Lightweight and Resilient Signatures for Cloud-Assisted Embedded IoT Systems
Resource-constrained embedded IoT devices in cloud-assisted systems face severe key-exposure risks, yet existing forward-secure signature schemes incur prohibitive computational and storage overheads, while cloud-assisted approaches rely on centralized or non-colluding semi-honest server assumptions. Method: We propose a lightweight, high-resilience digital signature framework featuring (i) the novel LRSHA/FLRSHA dual-mechanism with commitment separation to drastically reduce signing cost; (ii) a hardware-assisted distributed server architecture eliminating reliance on trusted central authorities or non-collusion assumptions; and (iii) tight integration of HSM coordination, secret key sharding, lightweight elliptic curves, and AVR assembly-level optimization. Contribution/Results: Our implementation achieves millisecond-scale forward-secure signing on 8-bit AVR microcontrollers, with both keys and signatures compressed to the hundred-byte level. We provide formal security proofs and open-source the implementation, demonstrating cross-platform efficiency and practicality.