Wireless Medical Sensor Networks (WMSNs) facilitate the real-time collection and transmission of patients’ physiological data, enabling remote healthcare and intelligent medical services. However, the inherent openness of wireless communication renders sensitive data vulnerable to security threats such as interception, tampering, and replay attacks. To mitigate these issues, this paper introduces a novel certificateless aggregate signcryption scheme based on elliptic curve cryptography. The proposed scheme eliminates the complexities associated with certificate management, ensures data confidentiality and unforgeability, and incorporates an anonymity mechanism to safeguard client identities. Moreover, an efficient invalid signature detection algorithm is introduced, which utilizes an authentication key to swiftly identify malicious nodes in the event of aggregate verification failure, thereby minimizing redundant computations and improving system robustness. Under the random oracle model, formal security proofs demonstrate the scheme’s resilience against adaptive chosen-ciphertext and forgery attacks. Experimental results indicate that the proposed scheme not only achieves lower communication overhead but also maintains competitive computational efficiency compared to existing schemes, all while delivering stronger security assurances.



