HPQ-AKE: A Provably Secure Sign-Less Hybrid Authenticated Key Exchange Protocol for Bandwidth-Constrained IoT and Edge Networks

๐Ÿ“… 2026-10-08
๐Ÿ“ˆ Citations: 0
โœจ Influential: 0
๐Ÿ“„ PDF
๐Ÿค– AI Summary
This study addresses the handshake latency and certificate bloat caused by post-quantum cryptography (PQC) signatures during post-quantum migration in IoT networks. We propose a signature-free hybrid authenticated key exchange protocol that introduces a novel dual-KEM mechanism to replace conventional transcript signatures, integrating the forward secrecy of ML-KEM with the implicit authentication of RSA. Within an extended Bellareโ€“Rogaway model, this design achieves a separation between classical authentication and quantum-safe session keys. Security proofs in the random oracle model, alongside micro-benchmarks, demonstrate that compared to a hybrid TLS 1.3 baseline, our scheme reduces handshake transmission overhead by 56.4% and satellite link latency by 31.4%, significantly optimizing resource consumption in bandwidth-constrained scenarios.
๐Ÿ“ Abstract
Securing bandwidth-constrained Internet of Things (IoT) and edge networks during post-quantum migration creates an authentication trade-off: ML-KEM provides post-quantum key establishment, whereas post-quantum signatures increase certificate-chain size, verification cost, and handshake latency. We present HPQ-AKE, a sign-less hybrid authenticated key exchange for RSA-enabled IoT gateways and edge/cloud services that replaces transcript signatures with dual KEMs. HPQ-AKE combines ML-KEM-768 for post-quantum session secrecy and forward secrecy with RSA-OAEP for implicit mutual authentication, preserving existing RSA-enabled infrastructure during migration. We analyze HPQ-AKE in an extended Bellare-Rogaway model, separating classical authentication in the Random Oracle Model from session-key secrecy in the Quantum Random Oracle Model. Under the Module-LWE and RSA assumptions, it establishes AKE security, forward secrecy, and conditional KCI resistance under the long-term-key-only exposure assumptions. Evaluation combines x86 micro-benchmarking, analytical latency modeling, and 10,000-iteration Monte Carlo simulation. HPQ-AKE reduces modeled handshake transmission from 13,009 to 5,668 Bytes, a 56.4% reduction relative to a Hybrid TLS 1.3 Full handshake, while requiring 7.11 ms of total local computation on the measured x86 testbed. Under a simulated 50 kbps satellite-like link with 600 ms RTT and stochastic jitter, median latency is 1,914 ms, 31.4% below the 2,791 ms baseline. At 20 ms RTT, modeled break-even thresholds are 0.31 Mbps against the pre-cached baseline and 4.08 Mbps against the full baseline; both decrease as RTT increases. These x86-based results motivate evaluation on gateway-class IoT and edge platforms; performance on ARM gateways and unaccelerated microcontrollers remains unvalidated.
Problem

Research questions and friction points this paper is trying to address.

post-quantum migration
authenticated key exchange
bandwidth-constrained IoT
edge networks
handshake latency
Innovation

Methods, ideas, or system contributions that make the work stand out.

Sign-less Hybrid AKE
Dual KEM
Post-Quantum Migration
Extended Bellare-Rogaway Model
Bandwidth-Constrained IoT
๐Ÿ”Ž Similar Papers
No similar papers found.