Post-Quantum Security Frameworks for Internet of Things Systems: A Layered Narrative Review of Architectures, Protocols, Trust, and Emerging Challenges
The analysis indicates a significant prevalence of lattice-based schemes, hybrid strategies, and integrations with blockchain technology, zero-knowledge proofs, federated learning, homomorphic encryption, AI, and Zero Trust architectures, as well as key gaps remain in side-channel evaluation, migration pathways, deployment costs, and real-world validation.
Abstract
Quantum computing poses a significant threat to classical asymmetric cryptography, which is essential for ensuring confidentiality, authentication, and key exchange in contemporary digital infrastructures. Although post-quantum cryptography (PQC) provides mechanisms that resist quantum attacks, its implementation in Internet of Things (IoT) systems is challenged by constrained resources, including limitations in computation, memory, energy, latency, and bandwidth, and the heterogeneity of devices. This paper offers a comprehensive narrative review of PQC approaches applicable to IoT, systematically organizing 30 peer-reviewed studies published between 2022 and 2026 across four layers: device, communication, distributed trust, and application. Additionally, the review examines two cross-cutting dimensions, privacy and side-channel resistance. The analysis indicates a significant prevalence of lattice-based schemes, hybrid strategies, and integrations with blockchain technology, zero-knowledge proofs, federated learning, homomorphic encryption, AI, and Zero Trust architectures. Notably, key gaps remain in side-channel evaluation, migration pathways, deployment costs, and real-world validation—issues that are particularly critical given the long lifecycles of IoT devices and the ongoing threat of “harvest now, decrypt later” attacks.
The study evaluates major post-quantum cryptographic primitives, assesses their suitability for blockchain environments, and proposes a layered architecture grounded in crypto-agility, defense-in-depth, and forward secrecy.
The rapid advancement of quantum computing poses a critical threat to classical cryptographic schemes that secure modern distributed systems. As the deployment of distributed infrastructures—including blockchains, cloud-native applications, and edge networks—continues to grow, there is an urgent need to transition towards quantum-resistant security mechanisms. This paper provides a comprehensive examination of post-quantum cryptographic (PQC) algorithms and their applicability in distributed system architectures. We analyze the impact of quantum threats on key components of distributed systems such as communication protocols, identity management, data integrity, and consensus mechanisms. Furthermore, we evaluate current NIST-standardized PQC algorithms in terms of computational efficiency, scalability, and integration overhead within distributed environments. Challenges in key management, performance trade-offs, and implementation considerations are discussed. Finally, we propose best practices and future directions for secure, quantum-resilient distributed systems.
Chen Ming· International Journal of Mod...· 0 citations
Encryption is the cornerstone of modern information security, enabling confidential communication across digital infrastructures that span personal devices, enterprise networks, cloud platforms, distributed ledgers, and the Internet of Things. This article provides a structured, in-depth review of encryption techniques documented in twenty-eight authoritative sources. Coverage spans symmetric algorithms (AES, DES, 3DES, Blowfish, RC4), asymmetric methods (RSA, ECC, ElGamal), classical information-theoretically secure ciphers (One-Time Pad), hybrid encryption systems, homomorphic encryption, blockchain, searchable encryption, and post-quantum cryptographic approaches based on lattice problems, code-based assumptions, and hash functions. For each technique, this review examines theoretical foundations, algorithmic structure, operational workflow, practical implementations, computational trade-offs, and security properties under both classical and quantum threat models. Structural process diagrams are provided to illustrate how plaintext is transformed to ciphertext and back under each paradigm. The following metrics were covered during the analysis Recommendations were made on what the best applicable solution across security level, key size, throughput, and quantum resistance demonstrates that no single algorithm universally satisfies all competing demands; hybrid and lattice-based designs represent the most promising directions for future-proof encryption. Open challenges including Fully Homomorphic Encryption (FHE) performance, post-quantum migration, IoT key management, and regulatory alignment are discussed, followed by a research agenda for the post-quantum era.
Anah Hassan Bijik, Sojah Patrick Yakubu, Ibrahim Lawal et al.· International Journal of Adv...· 0 citations
The proposed Quantum Shield-IoT is a quantum-resilient hybrid security framework that combines the Quantum Key Distribution (QKD) protocol of BB84 with ASCON lightweight authenticated encryption, blockchain security, and cloud computing to ensure secure end-to-end data transmission in IoT.
Yenubarla Winstone Smiles, Dr. S. Sevugarajan· International Journal of Inn...· 0 citations
Internet public-key cryptography faces long-term risk from quantum computers, especially when traffic can be collected now and decrypted later. After the NIST post-quantum cryptography standards, the deployment task has shifted from algorithm selection to protocol migration. This paper reviews ML-KEM hybrid key exchange in TLS and SSH through a standards-first narrative review and protocol comparison. It synthesizes NIST standards, RFCs and IETF drafts, experiments, measurements, and primary deployment reports. The paper develops a deployment-readiness framework with four layers: security continuity, protocol integration, operational observability, and crypto-agility. The analysis shows hybrid key exchange represents the most feasible short-term solution, as it introduces post-quantum confidentiality without discarding existing elliptic curve security guarantees. However, hybrid deployment does not provide full post-quantum security. The review argues that readiness depends on protocol binding, implementation behavior, monitoring, and governance as much as on algorithm strength. Handshake size, middlebox compatibility, implementation safety, telemetry, authentication migration, and organizational crypto-agility determine whether migration can progress without weakening current Internet security.
Yan Zhang· Applied and Computational En...· 0 citations
The Internet of Things look out on growing security and privacy defies, principally in light of the up growth of quantum threats. To handle these defies, we suggest a unified security framework that merges post-quantum blockchain technologies and zero-knowledge proofs (ZKPs) to attain secure authentication, decentralized identity management, and advanced data protection. The provided system based on a power-weighted consensus mechanism, compressed and overlapping recursive ZKPs, and transaction batching to decrease on-chain load. The outcomes display that the suggested system outperforms conventional systems and state-of-the-art solutions, with response time reduced to 92 ms, transaction throughput increased to 735 tx/s, energy consumption reduced to 0.37 J/op, and authentication accuracy increased to 97.6%, achieving a privacy score of 0.91.These outcomes emphasize that the offered framework not only attains superior performance but as well supplies strong resistance to quantum attacks and high privacy warranties, making it a promising solution for securing future IoT environments.
Hayder A. Nahi, Rusul A. Salman, Awring Falah Hassan et al.· Discover Computing· 0 citations