The proliferation of Internet of Things (IoT) networks demands security mechanisms that protect constrained devices without the computational cost of public-key cryptography. Conventional Pre-Shared Key (PSK) encryption, while efficient, remains vulnerable due to static key reuse, replay attacks, and the lack of key freshness. This paper presents the Dynamic Session Enhanced Key Protocol (DSEKP), a lightweight session-key rekeying framework that derives per-session AES-GCM keys using the HMAC-based Key Derivation Function (HKDF-SHA256) and authenticates session establishment through an HMAC proof in a single init-ack exchange. DSEKP was implemented on an ESP32 IoT sensor node and a Raspberry Pi 5 edge server communicating through a Mosquitto MQTT broker, and benchmarked against a static PSK baseline over more than 6,500 encrypted packets per configuration. The results demonstrate nearly identical throughput and reliability, with minimal runtime impact (approximately 27 percent one-time session-establishment latency and 10 percent per-packet payload overhead), while delivering per-session key isolation (assuming the long-term secret remains uncompromised) and built-in replay protection. The PSK baseline and DSEKP datasets are publicly archived on IEEE DataPort to enable full reproducibility and comparative benchmarking. These findings confirm that dynamic symmetric rekeying can substantially strengthen IoT-Edge links with minimal computational and bandwidth cost, offering a practical migration path from static PSK to session-aware and scalable IoT security.
翻译:物联网(IoT)网络的激增需要一种能在不引入公钥密码学计算开销的前提下保护受限设备的安全机制。传统的预共享密钥(PSK)加密虽然高效,但由于静态密钥重用、重放攻击以及缺乏密钥新鲜度,仍存在安全漏洞。本文提出动态会话增强密钥协议(DSEKP),一种轻量级会话密钥重协商框架,该框架使用基于HMAC的密钥派生函数(HKDF-SHA256)生成每会话AES-GCM密钥,并通过一次初始化-确认交换中的HMAC证明完成会话建立的认证。DSEKP在ESP32物联网传感器节点与树莓派5边缘服务器上实现,通过Mosquitto MQTT代理进行通信,并在每种配置下对超过6,500个加密数据包进行了与静态PSK基线的性能对比测试。结果表明,DSEKP在吞吐量和可靠性方面与基线几乎相同,运行时开销极小(约27%的一次性会话建立延迟和10%的每数据包负载开销),同时实现了每会话密钥隔离(假设长期密钥未被泄露)和内置的重放攻击防护。PSK基线与DSEKP的数据集已公开存档于IEEE DataPort,以确保完全的可复现性和对比基准测试。这些发现证实,动态对称密钥重协商能以极小的计算和带宽成本显著增强物联网-边缘链路的安全性,为从静态PSK向会话感知、可扩展的物联网安全方案迁移提供了可行的路径。