Secure Remote Attestation for IoT Device Swarms under Roving Malware Threats

Authors

  • H. O. Abdulraheem Cybersecurity Science Department, Federal University of Technology Minna, Niger State, Nigeria
  • I. Idris Cybersecurity Science Department, Federal University of Technology Minna, Niger State, Nigeria
  • J. A. Ojeniyi Cybersecurity Science Department, Federal University of Technology Minna, Niger State, Nigeria
  • I. A. Ibrahim Cybersecurity Science Department, Federal University of Technology Minna, Niger State, Nigeria

Keywords:

Internet of Things, Remote Attestation, Swarms, Physically Unclonable Functions (PUFs), IoT Nodes

Abstract

Remote attestation for IoT swarms faces critical gaps: software-based methods suffer high latency and assume tamper-proof hardware, while hardware-based solutions are costly and scale poorly. No existing approach provides both scalability and physical security simultaneously. This paper introduces a PUF-enhanced parallel attestation protocol that partitions memory across swarm nodes to achieve fast verification while embedding hardware-based security. The protocol was implemented on Raspberry Pi3 platforms as IoT provers with a dedicated 256 KB golden firmware region, excluding device-specific data to prevent false positives. Each device's memory was partitioned into blocks, with one block assigned per device for parallel attestation; each device used its PUF response to seed random bit sampling from its assigned block to generate a compact checksum. The border router aggregated individual checksums into a cumulative response for the verifier, with each device adding its MAC using a pre-shared key to prevent tampering with the router. The protocol was evaluated against three state?of?the?art techniques (SWARNA, FeSA, and JANUS) under identical hardware and memory configurations, measuring end?to?end latency, communication overhead, and energy consumption across swarm sizes of 32, 64, 128, and 256 nodes. The proposed technique detected roving malware with 95% accuracy. Experimental measurements showed end-to-end latency of 0.046 s for 32 nodes, representing reductions of 97%, 95%, and 91% compared to SWARNA (1.5 s), FeSA (1.0 s), and JANUS (0.5 s), respectively. The latency decreased as swarm size increased due to parallelism, while per-device communication overhead remained constant at 128 bytes regardless of swarm population. Energy consumption was approximately 154 ?J per device per round, which is about 17× lower than that of SWARNA and 650× lower than that of JANUS. This work provides a scalable, physically secure, and energy-efficient attestation solution for IoT swarms, suitable for smart manufacturing, industrial IoT, and defense environments, deployable on commodity hardware without expensive trusted modules.

References

Ahmadi, S., Le-Papin, J., Chen, L., Dongol, B., Radomirovic, S., & Treharne, H. (2024). On the Design and Security of Collective Remote Attestation Protocols. http://arxiv.org/abs/2407.09203.

Akhtar, M. H., Jabeen, T., Aziz, R., Amin, M. N., Rizwan, S. M., & Hamid, K. (2024). Intelligence based Self-Healing Network Design: An Automated Incident Response System for Troubleshooting of IoT Security Breaches. Retrieved: http://amresearchreview.com/index.php/Journal/about

Alam, I., Samiullah, M., Asaduzzaman, S. M., Kabir, U., Aahad, A. M., & Woo, S. S. (2025). MIRACLE: Malware image recognition and classification by layered extraction. Data Mining and Knowledge Discovery, 39(1). https://doi.org/10.1007/s10618-024-01078-z

Aliaj, E., De, I., Nunes, O., De Oliveira Nunes, I., & Tsudik, G. (2022). GAROTA: Generalized Active Root-Of-Trust Architecture (for Tiny Embedded Devices). Retrieved https://www.usenix.org/conference/usenixsecurity22/presentation/aliaj

Ammar, M., Caulfield, A., De, I., & Nunes, O. (2025). SoK: Integrity, Attestation, and Auditing of Program Execution.

Athar, S. O., Aman, M. N., & Sikdar, B. (2025). DuAtt: A Dual-Layer Attestation Scheme for PLC-Based Industrial Internet of Things. IEEE Internet of Things Journal, 12(20). https://doi.org/10.1109/JIOT.2025.3589940

Baig, M. A., Iqbal, A., Aman, M. N., & Sikdar, B. (2025). Leveraging AI to Compromise IoT Device Privacy by Exploiting Hardware Imperfections. IEEE Transactions on Artificial Intelligence, 6(6). https://doi.org/10.1109/TAI.2025.3526139

Bhole, M., Kastner, W., & Sauter, T. (2024). From Manual to Semi-Automated Safety and Security Requirements Engineering: Ensuring Compliance in Industry 4.0. https://standards.ieee.org/

