Viabilidade de Criptografia Pós-Quântica em Dispositivos IoT: Estudo de Caso Múltiplo com ESP32, ESP8266 e ARMv7

  • Wesley Rodrigues da Silva IPT
  • Eduardo Takeo Ueda IPT / UFSCar

Resumo


A padronização da criptografia pós-quântica (PQC) pelo NIST cria pressão para migrar a ampla base instalada de dispositivos IoT de baixo custo. Contudo, trabalhos correlatos costumam relatar tempo e energia sem registrar se os algoritmos de fato executam em hardware restrito. Este artigo apresenta um estudo de caso múltiplo sobre a viabilidade de executar algoritmos de assinatura digital padronizados pelo NIST em cinco unidades: duas placas ARMv7, um ESP32-S3, um ESP8266 e um processador de referência de alto desempenho. Comparamos o ECDSA clássico com ML-DSA, FN-DSA e SLH-DSA no nível de segurança 3 do NIST. O achado central é uma barreira concreta de viabilidade: o ESP32 e o ESP8266 não conseguiram executar ML-DSA nem FN-DSA, pois ambos dependem do SHAKE-256, enquanto o SLH-DSA, quando executou, levou dezenas de segundos por assinatura. Em ARMv7, por outro lado, o ML-DSA foi até mais rápido e mais eficiente energeticamente que o ECDSA. Escolher PQC para um produto IoT exige, portanto, verificar o suporte à primitiva de hash subjacente, e não apenas o nível de segurança nominal.

Palavras-chave: Internet das Coisas, Criptografia Pós-Quântica, Assinatura Digital, Estudo de Caso Múltiplo, Dispositivos Restritos

Referências

Bormann, C., Ersue, M., and Keranen, A. (2014). Terminology for Constrained-Node Networks. RFC 7228.

Certicom Research (2009). Standards for efficient cryptography SEC 1: Elliptic curve cryptography. Technical report, Certicom Corp. Version 2.0; Contact: Daniel R. L. Brown.

Fernández-Caramés, T. M. (2020). From pre-quantum to post-quantum iot security: A survey on quantum-resistant cryptosystems for the internet of things. IEEE Internet of Things Journal, 7(7):6457–6480.

Iqbal, S. S. and Zafar, A. (2023). A survey on post quantum cryptosystems: Concept, attacks, and challenges in iot devices. In Proceedings of [...], pages 460–465, New Delhi, India. IEEE.

Kannwischer, M. J., Schwabe, P., Stebila, D., and Wiggers, T. (2022). Improving software quality in cryptography standardization projects. In IEEE European Symposium on Security and Privacy, EuroS&P 2022 - Workshops, Genoa, Italy, June 6-10, 2022, pages 19–30, Los Alamitos, CA, USA. IEEE Computer Society.

MacKay, K. (2025). kmackay/micro-ecc.

NIST (2024a). Module-Lattice-Based Digital Signature Standard. Number FIPS 204. Gaithersburg, MD.

NIST (2024b). Module-Lattice-Based Key-Encapsulation Mechanism Standard. Number FIPS 203. Gaithersburg, MD.

NIST (2024c). Stateless Hash-Based Digital Signature Standard. Number FIPS 205. Gaithersburg, MD.

Prantl, T., Prantl, D., Bauer, A., Iffländer, L., Dmitrienko, A., Kounev, S., and Krupitzer, C. (2021). Benchmarking of pre- and post-quantum group encryption schemes with focus on IoT. In 2021 IEEE International Performance, Computing, and Communications Conference (IPCCC), pages 1–10. ISSN: 2374-9628.

Schöffel, M., Lauer, F., Rheinländer, C. C., and Wehn, N. (2021). On the energy costs of post-quantum KEMs in TLS-based low-power secure IoT. In Proceedings of the International Conference on Internet-of-Things Design and Implementation, IoTDI ’21, pages 158–168. Association for Computing Machinery.

Statista (2024). Internet of things (IoT) connected devices installed base worldwide from 2015 to 2025.

Yin, R. K. (2018). Case Study Research and Applications: Design and Methods. SAGE Publications, Thousand Oaks, CA, 6 edition.
Publicado
01/09/2026
SILVA, Wesley Rodrigues da; UEDA, Eduardo Takeo. Viabilidade de Criptografia Pós-Quântica em Dispositivos IoT: Estudo de Caso Múltiplo com ESP32, ESP8266 e ARMv7. In: WORKSHOP CIBERSEGURANÇA QUÂNTICA: TEORIA, TECNOLOGIAS E APLICAÇÕES - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 857-863. DOI: https://doi.org/10.5753/sbseg_estendido.2026.32683.