Elliptic Curve Cryptography for Lightweight IoT and Industrial IoT Security: A Focused Comparative Review of Three Design, Evaluation, and Architectural Approaches

Authors

  • Krishiyana Bhakta Polytech Nantes, Nantes Université Nantes, France
  • Sulakshyana Ghimire Nantes Université, Nantes, France
  • Sabil Shrestha Polytech Nantes, Nantes Université Nantes, France

DOI:

https://doi.org/10.65091/icicset.v3i1.109

Abstract

Elliptic curve cryptography (ECC) is a public-key
crypto primitive that is widely used because it achieves security
levels that are roughly equivalent to those of the conventional
public-key schemes with smaller key sizes; thus, a 256-bit ECC key
can provide security levels comparable to those of a 3072-bit RSA
modulus. This paper presents a selective review rather than a
comprehensive survey. Three recent peer-reviewed studies have
been chosen following a well-defined procedure, given that they
come at different points in the process of proposing, breaking and
systematizing lightweight security schemes: propose–break–
systematize. The first provides a protocol that integrates ECC with
a physically unclonable function (PUF) and applies a password
retrieval mechanism based on the Chinese Remainder Theorem,
with security analysis carried out with BAN logic and ProVerif.
The second one tests a formally proven anonymous ECC
authentication and key-agreement system and shows an
impersonation attack on the end-device of a system in which
ephemeral randomness can be leaked under an adversarial model,
which is then confirmed by AVISPA. The third proposes a
federated learning framework for the industrial IoT with the
adoption of certificateless ECC, similarity-based update
screening, and blockchain-based checkpoints. The three methods
operate on different architectures, threat models, platforms and
workloads, so the results of the measured performance are not
directly comparable. The review shows that the security claims are
critically dependent on what adversary model is assumed; that
none of the three reviewed studies reports any failure of the
underlying elliptic-curve arithmetic; and that the reviewed
literature does not provide the same reference configuration to
evaluate efficiency claims. A minimum reporting standard is
proposed to fill this void.

Downloads

Published

2026-10-02

How to Cite

[1]
K. Bhakta, S. Ghimire, and S. Shrestha, “Elliptic Curve Cryptography for Lightweight IoT and Industrial IoT Security: A Focused Comparative Review of Three Design, Evaluation, and Architectural Approaches”, ICICSET2025, vol. 3, no. 1, Oct. 2026.