Dushku, E., Rabbani, M. M., Vliegen, J., Braeken, A., & Mentens, N. (2023). PROVE: Provable remote attestation for public verifiability. Journal of Information Security and Applications, 75. https://doi.org/10.1016/j.jisa.2023.103448

Ferro, L., Bravi, E., Sisinni, S., & Lioy, A. (2024). SAFEHIVE: Secure Attestation Framework for Embedded and Heterogeneous IoT Devices in Variable Environments. SaT-CPS 2024 - Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems, 41–50. https://doi.org/10.1145/3643650.3658609

Kassem, N. El, Hellemans, W., Siachos, I., Dushku, E., Vasileiadis, S., Karas, D. S., Chen, L., Patsakis, C., & Giannetsos, T. (2025). PRIVE: Towards Privacy-Preserving Swarm Attestation. Proceedings of the International Conference on Security and Cryptography, 1, 247–262. https://doi.org/10.5220/0013629000003979

Khan, M. A., Aman, M. N., & Sikdar, B. (2024). Soteria: A Quantum-Based Device Attestation Technique for Internet of Things. IEEE Internet of Things Journal, 11(9). https://doi.org/10.1109/JIOT.2023.3346397

Khan, M. A., Shalu, Naveed, Q. N., Lasisi, A., Kaushik, S., & Kumar, S. (2024). A Multi-Layered Assessment System for Trustworthiness Enhancement and Reliability for Industrial Wireless Sensor Networks. Wireless Personal Communications, 137(4). https://doi.org/10.1007/s11277-024-11391-x

Khan, S., Martins, P. A. F. L., Sousa, B., & Pereira, V. (2025). A Comprehensive Review on Lightweight Cryptographic Mechanisms for Industrial Internet of Things Systems. In ACM Computing Surveys (Vol. 58, Number 1). Association for Computing Machinery. https://doi.org/10.1145/3757734

Kibret, S. W. (2022). Property-based attestation in device swarms: A machine learning approach. In Machine Learning for Cyber Security. https://doi.org/10.1515/9783110766745-004

Kuang, B., Fu, A., Gao, Y., Zhang, Y., Zhou, J., & Deng, R. H. (2023). FeSA: Automatic Federated Swarm Attestation on Dynamic Large-Scale IoT Devices. IEEE Transactions on Dependable and Secure Computing, 20(4), 2954–2969. https://doi.org/10.1109/TDSC.2022.3193106

Kumar, S., Eugster, P., & Santini, S. (2022). Software-Based Remote Network Attestation. IEEE Transactions on Dependable and Secure Computing, 19(5). https://doi.org/10.1109/TDSC.2021.3077993

Kwon, H. (2025). Secure and Scalable Device Attestation Protocol with Aggregate Signature. Symmetry, 17(5). https://doi.org/10.3390/sym17050698

Mehjabin, S. S., & Younis, M. (2025). PAMA: PUF-based Aggregated Multi-hop Attestation Protocol for IoT. IEEE International Conference on Communications. https://doi.org/10.1109/ICC52391.2025.11161539

Orman, A. (2025). Cyberattack Detection Systems in Industrial Internet of Things (IIoT) Networks in Big Data Environments. Applied Sciences (Switzerland), 15(6). https://doi.org/10.3390/app15063121

Song, H., Yuan, Y., Wang, Y., Yang, J., Luo, H., & Li, S. (2024). A Security Posture Assessment of Industrial Control Systems Based on Evidential Reasoning and Belief Rule Base. Sensors, 24(22). https://doi.org/10.3390/s24227135

Usman, A. B., & Asplund, M. (2024). Remote Attestation with Software Updates in Embedded Systems. 2024 IEEE Conference on Communications and Network Security, CNS 2024. https://doi.org/10.1109/CNS62487.2024.10735526

Vuseghesa, F. K., Messai, M. L., & Bentayeb, F. (2025). SHIELD: Self-Healing IoT Networks with Automated Response and AI-Driven Detection of Node Compromising Attacks. 21st International Wireless Communications and Mobile Computing Conference, IWCMC 2025. https://doi.org/10.1109/IWCMC65282.2025.11059566

Wu, Y., Wang, J., Wang, Y., Zhai, S., Li, Z., He, Y., Sun, K., Li, Q., & Zhang, N. (2024). Your Firmware Has Arrived: A Study of Firmware Update Vulnerabilities. Retrieved https://www.usenix.org/conference/usenixsecurity24/presentation/wu-yuhao

Zhang, X., Qin, K., Qu, S., Wang, T., Zhang, C., & Gu, D. (2024). Teamwork Makes TEE Work: Open and Resilient Remote Attestation on Decentralized Trust. http://arxiv.org/abs/2402.08908

Published

2026-06-30

Similar Articles

You may also start an advanced similarity search for this article.