Lightweight Zero-Knowledge Proof-Based Cryptographic Protocols for Secure and Privacy-Preserving Wearable IoT
Keywords:
Zero-Knowledge Proof; Wearable IoT; Privacy-Preserving Authentication; Elliptic Curve Cryptography; Sigma Protocol; Fiat–Shamir Heuristic; Lightweight Cryptography; IoT SecurityAbstract
Wearable Internet of Things (IoT) devices continuously capture physiological, behavioural, and locational data that are highly sensitive, yet the microcontrollers embedded in these devices possess only kilobytes of RAM, sub-100 MHz clock speeds, and milliampere-hour battery budgets. Conventional authentication and credential-verification mechanisms based on RSA, bilinear pairing, or heavyweight public-key infrastructure impose computation, bandwidth, and energy costs that are incompatible with such constraints, while simultaneously exposing raw or derived biometric data during verification. This paper proposes a lightweight, elliptic-curve-based Zero-Knowledge Proof (ZKP) framework that enables wearable devices to authenticate themselves and attest to properties of their sensed data without revealing the underlying secret or raw biosignal. The framework instantiates a Sigma-protocol-based commit-challenge-response exchange, hardened into a non-interactive zero-knowledge (NIZK) mode via the Fiat–Shamir heuristic for asynchronous wearable-to-gateway communication, and layers batched verification, session-key derivation, and revocation handling on top of a five-layer architecture spanning the sensing, prover, edge-gateway, verification, and application tiers. A formal security analysis establishes completeness, soundness, and honest-verifier zero-knowledge, and shows resistance to replay, man-in-the-middle, impersonation, and linkability attacks under the elliptic-curve discrete logarithm assumption. Simulation on a Cortex-M4-class microcontroller (secp256r1, 128-bit security) shows that the proposed protocol reduces prover-side computation by up to 91% relative to RSA-based ZKP baselines and by 58% relative to standard ECC-Schnorr identification, cuts communication overhead to 80 bytes per authentication, and reduces cumulative energy consumption by approximately 86% over 300 authentication rounds on a coin-cell-class power budget. These results indicate that carefully engineered ZKP protocols are practically deployable on constrained wearable hardware and offer a viable path toward privacy-preserving, mathematically verifiable trust in remote health monitoring, fitness analytics, and consumer wearable ecosystems.
Downloads
References
Goldwasser, S., Micali, S., & Rackoff, C. (1989). The knowledge complexity of interactive proof systems. SIAM Journal on Computing, 18(1), 186–208.
Schnorr, C. P. (1991). Efficient signature generation by smart cards. Journal of Cryptology, 4(3), 161–174.
Fiat, A., & Shamir, A. (1986). How to prove yourself: Practical solutions to identification and signature problems. In Proceedings of CRYPTO 1986 (pp. 186–194). Springer.
Chatzigiannakis, I., Andreou, A., Fischer, S., & Some, R. (2011). Elliptic curve based zero knowledge proofs and their applicability on resource constrained devices. In Proceedings of the IEEE 8th International Conference on Mobile Ad-Hoc and Sensor Systems (MASS) (pp. 715–720). IEEE. Available: https://arxiv.org/abs/1107.1626
Epiphaniou, G., et al. (2019). Non-interactive zero knowledge proofs for the authentication of IoT devices in reduced connectivity environments. Ad Hoc Networks. Available: http://eprints.bournemouth.ac.uk/33655/1/adhoc2019_epiphaniou_et_al.pdf
Wang, Z., et al. (2023). Lightweight zero-knowledge authentication scheme for IoT embedded devices (LZIA). Computers & Electrical Engineering / ScienceDirect. Available: https://www.sciencedirect.com/science/article/abs/pii/S1389128623004668
Author(s) (2025). Leveraging blockchain with zero knowledge proofs in wearable health technologies for personalized healthcare. Scientific Reports. Available: https://www.nature.com/articles/s41598-025-25146-6
Author(s) (2025). A lightweight QR-assisted zero-knowledge identification protocol for secure authentication. arXiv:2605.16912. Available: https://arxiv.org/pdf/2605.16912
Author(s) (2025). PRZK-Bind: A physically rooted zero-knowledge binding protocol for IoT device authentication. arXiv:2508.17913. Available: https://arxiv.org/pdf/2508.17913
Author(s) (2025). A lightweight zero-trust authentication architecture for IoT via unified enhanced FAST-SM9 and dynamic re-authentication. PMC. Available: https://www.ncbi.nlm.nih.gov/pmc/articles/PMC12558534/
Bünz, B., Bootle, J., Boneh, D., Poelstra, A., Wuille, P., & Maxwell, G. (2018). Bulletproofs: Short proofs for confidential transactions and more. In Proceedings of the IEEE Symposium on Security and Privacy (S&P) (pp. 315–334). IEEE.
Camenisch, J., & Lysyanskaya, A. (2004). Signature schemes and anonymous credentials from bilinear maps. In Proceedings of CRYPTO 2004 (pp. 56–72). Springer.
Author(s) (2026). Zero-knowledge proof (ZKP) authentication for offline CBDC payment systems using IoT devices. arXiv:2603.03804. Available: https://arxiv.org/pdf/2603.03804
Koblitz, N., Menezes, A. J., Wu, Y.-H., & Zuccherato, R. J. Algebraic aspects of cryptography. Springer-Verlag.
Menezes, A. J., van Oorschot, P. C., & Vanstone, S. A. (1996). Handbook of Applied Cryptography. CRC Press.
Bormann, C., Ersue, M., & Keranen, A. (2014). Terminology for constrained-node networks. IETF RFC 7228.
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All papers should be submitted electronically. All submitted manuscripts must be original work that is not under submission at another journal or under consideration for publication in another form, such as a monograph or chapter of a book. Authors of submitted papers are obligated not to submit their paper for publication elsewhere until an editorial decision is rendered on their submission. Further, authors of accepted papers are prohibited from publishing the results in other publications that appear before the paper is published in the Journal unless they receive approval for doing so from the Editor-In-Chief.
IJISAE open access articles are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. This license lets the audience to give appropriate credit, provide a link to the license, and indicate if changes were made and if they remix, transform, or build upon the material, they must distribute contributions under the same license as the original.


