Post-Quantum Security Frameworks for Internet of Things Systems: A Layered Narrative Review of Architectures, Protocols, Trust, and Emerging Challenges

Authors

DOI:

https://doi.org/10.26439/interfases2026.n023.8810

Keywords:

post-quantum cryptography, Internet of Things, lattice-based cryptography, side-channel attacks, privacy

Abstract

Quantum computing poses a significant threat to classical asymmetric cryptography, which is essential for ensuring confidentiality, authentication, and key exchange in contemporary digital infrastructures. Although post-quantum cryptography (PQC) provides mechanisms that resist quantum attacks, its implementation in Internet of Things (IoT) systems is challenged by constrained resources, including limitations in computation, memory, energy, latency, and bandwidth, and the heterogeneity of devices. This paper offers a comprehensive narrative review of PQC approaches applicable to IoT, systematically organizing 30 peer-reviewed studies published between 2022 and 2026 across four layers: device, communication, distributed trust, and application. Additionally, the review examines two cross-cutting dimensions, privacy and side-channel resistance. The analysis indicates a significant prevalence of lattice-based schemes, hybrid strategies, and integrations with blockchain technology, zero-knowledge proofs, federated learning, homomorphic encryption, AI, and Zero Trust architectures. Notably, key gaps remain in side-channel evaluation, migration pathways, deployment costs, and real-world validation—issues that are particularly critical given the long lifecycles of IoT devices and the ongoing threat of “harvest now, decrypt later” attacks.

Downloads

Download data is not yet available.

Author Biographies

  • Rodrigo Jara Espinoza, Laboratorio SAP, Universidad de Lima, Perú

    A Systems Engineering student at the University of Lima, with experience in the University of Lima SAP Laboratory. Their academic and professional profile is focused on software engineering and DevOps, with a particular interest in web development, process automation, and the continuous improvement of technological solutions.

  • Yohamin Nafit Pimentel Alarcon, Laboratorio SAP, Universidad de Lima, Perú

    A Systems Engineering student at the University of Lima, Peru. They currently work at the University of Lima SAP Laboratory. Their academic and professional profile focuses on cybersecurity, with research interests in cybersecurity and the Internet of Things (IoT).

  • Angelo Taco-Jimenez, Laboratorio SAP, Universidad de Lima, Perú

    Holds a bachelor’s degree in Systems Engineering from the University of Lima, graduating summa cum laude. Specializes in software development for mobile applications and currently serves as an Android Engineer at ITLAB and Android Project Manager at White Pencil Consulting. In addition, serves as a teaching assistant in the Systems Engineering program at the University of Lima and is pursuing a master’s degree in Innovation Management at the University of Lima’s Graduate School. Research interests include self-adaptive software and human–computer interaction.

  • Fabricio Martin Chavez Rodriguez, Laboratorio SAP, Universidad de Lima, Perú

    A Systems Engineering student at the University of Lima, where they also work in the University’s SAP Laboratory. Their academic and professional interests focus on information technologies, with particular emphasis on artificial intelligence, automation, the Internet of Things (IoT), information analytics, systems auditing, and digital transformation.

References

Ahmad, A., Jagatheswari, S., & Praveen, R. (2026). Quantum-secure lightweight fuzzy extractor based user authentication scheme for Internet of Medical Things. Soft Computing, 30, 787-808.

Alatawi, M. N. (2025). EdgeGuard-IoT: 6G-enabled edge intelligence for secure federated learning and adaptive anomaly detection in Industry 5.0. Computers, Materials & Continua, 85(1), 695-727.

Al-Doori, M. J., & Al-Gailani, M. F. (2023). Securing IoT networks with NTRU cryptosystem: A practical approach on ARM-based devices for edge and fog layer integration. International Journal of Intelligent Engineering & Systems, 16(5), 462-472.

Aleisa, M. A. (2025). Blockchain-enabled zero trust architecture for privacy-preserving cybersecurity in IoT environments. IEEE Access, 13, 18660-18676.

Al-Mekhlafi, Z. G., Altmemi, J. M. H., Al-Shareeda, M. A., Al-Al-Hchaimi, A. A. J., Gaber, T., Homod, R. Z., Mohammed, B. A., Alshammari, G., Al-Dhlan, K. A., Alrashdi, R., & Alkhabra, Y. A. (2026). A post-quantum secure solution for SECS/GEM communications in Industrial Internet of Things (IIoT) application. IEEE Open Journal of the Communications Society, 7, 670-684. https://doi.org/10.1109/OJCOMS.2026.3654010

Aneesh Kumar, K. B., Mohith, L. S., Jain, K., Krishnan, P., Venkatachalam, N., & Buyya, R. (2025). Post-quantum cryptography-based multimedia encryption communication scheme in IoT consumer electronics. IEEE Transactions on Consumer Electronics, 71(2), 4995-5006. https://doi.org/10.1109/TCE.2025.3572949

Castiglione, A., Esposito, J. G., Loia, V., Nappi, M., Pero, C., & Polsinelli, M. (2025). Integrating post-quantum cryptography and blockchain to secure low-cost IoT devices. IEEE Transactions on Industrial Informatics, 21(2), 1674-1683.

Cruz-Piris, L., Marín-López, A., Álvarez-Campana, M., Sanz, M., Moreno, J. I., & Arroyo, D. (2025). Measuring the impact of post quantum cryptography in Industrial IoT scenarios. Internet of Things, 34, Article 101793.

