Secure Remote Attestation for IoT Device Swarms under Roving Malware Threats
Keywords:
Internet of Things, Remote Attestation, Swarms, Physically Unclonable Functions (PUFs), IoT NodesAbstract
Remote attestation for IoT swarms faces critical gaps: software-based methods suffer high latency and assume tamper-proof hardware, while hardware-based solutions are costly and scale poorly. No existing approach provides both scalability and physical security simultaneously. This paper introduces a PUF-enhanced parallel attestation protocol that partitions memory across swarm nodes to achieve fast verification while embedding hardware-based security. The protocol was implemented on Raspberry Pi3 platforms as IoT provers with a dedicated 256 KB golden firmware region, excluding device-specific data to prevent false positives. Each device's memory was partitioned into blocks, with one block assigned per device for parallel attestation; each device used its PUF response to seed random bit sampling from its assigned block to generate a compact checksum. The border router aggregated individual checksums into a cumulative response for the verifier, with each device adding its MAC using a pre-shared key to prevent tampering with the router. The protocol was evaluated against three state?of?the?art techniques (SWARNA, FeSA, and JANUS) under identical hardware and memory configurations, measuring end?to?end latency, communication overhead, and energy consumption across swarm sizes of 32, 64, 128, and 256 nodes. The proposed technique detected roving malware with 95% accuracy. Experimental measurements showed end-to-end latency of 0.046 s for 32 nodes, representing reductions of 97%, 95%, and 91% compared to SWARNA (1.5 s), FeSA (1.0 s), and JANUS (0.5 s), respectively. The latency decreased as swarm size increased due to parallelism, while per-device communication overhead remained constant at 128 bytes regardless of swarm population. Energy consumption was approximately 154 ?J per device per round, which is about 17× lower than that of SWARNA and 650× lower than that of JANUS. This work provides a scalable, physically secure, and energy-efficient attestation solution for IoT swarms, suitable for smart manufacturing, industrial IoT, and defense environments, deployable on commodity hardware without expensive trusted modules.
References
Ahmadi, S., Le-Papin, J., Chen, L., Dongol, B., Radomirovic, S., & Treharne, H. (2024). On the Design and Security of Collective Remote Attestation Protocols. http://arxiv.org/abs/2407.09203.
Akhtar, M. H., Jabeen, T., Aziz, R., Amin, M. N., Rizwan, S. M., & Hamid, K. (2024). Intelligence based Self-Healing Network Design: An Automated Incident Response System for Troubleshooting of IoT Security Breaches. Retrieved: http://amresearchreview.com/index.php/Journal/about
Alam, I., Samiullah, M., Asaduzzaman, S. M., Kabir, U., Aahad, A. M., & Woo, S. S. (2025). MIRACLE: Malware image recognition and classification by layered extraction. Data Mining and Knowledge Discovery, 39(1). https://doi.org/10.1007/s10618-024-01078-z
Aliaj, E., De, I., Nunes, O., De Oliveira Nunes, I., & Tsudik, G. (2022). GAROTA: Generalized Active Root-Of-Trust Architecture (for Tiny Embedded Devices). Retrieved https://www.usenix.org/conference/usenixsecurity22/presentation/aliaj
Ammar, M., Caulfield, A., De, I., & Nunes, O. (2025). SoK: Integrity, Attestation, and Auditing of Program Execution.
Athar, S. O., Aman, M. N., & Sikdar, B. (2025). DuAtt: A Dual-Layer Attestation Scheme for PLC-Based Industrial Internet of Things. IEEE Internet of Things Journal, 12(20). https://doi.org/10.1109/JIOT.2025.3589940
Baig, M. A., Iqbal, A., Aman, M. N., & Sikdar, B. (2025). Leveraging AI to Compromise IoT Device Privacy by Exploiting Hardware Imperfections. IEEE Transactions on Artificial Intelligence, 6(6). https://doi.org/10.1109/TAI.2025.3526139
Bhole, M., Kastner, W., & Sauter, T. (2024). From Manual to Semi-Automated Safety and Security Requirements Engineering: Ensuring Compliance in Industry 4.0. https://standards.ieee.org/
Dushku, E., Rabbani, M. M., Vliegen, J., Braeken, A., & Mentens, N. (2023). PROVE: Provable remote attestation for public verifiability. Journal of Information Security and Applications, 75. https://doi.org/10.1016/j.jisa.2023.103448
Ferro, L., Bravi, E., Sisinni, S., & Lioy, A. (2024). SAFEHIVE: Secure Attestation Framework for Embedded and Heterogeneous IoT Devices in Variable Environments. SaT-CPS 2024 - Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems, 41–50. https://doi.org/10.1145/3643650.3658609
