Merkle Tree-Enhanced ECDH Mutual Authentication for Secure and Lightweight IoT Communication


Kaygisiz S. Y., DALKILIÇ G.

9th International Symposium on Innovative Approaches in Smart Technologies, ISAS 2025, Gaziantep, Türkiye, 27 - 28 Haziran 2025, (Tam Metin Bildiri) identifier

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Doi Numarası: 10.1109/isas66241.2025.11101863
  • Basıldığı Şehir: Gaziantep
  • Basıldığı Ülke: Türkiye
  • Anahtar Kelimeler: elliptic curve cryptography, Internet of things, Merkle tree, mutual authentication
  • Manisa Celal Bayar Üniversitesi Adresli: Evet

Özet

Resource-constrained Internet of Things (IoT) devices require secure yet lightweight authentication mechanisms, particularly in peer-to-peer scenarios. This paper proposes a novel mutual authentication protocol. The protocol integrates an asymmetric key-agreement protocol, Elliptic Curve Diffie-Hellman (ECDH), for efficient key exchange, initial HMAC verifications with a distributed trust model based on local device ledgers managed via Bloom filters and Merkle Trees, eliminating reliance on a server or a gateway during authentication. It also employs dynamic channel switching, BLE to Wi-Fi or ESP-NOW, to balance energy efficiency and performance during verification phases, further increasing authenticity and security. The protocol's BAN logic representation is provided for the security validation and analysis. The scheme provides mutual authentication and secure session key establishment with forward secrecy. It incorporates nonces to resist replay, man-in-the-middle, and impersonation attacks, offering a scalable and robust security solution for constrained IoT networks.