A Comprehensive Survey,” IEEE Internet of Things Journal, vol. 9, no. 11, pp. 8205–8228, Jun. 2022.

C. Gupta and G. Varshney, “A Lightweight and Secure PUF-Based Authentication and Key-Exchange Protocol for IoT Devices,” arXiv.org, Nov. 2023.

Y. Zhuang and G. Li, “A Lightweight PUF-based Authentication Protocol,” arXiv.org, May 21, 2024.

L. Marin, M. Pawlowski, and A. Jara, “Optimized ECC Implementation for Secure Communication between Heterogeneous IoT Devices,” Sensors, vol. 15, no. 9, pp. 21478–21499, Aug. 2015.

M. Tanveer, A. U. Khan, H. Shah, S. A. Chaudhry, and A. Naushad, “PASKE-IoD: Privacy-Protecting Authenticated Key Establishment for Internet of Drones,” IEEE Access, vol. 9, pp. 145683–145698, Oct. 2021.

N. Zarbi, A. Zaeembashi, N. Bagheri, and M. Adeli, “Toward Designing a Lightweight RFID Authentication Protocol for Constrained Environments,” IET Communications, vol. 18, no. 14, pp. 846–859, Jun. 2024.

K. Fan, L. Qi, Z. Kuan, and Y. Yang, “Cloud-Based Lightweight Secure RFID Mutual Authentication Protocol in IoT,” Information Sciences, vol. 527, pp. 329–340, Jul. 2020.

Q. Xie and Z. Ding, “Provably Secure and Lightweight Blockchain Based Cross Hospital Authentication Scheme for IoMT-based Healthcare,” Scientific Reports, vol. 15, no. 1, Feb. 2025,

L. Khajehzadeh, H. Barati, and A. Barati, “L2AI: Lightweight Three-Factor Authentication and Authorization in IOMT Blockchain-Based Environment,” arXiv.org. Jul. 2024.

B. Rezvani, F. Coleman, and W. Diehl, “Hardware Implementations of NIST Lightweight Cryptographic Candidates: A First Look,” Cryptology ePrint Archive, pp. 1-20, Nov. 2019.

I. Elsadek, S. Aftabjahani, D. Gardner, E. MacLean, J. R. Wallrabenstein, and E. Y. Tawfik, “Hardware and Energy Efficiency Evaluation of NIST Lightweight Cryptography Standardization Finalists,” 2022 IEEE International Symposium on Circuits and Systems (ISCAS), pp. 133–137, May 2022.

Published

2026-09-14

Issue

Section

Articles