• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Towards Stateless Post-Quantum Remote Attestation for IoT Using TPM and DICE
 
  • Details
  • Full
Options
November 14, 2025
Conference Paper
Title

Towards Stateless Post-Quantum Remote Attestation for IoT Using TPM and DICE

Abstract
Remote attestation is a cornerstone of Trusted Computing, ensuring the integrity and trustworthiness of devices in diverse environments, ranging from resource-constrained IoT nodes to cloud-based virtual machines (VMs). The two predominant attestation technologies, the Trusted Platform Module (TPM) and the Device Identifier Composition Engine (DICE), provide strong security guarantees but often rely on stateful challenge-response models. These models introduce scalability challenges, particularly in large-scale Internet of Things (IoT) and smart metering deployments.This paper presents a powerful stateless post-quantum remote attestation approach for IoT devices, leveraging authenticated and encrypted (AEAD) challenges within TPM and DICE-based attestation. The stateless approach effectively limits replay attacks to a short validity window, even in environments where IoT devices lack real-time clocks, and enables robust integrity and trust verification across dynamic network topologies, by avoiding the downsides of other freshness concepts for remote attestation.Furthermore, this paper presents a performance evaluation of suitable post-quantum cryptography (PQC) algorithms across five heterogeneous hardware platforms, ranging from high-end laptops to constrained IoT devices, to present a recommendation to the reader, thereby illustrating the continued utility of remote attestation on IoT devices in the future.Our findings suggest that stateless post-quantum remote attestation can enhance security and scalability in IoT environments, by reducing overhead from storage of nonces making it a compelling alternative to traditional challenge-response models.
Author(s)
Eckel, Michael  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Gorbracht, Janik
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Gkoktsis, George
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Kaupat, Tobias
Mainwork
IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications, TrustCom 2025. Proceedings  
Conference
International Conference on Trust, Security and Privacy in Computing and Communications 2025  
DOI
10.1109/Trustcom66490.2025.00350
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024