Abstract
Industrial Internet of Things (IIoT) deployments increasingly rely on cloud–edge collaboration while operating with long-lived field devices, heterogeneous hardware, deterministic control requirements, and bandwidth-constrained links. These properties make “PQC everywhere” upgrades costly and operationally risky, yet the edge–device access boundary remains a critical trust bottleneck and an attractive target for impersonation, replay, and key-compromise threats. This paper proposes a selective-deployment approach for post-quantum authentication in industrial systems: rather than enforcing uniform migration, we identify security-critical boundaries and map protocol changes to lifecycle safe points to enable incremental, deployable protection. Building on this framework, we design SDAKA, a lifecycle-oriented post-quantum authentication and key agreement protocol spanning onboarding/registration, runtime access, maintenance (key evolution), and decommissioning/ revocation. SDAKA combines the standardized post-quantum signature primitive ML-DSA with an ML-KEM-inspired Module-LWE key-establishment component to establish session keys and authenticate lifecycle operations, while supporting operational needs such as pseudonymous access with accountable traceability. We validate the protocol via machine-checked symbolic analysis (ProVerif) and reduction-style security arguments in the Real-or-Random (RoR) model. A heterogeneous edge–device testbed evaluation further demonstrates that SDAKA’s computational latency and communication overhead remain practical for industrial links, and that different security configurations provide flexible trade-offs between protection strength and deployment cost.
| Original language | English |
|---|---|
| Journal | IEEE Internet of Things Journal |
| DOIs | |
| State | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- Edge computing
- industrial internet of things (IIoT)
- key agreement
- post-quantum cryptography (PQC)
- protocol verification
- selective deployment
Fingerprint
Dive into the research topics of 'Selective Deployment of Post-Quantum Edge–Device Authentication for IIoT: A Lifecycle-Oriented SDAKA Protocol'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver