Skip to content
Open access

Lightweight Anonymous Group Authentication and Quantum-Cloud Key Distribution Based on PUF for Classical Network Environments

Jul 2026 · Italian National Conference on Sensors · Vol 26 · 0 citations · 71 references
Medicine

TL;DR

Performance evaluations demonstrate that the proposed lightweight anonymous group authentication scheme outperforms existing comparable schemes in terms of computational cost, communication overhead, and dynamic group management efficiency, demonstrating its potential for resource-constrained IoT environments, pending further validation on real hardware platforms.

Abstract

With the rapid development of quantum computing, in response to its disruptive threats to traditional cryptosystems and the urgent demand for lightweight and highly scalable secure group communication among resource-constrained devices in large-scale Internet of Things (IoT) scenarios, this paper proposes a lightweight anonymous group authentication scheme that integrates Physical Unclonable Functions (PUFs), distributed Gossip algorithms, and quantum key distribution. By exploiting the uniqueness and unclonability derived from the inherent physical characteristics of PUF hardware, the scheme fundamentally eliminates attack vectors against quantum computers without requiring devices to pre-store any secret keys in their memory, while the QKCS pre-provisions CRPs and key seeds, which is the standard enrollment procedure in PUF-based systems. Combined with information-theoretically secure quantum keys as session keys, it forms a dual protection mechanism: anti-forgery at the physical layer and anti-quantum attack at the cryptographic layer. Innovatively, the Gossip algorithm is deeply integrated with group key agreement, converting global broadcast into local iterative interactions between nodes, which effectively alleviates broadcast storms and improves the scalability and fault tolerance of the protocol. Meanwhile, a pseudonym mechanism is introduced to achieve anonymous identity protection, and a dynamic key update strategy guarantees forward and backward security when members join or leave the group. Formal verification based on BAN logic and security analysis show that the proposed protocol can resist typical attacks such as replay attacks, man-in-the-middle attacks, and impersonation attacks. Performance evaluations demonstrate that our scheme outperforms existing comparable schemes in terms of computational cost, communication overhead, and dynamic group management efficiency, demonstrating its potential for resource-constrained IoT environments, pending further validation on real hardware platforms.

Read PDF

Similar papers

Open access Jul 2026

Problems and prospects of building authentication methods in quantum key distribution channels

The paper addresses entity authentication in quantum key distribution (QKD) systems as a decisive condition of their practical security. It is shown that the information-theoretic security of quantum key agreement does not eliminate the need to authenticate the communicating parties: an unauthenticated classical channel leaves the system exposed to the man-in-the-middle attack, since the eavesdropper can run independent QKD instances with each party and reconcile two keys under full control. Existing authentication methods are analysed and classified by the underlying cryptographic primitive: symmetric schemes based on Wegman–Carter universal hashing, pre-shared and fixed keys, public-key infrastructure, two-way authentication, quantum entity/identity authentication, and zero-knowledge proofs. For each class the operating principle, advantages and limitations are determined, with emphasis on key management, scalability and trust distribution. It is established that symmetric and quantum-layer methods rely on pre-shared secrets with a quadratic growth of key material, public-key infrastructure introduces a single trust bottleneck and quantum-vulnerable primitives, while existing zero-knowledge authentication schemes are quantum and bound to the physical layer or solve network properties other than identity. A comparative analysis reveals an unresolved scientific gap: the absence of a scalable entity-authentication method that simultaneously provides non-disclosure of the secret, quantum resistance, sub-quadratic scalability and minimisation of trust assumptions. On this basis, a prospective research direction is substantiated – the construction of entity-authentication methods based on post-quantum zero-knowledge proofs operating over the classical control plane of scalable QKD networks. The requirements for such a method are formulated, and its compatibility with formal QKD security proofs is discussed.

