One-to-Many Authentication and Key Agreement Scheme With Desynchronization Resilience and Forward Secrecy for Multi-Device IoT
Abstract
Lightweight authentication schemes based on pre-shared keys (PSK) are widely adopted to secure data access and preserve privacy in the Internet of Things (IoT). However, ensuring forward secrecy in the event of PSK compromise remains a fundamental challenge. Although credential update mechanisms can provide dynamic authentication and forward secrecy, many existing schemes remain vulnerable to desynchronization attacks. Moreover, as IoT deployments scale, achieving forward secrecy for one-to-many authentication in multi-device environments becomes increasingly complex. To address these challenges, we propose a one-to-many authentication scheme with desynchronization resilience and forward secrecy based on the Chinese Remainder Theorem (CRT). Specifically, we introduce a deterministic prime derivation function (PDF) that enables deterministic reconstruction of per-device primes via a compact reconstruction descriptor and avoids the bandwidth cost of transmitting the full moduli. We further redesign the PSK-based updates by replacing explicit device credential refreshes with challenge–response regeneration and by binding credential generation to pseudonym rotation, achieving desynchronization resilience and forward secrecy in multi-device IoT. In addition, the scheme establishes multiple distinct session keys in a single authentication round and offloads heavy computation to the edge gateway. Finally, we analyze the security of the proposed scheme through both formal and informal methods and validate its feasibility on a Xilinx ZedBoard FPGA. Comparative evaluations with state-of-the-art schemes demonstrate clear advantages in terms of both security and performance.