Kassem, N. El, Hellemans, W., Siachos, I., Dushku, E., Vasileiadis, S., Karas, D. S., Chen, L., Patsakis, C., & Giannetsos, T. (2025). PRIVE: Towards Privacy-Preserving Swarm Attestation. Proceedings of the International Conference on Security and Cryptography, 1, 247–262. https://doi.org/10.5220/0013629000003979
Khan, M. A., Aman, M. N., & Sikdar, B. (2024). Soteria: A Quantum-Based Device Attestation Technique for Internet of Things. IEEE Internet of Things Journal, 11(9). https://doi.org/10.1109/JIOT.2023.3346397
Khan, M. A., Shalu, Naveed, Q. N., Lasisi, A., Kaushik, S., & Kumar, S. (2024). A Multi-Layered Assessment System for Trustworthiness Enhancement and Reliability for Industrial Wireless Sensor Networks. Wireless Personal Communications, 137(4). https://doi.org/10.1007/s11277-024-11391-x
Khan, S., Martins, P. A. F. L., Sousa, B., & Pereira, V. (2025). A Comprehensive Review on Lightweight Cryptographic Mechanisms for Industrial Internet of Things Systems. In ACM Computing Surveys (Vol. 58, Number 1). Association for Computing Machinery. https://doi.org/10.1145/3757734
Kibret, S. W. (2022). Property-based attestation in device swarms: A machine learning approach. In Machine Learning for Cyber Security. https://doi.org/10.1515/9783110766745-004
Kuang, B., Fu, A., Gao, Y., Zhang, Y., Zhou, J., & Deng, R. H. (2023). FeSA: Automatic Federated Swarm Attestation on Dynamic Large-Scale IoT Devices. IEEE Transactions on Dependable and Secure Computing, 20(4), 2954–2969. https://doi.org/10.1109/TDSC.2022.3193106
Kumar, S., Eugster, P., & Santini, S. (2022). Software-Based Remote Network Attestation. IEEE Transactions on Dependable and Secure Computing, 19(5). https://doi.org/10.1109/TDSC.2021.3077993
Kwon, H. (2025). Secure and Scalable Device Attestation Protocol with Aggregate Signature. Symmetry, 17(5). https://doi.org/10.3390/sym17050698
Mehjabin, S. S., & Younis, M. (2025). PAMA: PUF-based Aggregated Multi-hop Attestation Protocol for IoT. IEEE International Conference on Communications. https://doi.org/10.1109/ICC52391.2025.11161539
Orman, A. (2025). Cyberattack Detection Systems in Industrial Internet of Things (IIoT) Networks in Big Data Environments. Applied Sciences (Switzerland), 15(6). https://doi.org/10.3390/app15063121
Song, H., Yuan, Y., Wang, Y., Yang, J., Luo, H., & Li, S. (2024). A Security Posture Assessment of Industrial Control Systems Based on Evidential Reasoning and Belief Rule Base. Sensors, 24(22). https://doi.org/10.3390/s24227135
Usman, A. B., & Asplund, M. (2024). Remote Attestation with Software Updates in Embedded Systems. 2024 IEEE Conference on Communications and Network Security, CNS 2024. https://doi.org/10.1109/CNS62487.2024.10735526
Vuseghesa, F. K., Messai, M. L., & Bentayeb, F. (2025). SHIELD: Self-Healing IoT Networks with Automated Response and AI-Driven Detection of Node Compromising Attacks. 21st International Wireless Communications and Mobile Computing Conference, IWCMC 2025. https://doi.org/10.1109/IWCMC65282.2025.11059566
Wu, Y., Wang, J., Wang, Y., Zhai, S., Li, Z., He, Y., Sun, K., Li, Q., & Zhang, N. (2024). Your Firmware Has Arrived: A Study of Firmware Update Vulnerabilities. Retrieved https://www.usenix.org/conference/usenixsecurity24/presentation/wu-yuhao
Zhang, X., Qin, K., Qu, S., Wang, T., Zhang, C., & Gu, D. (2024). Teamwork Makes TEE Work: Open and Resilient Remote Attestation on Decentralized Trust. http://arxiv.org/abs/2402.08908
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Nigerian Journal of Technological Development

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
In accordance with the Copyright Act of 1976, which became effective January 1, 1978, the following statement signed by each author must accompany the manuscript submitted: "I, the undersigned author, transfer all copyright ownership of the manuscript referenced above to the Nigerian Journal of Technological Development, in the event the work is published. I warrant that the article is original, does not infringe upon any copyright or other proprietary right of any third party, is not under consideration by another journal, and has not been published previously. I have reviewed and approved the submitted version of the manuscript and agree to its publication in the Nigerian Journal of Technological Development." A copyright transfer form can be downloaded from the NJTD Website (http://njtd.com.ng/index.php/njtd). Author(s) will be consulted, whenever possible, regarding republication of material. All authors must have access to the data presented, and the authors and sponsor (if applicable) must agree to share original data with the editor if requested.
