The Internet of Things (IoT) is expected to interconnect more than 75 billion devices worldwide, yet device authenticity remains one of the most pressing unsolved security challenges in the IoT space. Typical IoT nodes have limited computing power, memory, and battery capacity, making traditional public-key-based authentication difficult to implement without compromising either security or resource conservation. This paper presents a structured narrative review and quantitative comparison of lightweight authentication protocols for IoT environments published between 2024 and 2026, spanning seven families: Elliptic Curve Cryptography (ECC)-based, ECC for Radio Frequency Identification (RFID), hash-based, Physical Unclonable Function (PUF)-based, biometric and behavioural, blockchain-assisted, and machine-learning-augmented protocols. The review adds message-level protocol-flow comparisons for representative ECC- and PUF-based schemes, a benchmarking table of published latency, message-size, and energy indicators, and five sector-specific case studies. Reported findings include dynamic-credential ECC schemes reducing communication and computational overhead by more than 37% over prior ECC schemes; PUF-based techniques using machine learning to improve modelling-attack resistance by more than 35% over earlier techniques; blockchain-assisted authentication for fog-enabled IoT; and multi-sector schemes such as SELAP, reducing computation and communication cost to 422 ms and 960 bits respectively, against 548 ms and 2048 bits for the earlier ELWSCAS protocol. Protocols are also examined against ephemeral information leakage, modelling attacks on PUFs, node cloning, and physical tampering. No protocol category is universally optimal; selection depends on a deployment's constraints, threat model, and sector. Research is converging on hybrid designs combining hardware-rooted trust, efficient public-key primitives, decentralised trust, and intelligent anomaly detection.
Open access
2 source records
Physical Unclonable Functions (PUFs) and Hardware Security
Fruit and vegetable supply chains generate heterogeneous data across production, storage, logistics, and sales, creating challenges for trusted data sharing, privacy protection, and real-time traceability across distributed supply-chain information systems. Conventional single-chain blockchains suffer from limited scalability, data redundancy, and low retrieval efficiency, making them inadequate for high-frequency full-process information management. This study proposes a multi-chain blockchain framework for trusted full-process information management of fruit and vegetable supply chains. The framework integrates traceability, enterprise, notary, and regulatory chains to support hierarchical data management and privacy isolation. A reputation-based notary node election mechanism and a threshold-signature scheme based on Shamir secret sharing are designed to enhance cross-chain security and distributed regulatory consensus. To improve retrieval efficiency, a Cuckoo-Augmented Merkle Tree (CMerkle) and a skip-list-based block index are developed. Simulation results show that all malicious nodes were restricted by the 19th round, signature aggregation required 70.16 ms in a 500-node setting, and CMerkle achieved retrieval speedups of 14.7 and 153 times at data scales of 500 and 10,000 records, respectively. The framework supports trusted data governance, real-time traceability, privacy-preserving sharing, and regulatory decision support in blockchain-enabled supply-chain information systems.