{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,15]],"date-time":"2026-05-15T16:24:15Z","timestamp":1778862255501,"version":"3.51.4"},"reference-count":32,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2016,12,14]],"date-time":"2016-12-14T00:00:00Z","timestamp":1481673600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Secure communication is a significant issue in wireless sensor networks. User authentication and key agreement are essential for providing a secure system, especially in user-oriented mobile services. It is also necessary to protect the identity of each individual in wireless environments to avoid personal privacy concerns. Many authentication and key agreement schemes utilize a smart card in addition to a password to support security functionalities. However, these schemes often fail to provide security along with privacy. In 2015, Chang et al. analyzed the security vulnerabilities of previous schemes and presented the two-factor authentication scheme that provided user privacy by using dynamic identities. However, when we cryptanalyzed Chang et al.\u2019s scheme, we found that it does not provide sufficient security for wireless sensor networks and fails to provide accurate password updates. This paper proposes a security-enhanced authentication and key agreement scheme to overcome these security weaknesses using biometric information and an elliptic curve cryptosystem. We analyze the security of the proposed scheme against various attacks and check its viability in the mobile environment.<\/jats:p>","DOI":"10.3390\/s16122123","type":"journal-article","created":{"date-parts":[[2016,12,14]],"date-time":"2016-12-14T10:14:47Z","timestamp":1481710487000},"page":"2123","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":86,"title":["Three-Factor User Authentication and Key Agreement Using Elliptic Curve Cryptosystem in Wireless Sensor Networks"],"prefix":"10.3390","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-9011-8410","authenticated-orcid":false,"given":"YoHan","family":"Park","sequence":"first","affiliation":[{"name":"School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"YoungHo","family":"Park","sequence":"additional","affiliation":[{"name":"School of Electronics Engineering, Kyungpook National University, Daegu 41566, Korea"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2016,12,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"102","DOI":"10.1109\/MCOM.2002.1024422","article-title":"A survey on sensor networks","volume":"40","author":"Akyildiz","year":"2002","journal-title":"IEEE Commun. Mag."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"2292","DOI":"10.1016\/j.comnet.2008.04.002","article-title":"Wireless sensor network survey","volume":"52","author":"Yick","year":"2008","journal-title":"Comput. Netw."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1645","DOI":"10.1016\/j.future.2013.01.010","article-title":"Internet of Things (IoT): A vision, architectural elements, and future directions","volume":"29","author":"Gubbi","year":"2013","journal-title":"Futur. Gene Comput. Syst."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Pathan, A.S.K., Lee, H.W., and Hong, C.S. (2006, January 20\u201322). Security in wireless sensor networks: Issues and challenges. Proceedings of the 8th International Conference Advanced Communication Technology (ICACT), Phoenix Park, Korea.","DOI":"10.1109\/ICACT.2006.206151"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1145\/990680.990707","article-title":"Security in wireless sensor networks","volume":"47","author":"Perrig","year":"2004","journal-title":"ACM Commun."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"93","DOI":"10.1007\/s10916-010-9449-4","article-title":"Security and privacy issues in wireless sensor networks for healthcare applications","volume":"36","author":"Liu","year":"2012","journal-title":"J. Med. Syst."},{"key":"ref_7","unstructured":"Wong, K.H., Zheng, Y., Cao, J., and Wang, S. (2006, January 5\u20137). A dynamic user authentication scheme for wireless sensor networks. Proceedings of the IEEE International Conference on Sensor Networks, Ubiquitous, and Trustworthy Computing, Taichung, Taiwan."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"1086","DOI":"10.1109\/TWC.2008.080128","article-title":"Two-factor user authentication scheme in wireless sensor networks","volume":"8","author":"Das","year":"2009","journal-title":"IEEE Trans. Wirel. Commun."},{"key":"ref_9","first-page":"361","article-title":"An enhanced two-factor user authentication scheme in wireless sensor networks","volume":"10","author":"He","year":"2010","journal-title":"Ad Hoc Sens. Wirel. Netw."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"2450","DOI":"10.3390\/s100302450","article-title":"Cryptanalysis and security improvements of two-factor user authentication in wireless sensor networks","volume":"10","author":"Khan","year":"2010","journal-title":"Sensors"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"704","DOI":"10.4218\/etrij.10.1510.0134","article-title":"A robust mutual authentication protocol for wireless sensor networks","volume":"32","author":"Chen","year":"2010","journal-title":"ETRI J."