A Post-Quantum Cryptographic Framework for Secure and Resilient IoT Communication
Keywords:
Post-quantum cryptography; Internet of Things security; module learning with errors; key encapsulation mechanism; lightweight cryptography; crypto-agility; hash-based signatures; quantum-resilient communication.Abstract
The impending emergence of cryptographically relevant quantum computers poses an existential threat to the elliptic-curve and RSA-based key-exchange protocols that currently secure the vast majority of Internet of Things (IoT) deployments. Constrained IoT devices are especially exposed to “harvest-now, decrypt-later” adversaries because their long deployment lifetimes routinely exceed the anticipated timeline for quantum cryptanalytic capability. This paper proposes PQ-IoTShield, a post-quantum cryptographic framework purpose-built for resource-constrained IoT communication. The framework combines a lightweight Module Learning-With-Errors (Module-LWE) key encapsulation mechanism with a compact hash-based digital signature scheme inside a crypto-agility controller that dynamically selects among NIST security categories L1, L3, and L5 according to a device's live compute, memory, energy, and bandwidth budget. An adaptive session resilience layer performs loss-aware retransmission and partial-key reconciliation to sustain secure session establishment over lossy low-power wide-area network (LPWAN) links. The framework was implemented on ESP32 and ARM Cortex-M4 (STM32L4) reference platforms and evaluated against RSA-2048, ECDH (secp256r1), NTRU-HPS, and standalone Kyber-512/Dilithium2 baselines using an NS-3-based lossy-link emulation testbed. PQ-IoTShield reduced mean handshake latency by 23.6% to 90.5% relative to the evaluated baselines, lowered per-handshake energy consumption to 4.6 mJ, and sustained a 79.7% successful session-establishment rate at 30% simulated packet loss compared with 33.1% for standalone Kyber-512. Ablation experiments confirm that the crypto-agility controller and the resilience layer each provide statistically significant, non-redundant contributions to overall performance. These results indicate that PQ-IoTShield is a practical, deployable pathway toward quantum-resilient IoT communication.
References
[1] Shor, P. W. (1999). Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM Review, 41(2), 303–332. https://doi.org/10.1137/s0036144598347011
[2] Grover, L. K. (1996). A fast quantum mechanical algorithm for database search. Proceedings of the Twenty-Eighth Annual ACM Symposium on Theory of Computing - STOC ’96, 212–219. https://doi.org/10.1145/237814.237866
[3] Nagy, N., Alnemer, S., Alshuhail, L. M., Alobiad, H., Almulla, T., Alrumaihi, F. A., Ghadra, N., & Nagy, M. (2025). Module-Lattice-Based Key-Encapsulation Mechanism Performance Measurements. Sci, 7(3), 91. https://doi.org/10.3390/sci7030091
[4] Truong, Q. D., Duong, P. N., & Lee, H. (2024). Efficient Low-Latency Hardware Architecture for Module-Lattice-Based Digital Signature Standard. IEEE Access, 12, 32395–32407. https://doi.org/10.1109/access.2024.3370470
[5] Uthayakumar, C., Jayaraman, R., Raja, H. A., & Shabbir, N. (2025). QSEER-Quantum-Enhanced Secure and Energy-Efficient Routing Protocol for Wireless Sensor Networks (WSNs). Sensors, 25(18), 5924. https://doi.org/10.3390/s25185924
[6] Liu, S., & Sakzad, A. (2025). Compact Lattice-Coded (Multi-recipient) Kyber Without CLT Independence Assumption. Advances in Cryptology – ASIACRYPT 2025, 363–395. https://doi.org/10.1007/978-981-95-5099-9_12
[7] Regev, O. (2005). On lattices, learning with errors, random linear codes, and cryptography. Proceedings of the Thirty-Seventh Annual ACM Symposium on Theory of Computing, 84–93. https://doi.org/10.1145/1060590.1060603
[8] Bos, J., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J. M., Schwabe, P., Seiler, G., & Stehle, D. (2018). CRYSTALS - Kyber: A CCA-Secure Module-Lattice-Based KEM. 2018 IEEE European Symposium on Security and Privacy (EuroS&P), 353–367. https://doi.org/10.1109/eurosp.2018.00032
[9] Truong, Q. D., Duong, P. N., & Lee, H. (2024). Efficient Low-Latency Hardware Architecture for Module-Lattice-Based Digital Signature Standard. IEEE Access, 12, 32395–32407. https://doi.org/10.1109/access.2024.3370470
[10] Maxrizal, M. (2022). Public Key Cryptosystem Based on Singular Matrix. Trends in Sciences, 19(3), 2147. https://doi.org/10.48048/tis.2022.2147
[11] Sun, S., Zhang, R., & Ma, H. (2020). Efficient Parallelism of Post-Quantum Signature Scheme SPHINCS. IEEE Transactions on Parallel and Distributed Systems, 31(11), 2542–2555. https://doi.org/10.1109/tpds.2020.2995562
[12] Abbasi, M., Cardoso, F., Váz, P., Silva, J., & Martins, P. (2025). A Practical Performance Benchmark of Post-Quantum Cryptography Across Heterogeneous Computing Environments. Cryptography, 9(2), 32. https://doi.org/10.3390/cryptography9020032
[13] Nagy, N., Alnemer, S., Alshuhail, L. M., Alobiad, H., Almulla, T., Alrumaihi, F. A., Ghadra, N., & Nagy, M. (2025). Module-Lattice-Based Key-Encapsulation Mechanism Performance Measurements. Sci, 7(3), 91. https://doi.org/10.3390/sci7030091
[14] Selvakumar, S., Ahilan, A., Ben Sujitha, B., & Muthukumaran, N. (2024). Crystals kyber cryptographic algorithm for efficient IoT D2d communication. Wireless Networks, 31(2), 1053–1070. https://doi.org/10.1007/s11276-024-03790-6
[15] Steinfeld, R., Esgin, M. F., Jagganath, N., Sakzad, A., Rudolph, C., & Boorman, J. (2026). PQCIP: A Post-Quantum Cryptography Educational Program for Cybersecurity Professionals. Proceedings of the 57th ACM Technical Symposium on Computer Science Education V.1, 1026–1032. https://doi.org/10.1145/3770762.3772573
[16] Hofheinz, D., Hövelmanns, K., & Kiltz, E. (2017). A Modular Analysis of the Fujisaki-Okamoto Transformation. Theory of Cryptography, 341–371. https://doi.org/10.1007/978-3-319-70500-2_12
[17] Hoffmann, L. (2016). Q&A: Finding New Directions in Cryptography. Communications of the ACM, 59(6), 112. https://doi.org/10.1145/2911977
[18] Rivest, R. L., Shamir, A., & Adleman, L. (1978). A Method for Obtaining Digital Signatures and Public-Key Cryptosystems (, Ed.). Defense Technical Information Center. https://doi.org/10.21236/ada606588
[19] Guide to Elliptic Curve Cryptography. (2004). In (Editor), Springer Professional Computing. Springer-Verlag. https://doi.org/10.1007/b97644
[20] Turan, M. S., McKay, K. A., Chang, D., Kang, J., & Kelsey, J. (2025). Ascon-based lightweight cryptography standards for constrained devices : (, Ed.). National Institute of Standards and Technology (U.S.). https://doi.org/10.6028/nist.sp.800-232