PQ-Secureedge: A Lightweight Lattice-Inspired Post-Quantum Key Encapsulation And Trust-Adaptive Refresh Framework For Zero-Trust Edge-Iot Confidentiality
Keywords:
PQ-SecureEdge, post-quantum cryptography, lattice-based key encapsulation, zero-trust architecture, edge computing security, trust-adaptive key managementAbstract
The rapid advancement of quantum computing poses a long-term threat to the classical cryptographic primitives, such as elliptic-curve and RSA-based key exchange, that currently secure edge-based Internet of Things (IoT) communication. Adversaries capable of harvesting encrypted traffic today may decrypt it once large-scale quantum computers become available, a risk that is especially acute for long-lived edge deployments. This paper presents PQ-SecureEdge, a lightweight post-quantum extension of a previously established zero-trust adaptive cryptographic model for resource-constrained edge computing networks. PQ-SecureEdge introduces two complementary mechanisms: a Lightweight Modular Key Encapsulation (LMKE) scheme built on simplified learning-with-errors modular arithmetic suited to microcontroller-class IoT hardware, and a Trust-Adaptive Session Refresh (TASR) protocol that ties key-rotation frequency to a device's evolving trust score rather than to fixed intervals. Experimental evaluation on a 100-device, five-edge-node testbed shows that PQ-SecureEdge reduces overall key-exchange latency by 21.5% relative to Kyber-512 and 35.4% relative to NTRU-HPS-2048, while lowering memory footprint by 21.3% relative to Kyber-512. Trust-adaptive refresh further lowers average re-keying energy overhead by 41.2% relative to fixed-interval rotation, without measurable loss of security. Security analysis confirms that PQ-SecureEdge preserves a 128-bit post-quantum security margin comparable to NIST-standardized schemes. Statistical analysis across three comparative evaluations confirms the efficiency and robustness of the proposed extension.