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1002\/sec.517","article-title":"Two-factor mutual authentication with key agreement in wireless sensor networks","volume":"9","author":"Vaidya","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"6443","DOI":"10.3390\/s140406443","article-title":"Security analysis and improvements of two-factor mutual authentication with key agreement in wireless sensor networks","volume":"14","author":"Kim","year":"2014","journal-title":"Sensors"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"29841","DOI":"10.3390\/s151229767","article-title":"Enhanced two-factor authentication and key agreement using dynamic identities in wireless sensor networks","volume":"15","author":"Chang","year":"2015","journal-title":"Sensors"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Yoon, E.J., and Yoo, K.Y. (2014, January 24\u201328). A biometric-based authenticated key agreement scheme using ECC for wireless sensor networks. Proceedings of the 29th Annual ACM Symposium on Applied Computing, Gyeongju, Korea.","DOI":"10.1145\/2554850.2555045"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"1377","DOI":"10.1007\/s11277-015-2288-3","article-title":"A secure and efficient user anonymity-preserving three-factor authentication protocol for large-scale distributed wireless sensor networks","volume":"82","author":"Das","year":"2015","journal-title":"Wirel. Pers. Commun."},{"key":"ref_17","first-page":"1","article-title":"A secure and effective biometric-based user authentication scheme for wireless sensor networks using smart card and fuzzy extractor","volume":"2015","author":"Das","year":"2015","journal-title":"Int. J. Commun. Syst."},{"key":"ref_18","first-page":"1","article-title":"Security improvement on biometric based authentication scheme for wireless sensor networks using fuzzy extraction","volume":"8572410","author":"Choi","year":"2016","journal-title":"Int. J. Dist. Sens. Netw."},{"key":"ref_19","first-page":"1","article-title":"Secure biometric-based authentication scheme with smart card revocation\/reissue for wireless sensor networks","volume":"12","author":"Park","year":"2016","journal-title":"Int. J. Dist. Sens. Netw."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.jnca.2009.08.001","article-title":"An efficient biometric-based remote authentication scheme using smart cards","volume":"33","author":"Li","year":"2010","journal-title":"J. Netw. Comp. Appl."},{"key":"ref_21","first-page":"233","article-title":"A logic of authentication","volume":"426","author":"Burrows","year":"1989","journal-title":"Proc. R. Soc. Lond. A Math. Phys. Eng. Sci."},{"key":"ref_22","first-page":"202","article-title":"A Simple User Authentication Scheme for Grid Computing","volume":"7","author":"Lu","year":"2008","journal-title":"IJ Netw. Sec."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Dodis, Y., Reyzin, L., and Smith, A. (2004, January 2\u20136). Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. Proceedings of the International Conference on the Theory and Applications of Cryptographic Techniques, Interlaken, Switzerland.","DOI":"10.1007\/978-3-540-24676-3_31"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10916-014-0016-2","article-title":"A user anonymity preserving three-factor authentication scheme for telecare medicine information systems","volume":"38","author":"Tan","year":"2014","journal-title":"J. Med. Syst."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Jung, J., Kim, J., Choi, Y., and Won, D. (2016). An Anonymous User Authentication and Key Agreement Scheme Based on a Symmetric Cryptosystem in Wireless Sensor Networks. Sensors, 16.","DOI":"10.3390\/s16081299"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"4767","DOI":"10.3390\/s110504767","article-title":"A secured authentication protocol for wireless sensor networks using elliptic curves cryptography","volume":"11","author":"Yeh","year":"2011","journal-title":"Sensors"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., and Jun, B. (1999, January 15\u201319). Differential power analysis. Proceedings of the Advances in Cryptology-CRYPTO\u201999, Santa Barbara, CA, USA.","DOI":"10.1007\/3-540-48405-1_25"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.adhoc.2015.05.020","article-title":"A secure light weight scheme for user authentication and key agreement in multi-gateway based wireless sensor networks","volume":"36","author":"Amin","year":"2016","journal-title":"Ad Hoc Netw."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1016\/j.ins.2015.02.010","article-title":"A secure temporal-credential-based mutual authentication and key agreement scheme with pseudo identity for wireless sensor networks","volume":"321","author":"He","year":"2015","journal-title":"Inf. Sci."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Jiang, Q., Kumar, N., Ma, J., Shen, J., He, D., and Chilamkurti, N. (2016). A privacy-aware two-factor authentication protocol based on elliptic curve cryptography for wireless sensor networks. Int. J. Netw. Manag.","DOI":"10.1002\/nem.1937"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Lu, Y., Li, L., Yang, X., and Yang, Y. (2015). Robust biometrics based authentication and key agreement scheme for multi-server environments using smart cards. PLoS ONE, 10.","DOI":"10.1371\/journal.pone.0126323"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s13638-015-0406-2","article-title":"Efficient authenticated key exchange protocols for wireless body area networks","volume":"2015","author":"Liu","year":"2015","journal-title":"EURASIP J. Wirel. Commun. Netw."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/16\/12\/2123\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T19:28:30Z","timestamp":1760210910000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/16\/12\/2123"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016,12,14]]},"references-count":32,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2016,12]]}},"alternative-id":["s16122123"],"URL":"https:\/\/doi.org\/10.3390\/s16122123","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016,12,14]]}}}