计算机科学
计算机网络
协议(科学)
身份验证协议
认证(法律)
软件部署
计算机安全
报文认证码
密码协议
轻量级可扩展身份验证协议
密码学
鉴定(生物学)
服务器
钥匙(锁)
协议分析
移动计算
智能网
挑战握手验证协议
路由协议
电子邮件
数据认证算法
网络访问控制
Internet协议套件
移动电话技术
作者
Hao Tang,Hui He,Weizhe Zhang,Hongwei Yang,Qingyang Fan
标识
DOI:10.1109/jiot.2026.3696043
摘要
Industrial Internet of Things (IIoT) deployments increasingly rely on cloud–edge collaboration while operating with long-lived field devices, heterogeneous hardware, deterministic control requirements, and bandwidth-constrained links. These properties make “PQC everywhere” upgrades costly and operationally risky, yet the edge–device access boundary remains a critical trust bottleneck and an attractive target for impersonation, replay, and key-compromise threats. This paper proposes a selective-deployment approach for post-quantum authentication in industrial systems: rather than enforcing uniform migration, we identify security-critical boundaries and map protocol changes to lifecycle safe points to enable incremental, deployable protection. Building on this framework, we design SDAKA, a lifecycle-oriented post-quantum authentication and key agreement protocol spanning onboarding/registration, runtime access, maintenance (key evolution), and decommissioning/ revocation. SDAKA combines the standardized post-quantum signature primitive ML-DSA with an ML-KEM-inspired Module-LWE key-establishment component to establish session keys and authenticate lifecycle operations, while supporting operational needs such as pseudonymous access with accountable traceability. We validate the protocol via machine-checked symbolic analysis (ProVerif) and reduction-style security arguments in the Real-or-Random (RoR) model. A heterogeneous edge–device testbed evaluation further demonstrates that SDAKA’s computational latency and communication overhead remain practical for industrial links, and that different security configurations provide flexible trade-offs between protection strength and deployment cost.
科研通智能强力驱动
Strongly Powered by AbleSci AI