Skip to main navigation Skip to search Skip to main content

Selective Deployment of Post-Quantum Edge–Device Authentication for IIoT: A Lifecycle-Oriented SDAKA Protocol

  • Harbin Institute of Technology
  • Peng Cheng Laboratory

Research output: Contribution to journalArticlepeer-review

Abstract

Industrial Internet of Things (IIoT) deployments increasingly rely on cloud–edge collaboration while operating with long-lived field devices, heterogeneous hardware, deterministic control requirements, and bandwidth-constrained links. These properties make “PQC everywhere” upgrades costly and operationally risky, yet the edge–device access boundary remains a critical trust bottleneck and an attractive target for impersonation, replay, and key-compromise threats. This paper proposes a selective-deployment approach for post-quantum authentication in industrial systems: rather than enforcing uniform migration, we identify security-critical boundaries and map protocol changes to lifecycle safe points to enable incremental, deployable protection. Building on this framework, we design SDAKA, a lifecycle-oriented post-quantum authentication and key agreement protocol spanning onboarding/registration, runtime access, maintenance (key evolution), and decommissioning/ revocation. SDAKA combines the standardized post-quantum signature primitive ML-DSA with an ML-KEM-inspired Module-LWE key-establishment component to establish session keys and authenticate lifecycle operations, while supporting operational needs such as pseudonymous access with accountable traceability. We validate the protocol via machine-checked symbolic analysis (ProVerif) and reduction-style security arguments in the Real-or-Random (RoR) model. A heterogeneous edge–device testbed evaluation further demonstrates that SDAKA’s computational latency and communication overhead remain practical for industrial links, and that different security configurations provide flexible trade-offs between protection strength and deployment cost.

Original languageEnglish
JournalIEEE Internet of Things Journal
DOIs
StateAccepted/In press - 2026
Externally publishedYes

Keywords

  • Edge computing
  • industrial internet of things (IIoT)
  • key agreement
  • post-quantum cryptography (PQC)
  • protocol verification
  • selective deployment

Fingerprint

Dive into the research topics of 'Selective Deployment of Post-Quantum Edge–Device Authentication for IIoT: A Lifecycle-Oriented SDAKA Protocol'. Together they form a unique fingerprint.

Cite this