Viabilidade de Criptografia Pós-Quântica em Dispositivos IoT: Estudo de Caso Múltiplo com ESP32, ESP8266 e ARMv7
Resumo
A padronização da criptografia pós-quântica (PQC) pelo NIST cria pressão para migrar a ampla base instalada de dispositivos IoT de baixo custo. Contudo, trabalhos correlatos costumam relatar tempo e energia sem registrar se os algoritmos de fato executam em hardware restrito. Este artigo apresenta um estudo de caso múltiplo sobre a viabilidade de executar algoritmos de assinatura digital padronizados pelo NIST em cinco unidades: duas placas ARMv7, um ESP32-S3, um ESP8266 e um processador de referência de alto desempenho. Comparamos o ECDSA clássico com ML-DSA, FN-DSA e SLH-DSA no nível de segurança 3 do NIST. O achado central é uma barreira concreta de viabilidade: o ESP32 e o ESP8266 não conseguiram executar ML-DSA nem FN-DSA, pois ambos dependem do SHAKE-256, enquanto o SLH-DSA, quando executou, levou dezenas de segundos por assinatura. Em ARMv7, por outro lado, o ML-DSA foi até mais rápido e mais eficiente energeticamente que o ECDSA. Escolher PQC para um produto IoT exige, portanto, verificar o suporte à primitiva de hash subjacente, e não apenas o nível de segurança nominal.
Referências
Certicom Research (2009). Standards for efficient cryptography SEC 1: Elliptic curve cryptography. Technical report, Certicom Corp. Version 2.0; Contact: Daniel R. L. Brown.
Fernández-Caramés, T. M. (2020). From pre-quantum to post-quantum iot security: A survey on quantum-resistant cryptosystems for the internet of things. IEEE Internet of Things Journal, 7(7):6457–6480.
Iqbal, S. S. and Zafar, A. (2023). A survey on post quantum cryptosystems: Concept, attacks, and challenges in iot devices. In Proceedings of [...], pages 460–465, New Delhi, India. IEEE.
Kannwischer, M. J., Schwabe, P., Stebila, D., and Wiggers, T. (2022). Improving software quality in cryptography standardization projects. In IEEE European Symposium on Security and Privacy, EuroS&P 2022 - Workshops, Genoa, Italy, June 6-10, 2022, pages 19–30, Los Alamitos, CA, USA. IEEE Computer Society.
MacKay, K. (2025). kmackay/micro-ecc.
NIST (2024a). Module-Lattice-Based Digital Signature Standard. Number FIPS 204. Gaithersburg, MD.
NIST (2024b). Module-Lattice-Based Key-Encapsulation Mechanism Standard. Number FIPS 203. Gaithersburg, MD.
NIST (2024c). Stateless Hash-Based Digital Signature Standard. Number FIPS 205. Gaithersburg, MD.
Prantl, T., Prantl, D., Bauer, A., Iffländer, L., Dmitrienko, A., Kounev, S., and Krupitzer, C. (2021). Benchmarking of pre- and post-quantum group encryption schemes with focus on IoT. In 2021 IEEE International Performance, Computing, and Communications Conference (IPCCC), pages 1–10. ISSN: 2374-9628.
Schöffel, M., Lauer, F., Rheinländer, C. C., and Wehn, N. (2021). On the energy costs of post-quantum KEMs in TLS-based low-power secure IoT. In Proceedings of the International Conference on Internet-of-Things Design and Implementation, IoTDI ’21, pages 158–168. Association for Computing Machinery.
Statista (2024). Internet of things (IoT) connected devices installed base worldwide from 2015 to 2025.
Yin, R. K. (2018). Case Study Research and Applications: Design and Methods. SAGE Publications, Thousand Oaks, CA, 6 edition.