Y. Kotukh, M. V. Korobchynskyi, V. Kozlovskyi et al. · 0 citations
Open access Aug 2026

Lightweight Post Quantum Homomorphic Encryption for Secure Network Traffic Intrusion detection

These quantum computing technologies are a serious risk for existing “Cryptographic Algorithms, corresponding “RSA, ECC, and Diffie-Hellman”. The Quantum Algorithm “Shor's can break classical” public-key encryption systems effectively and now there is a momentous security concern of cloud computing, IoT systems, and healthcare networks, as well as the future 6G communication systems. In response to the above difficulties, researchers have suggested two new methods of privacy-preserving encrypted computation, namely: “Post-Quantum Cryptography (PQC) and Fully Homomorphic Encryption (FHE)". But the current “Post-Quantum Homomorphic Encryption (PQHE)” solutions have high computational complexity, expanded ciphertext size, latency, and are not widely deployed in cybersecurity applications. This research aims to provide a lightweight Post-Quantum Homomorphic Encryption framework for secure network traffic analysis with the intrusion detection dataset from CICIDs 2018. The proposed framework combines the lattice-based PQHE concepts, “Principal Component Analysis (PCA) and K-Means cluster to envision encrypted traffic and secure intrusion analysis. Data preprocessing, feature standardization, dimensionality reduction, encrypted traffic representation, clustering analysis and graphical visualization are parts of the experimental methodology. To address the key challenges, by using two major approaches for privacy-preserving encrypted computation have been proposed: “Post-Quantum Cryptography (PQC) and Fully Homomorphic Encryption (FHE)”. The current Post-Quantum Homomorphic Encryption (PQHE) systems, on the contrary, are complicated, costly in the length of the ciphertext, slow and not widely used in terms of cybersecurity. To protect network traffic analysis a lightweight Post-Quantum Homomorphic Encryption framework is proposed in this research to achieve network security using intrusion detection data set CICIDS2018.

Mariam Nayab, Muhammad Sajid Qureshi, Abdul Jabbar · 0 citations
Jul 2026

A Novel Post-Quantum Cryptography-Based Authentication and Secret Key Establishment Protocol for Smart Grid

The increasing integration of smart grids within the Internet of Things (IoT) ecosystem requires the implementation of robust security measures due to vulnerabilities brought about by pervasive connectivity. Previous smart grid security protocols are based on classical cryptographic algorithms, which are susceptible to significant threats from emerging quantum computers. Consequently, the adoption of quantum-resistant solutions is imperative for the long-term security of smart grids. This paper presents a novel protocol for authentication and secret key establishment in smart grids, utilizing post-quantum cryptography (PQC) algorithms. Our proposed protocol employs the FALCON digital signature algorithm for integrity verification and the CRYSTALS-Kyber key encapsulation mechanism (KEM) for secret key establishment, providing robust protection against quantum attacks. Our optimized implementation of the proposed protocol on a graphics processing unit (GPU) targets grid security module (GSM)/gateway-side deployments and demonstrates scalability under large numbers of concurrent authentication requests. Experimental validation demonstrates the proposed protocol's ability to effectively manage numerous concurrent authentication requests, ensuring secure and efficient communication within smart grid networks.

Muhammad Asfand Hafeez, Arslan Munir · 0 citations
Conference Open access 2026

Security Enhancements of the Quantum-Resistant Identity Authentication and Key Agreement Scheme for UAV Networks Based on Kyber Algorithm

: Secure UAV communication requires robust, quantum-resistant protocols that are resilient to physical capture and operate under severe resource constraints. This work identifies critical vulnerabilities—including desynchronization, capture attacks, and lack of forward secrecy—in the LIGKYX protocol(Xia et al., 2024). To address these flaws, we propose a novel protocol that replaces LIGKYX’s ECC with Physical Unclonable Functions (PUFs) for device authentication and integrates the post-quantum Kyber mechanism for key establishment. Enhanced with authenticated encryption and nonce-based key derivation, our protocol is formally verified (using BAN logic) to resist replay, impersonation, desynchronization, and capture attacks. Performance analysis confirms its lower computational and communication overhead, making it suitable for constrained UAV networks.

Mohammed Zitouni, Hicham Hameurlaine, Mustapha Bensalah · 0 citations
Open access Aug 2026

Secure PUF-ASCON-Based Gateway-Assisted D2D Authentication for Resource-Constrained Smart-Manufacturing IIoT Devices

Smart-manufacturing Industrial Internet of Things (IIoT) deployments increasingly depend on low-latency device-to-device (D2D) communication among resource-constrained, physically exposed field devices. This setting makes mutual authentication and session-key establishment difficult: public-key-intensive or cloud-dependent schemes add overhead, availability dependence, and single points of failure, while weak PUF-based designs may expose challenge-response pairs (CRPs) to replay, disclosure, and modeling attacks. This paper proposes PASMAP, a lightweight PUF-ASCON mutual authentication protocol for gateway-assisted D2D communication in smart-manufacturing IIoT. PASMAP combines SRAM-PUF key reconstruction, fuzzy-extractor helper data, hash- and XOR-based obfuscation, and ASCON authenticated encryption with associated data (AEAD) to protect hardware-rooted identities, hide raw PUF responses, and establish fresh session keys for post-authentication data exchange under an explicitly trusted local-gateway model. The protocol is evaluated against physical, protocol-level, and insider threats, including cloning, tampering, replay, man-in-the-middle, CRP disclosure, PUF modeling, stolen-verifier, and known-key attacks. A real-or-random (ROR) analysis bounds the adversary’s session-key advantage using hash collisions, PUF-response prediction, online guessing, and ASCON AEAD security. A mixed-platform evaluation based on ESP32 primitive timings for the edge devices and desktop timings for the resource-rich gateway yields an estimated total computation cost of 4.762 ms. The initiator and responder require 2.006 ms/264.79 μJ and 2.679 ms/353.63 μJ of computational energy, respectively, while the five-message exchange carries 4704 bits. These results indicate low computational overhead under the stated benchmark and power-model assumptions. However, the protocol totals are operation-count-based estimates, the PUF and fuzzy-extractor operations are simulated, and the energy model excludes several platform- and communication-dependent costs. A complete embedded implementation is therefore required to validate end-to-end latency, memory use, energy consumption, communication-stack overhead, SRAM-PUF reliability, and fuzzy-extractor performance.

Alanoud Subahi · 0 citations
Review Open access 2023

The Role of Quantum-Safe Cryptography in Next-Generation Security

Quantum computing offers major computational advances but threatens modern public-key cryptography. Classical algorithms such as RSA, Diffie–Hellman (DH), and Elliptic Curve Cryptography (ECC) are vulnerable to quantum attacks, particularly Shor’s algorithm. As large-scale quantum capabilities emerge, post-quantum cryptography (PQC) has become essential to ensure future data confidentiality, integrity, and authentication. This paper discusses the need to replace classical cryptography, explores quantum-safe solutions, and examines challenges in large-scale migration. PQC is critical across government, critical infrastructure, finance, healthcare, telecommunications, IoT, autonomous vehicles, and 6G networks. A key concern is “harvest-now, decrypt-later” attacks, where encrypted data is stored today for future quantum decryption. The study analyzes classical cryptographic vulnerabilities and reviews major PQC families: lattice-based, hash-based, code-based, multivariate-based, and isogeny-based schemes, highlighting the ongoing NIST standardization efforts. It proposes a migration framework including quantum-readiness assessment, algorithm selection, hybrid implementation, and performance evaluation. Results show that although PQC introduces higher computational complexity, optimized implementations can support real-time applications with reasonable overhead. Among PQC approaches, lattice-based schemes appear most mature and balanced in terms of security and key size. The paper concludes that quantum-safe cryptography is a necessary evolution requiring continuous monitoring, adaptable systems, and alignment with emerging standards.

Noah Wright, Isabella Moore · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.