Do, T.-B., & Tran, Q.-H. (2026). A hybrid lightweight and post-quantum communication framework for NB-IoT networks. Microsystem Technologies, 32, Article 37. https://doi.org/10.1007/s00542-026-06031-2

Elkhodr, M. (2025). An AI-driven framework for integrated security and privacy in Internet of Things using quantum-resistant blockchain. Future Internet, 17(6), Article 246.

Halak, B., Gibson, T., Henley, M., Botea, C.-B., Heath, B., & Khan, S. (2024). Evaluation of performance, energy, and computation costs of quantum-attack resilient encryption algorithms for embedded devices. IEEE Access, 12, 8791-8805.

Iavich, M., Kuchukhidze, T., & Bocu, R. (2025). Fractional Verkle trees for scalable post-quantum signatures. IEEE Access, 13, 209921-209937.

Kerimbayeva, A., Iavich, M., Begimbayeva, Y., Gnatyuk, S., Tynymbayev, S., Temirbekova, Z., & Ussatova, O. (2025). A lightweight variant of Falcon for efficient post-quantum digital signature. Information, 16(7), Article 564.

Kim, C., Kwon, D., Park, Y., & Park, Y. (2026). Quantum-resistant three-party mutual authentication protocol for industrial IoT environments. IEEE Internet of Things Journal. Advance online publication. https://doi.org/10.1109/JIOT.2026.3677406

Kjamilji, A. (2024). Privacy-preserving zero-sum-path evaluation of decision trees in postquantum industrial IoT. IEEE Transactions on Industrial Informatics, 20(8), 10178-10191.

Kundu, S., Ghosh, A., Karmakar, A., Sen, S., & Verbauwhede, I. (2025). Rudraksh: A compact and lightweight post-quantum key-encapsulation mechanism. IACR Transactions on Cryptographic Hardware and Embedded Systems, 2025(2), 647-680.

Kwon, J., Lee, S., Lee, B., Seo, H., & Cho, J. (2025). Efficient implementations of AIMer post-quantum signature scheme for low-end to high-end IoT devices. IEEE Internet of Things Journal, 12(22), 46817-46837.

Li, Z., & Wang, D. (2022). Achieving one-round password-based authenticated key exchange over lattices. IEEE Transactions on Services Computing, 15(1), 308-321.

Mahdi, L. H., & Abdullah, A. A. (2025). A hybrid post-quantum cryptographic framework integrating Kyber-512 and ASCON for secure IoT communications. Engineering, Technology & Applied Science Research, 15(5), 26527-26533.

Marchsreiter, D. (2025). Towards quantum-safe blockchain: Exploration of PQC and public-key recovery on embedded systems. IET Blockchain, 5(1), Article e12094.

Ojetunde, B., Kurihara, T., Yano, K., Sakano, T., & Yokoyama, H. (2025). A practical implementation of post-quantum cryptography for secure wireless communication. Network, 5(2), Article 20.

Poomekum, P., Suriyawong, A., & Fugkeaw, S. (2025). Fine-grained and lightweight quantum-resistant access control system with efficient revocation for IoT cloud. IEEE Open Journal of the Communications Society, 6, 8652-8666.

Rahmati, M., & Pagano, A. (2025). Federated learning-driven cybersecurity framework for IoT networks with privacy preserving and real-time threat detection capabilities. Informatics, 12(3), Article 62.

Señor, J., Portilla, J., & Mujica, G. (2022). Analysis of the NTRU post-quantum cryptographic scheme in constrained IoT edge devices. IEEE Internet of Things Journal, 9(19), 18778-18790.

Shim, K.-A. (2024). On the suitability of post-quantum signature schemes for Internet of Things. IEEE Internet of Things Journal, 11(6), 10648-10665.

Tawfik, M., Abdelhaliem, A. H., & Fathi, I. (2025). Quantum-resistant privacy-preserving IoT authentication via zero-knowledge proofs and blockchain integration. Statistics, Optimization & Information Computing, 14(3), 1374-1402. https://doi.org/10.19139/soic-2310-5070-2399

Wu, J., Yu, Y., Chen, Z., Yang, H., Li, C., & Liu, Z. (2025). CBPSPX: A CUDA-based batch parallel optimization of post-quantum signature SPHINCS+. IEEE Internet of Things Journal, 12(18), 37898-37911.

Wu, W., Dong, J., Hou, Y., Liu, M., Li, L., & Dong, Z. (2026). RIGHT: GPU-optimized parallel PQC HAETAE for high-throughput cryptographic acceleration. IEEE Transactions on Industrial Informatics, 22(1), 532-542.

Xu, D., Wang, X., Hao, Y., Zhang, Z., Hao, Q., Jia, H., Dong, H., & Zhang, L. (2022). Ring-ExpLWE: A high-performance and lightweight post-quantum encryption scheme for resource-constrained IoT devices. IEEE Internet of Things Journal, 9(23), 24122-24134.

Zafar, A., & Iqbal, S. S. (2025). Integrating code-based post-quantum cryptography into SSL TLS protocols through an interoperable hybrid framework. Discover Computing, 28, Article 202. https://doi.org/10.1007/s10791-025-09735-7

Downloads

Published

2026-07-30

Issue

Section

Review papers

How to Cite

Jara Espinoza, R., Pimentel Alarcon, Y. N., Taco-Jimenez, A., & Chavez Rodriguez, F. M. (2026). Post-Quantum Security Frameworks for Internet of Things Systems: A Layered Narrative Review of Architectures, Protocols, Trust, and Emerging Challenges. Interfases, 023, 165-194. https://doi.org/10.26439/interfases2026.n023.8810