Name
On the implementation of post-quantum remote attestation protocols for IoT
Authors
Daniel Sanz Sobrino, Roger Farrerons Calbet, DavidArroyo, Andrés Marín López
Abstract
We present a post-quantum (PQ) upgrade of RESEKRA, a Trusted Platform Module (TPM)-centric remote attestation protocol for IoT devices, aligned with FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA). Our hybrid design combines lattice cryptography with RSA/ECC and requires verification under both classical and PQ models to prevent downgrade attacks. It runs on unmodified commodity TPMs and supports dynamic enrolment, sealed-key attestation, and verifier-controlled policy updates on resource-constrained platforms. Each successful attestation is anchored in Hyperledger Fabric, which forms a tamper-evident audit trail that mitigates single points of failure in audit availability through distributed endorsement and thwarts rollback attempts.