IMACO: A Security-Floor-Constrained Adaptive Cryptography Framework for Constrained CoAP-Class IoT | IJCT Volume 13 – Issue 4 | IJCT-V13I4P28

IJCT
International Journal of Computer Techniques
ISSN 2394-2231 · Peer-Reviewed · Open Access
📚 Volume 13, Issue 4
📅 August 24, 2026
📄 Pages 276–286
🔖 ID: IJCT-V13I4P28

IMACO: A Security-Floor-Constrained Adaptive Cryptography Framework for Constrained CoAP-Class IoT

Author(s)

Adnan H. Al-Helali, Judy Ammar Jaradat

Abstract

Constrained CoAP-class Internet of Things (IoT) devices, including deployments protected by OSCORE, must maintain authenticated protection while operating under changing energy, memory, latency, and packet overhead limits. Controller-driven adaptation may improve efficiency, but it can also create a security-downgrade path when a gateway influences the selection decision. This study proposes IMACO, a security-floor-constrained adaptive cryptography framework that keeps final authority on the endpoint. The method stores a small, signed catalog of approved authenticated encryption profiles, assigns each profile a security label and predicted resource costs, filters candidates against a locally enforced security floor and current device budgets, and ranks only the remaining safe and feasible profiles. Gateway observations may refine cost or utility estimates but cannot modify the local floor or profile labels. Formal analysis under a network adversary that may control the gateway shows that every profile returned by the selector satisfies the device’s minimum-security requirement. Cost-estimation errors may reduce efficiency or availability, but they do not authorize selection below the floor; when no safe feasible profile exists, the device uses a signed fallback or suspends the protected service. These results establish a clear separation between security enforcement and performance optimization. The framework therefore provides a defensible basis for future Contiki-NG and Cooja experiments measuring energy, latency, memory, packet overhead, and adaptation behavior.

Keywords

IoT Crypto-agility; downgrade resistance; security protocols; authenticated profile switching; AEAD; post quantum migration; software prototype

Conclusion

IMACO is an effective solution to the practical trust question of how an IoT node can use gateway suggestions while protecting itself against link-time downgrades. The node constructs the safe set, then ranks only safe profiles by increasing measured cost and authenticates profile changes by policy binding, monotonic epochs, fresh key derivation, and acknowledgement binding. The executable prototype rejected all downgrade attempts, switch replays, profile-ID forgeries, ciphertext modifications, or data replays in 1000 trials per category; the unsafe baseline accepted all downgrade recommendations. In the same trial, it did not show any measurable improvement in throughput over a static P3: at 1962 bps versus 2047 bps, IMACO was 1.75% slower on average, and the 95% confidence interval included zero. The best interpretation of these results is that IMACO provides at least one downgrade-resistant option while not compromising on other performance guarantees. Microcontroller power measurements, formal verification, compact encoding optimizations, and standards compliance are worthwhile avenues for future work.

References

[1] M. S. Turan, K. McKay, J. Kang, J. Kelsey, and D. Chang, Ascon-Based Lightweight Cryptography Standards for Constrained Devices:
Authenticated Encryption, Hash, and Extendable Output Functions, NIST SP 800-232, Aug. 2025, doi: 10.6028/NIST.SP.800-232.
[2] C. Dobraunig, M. Eichlseder, F. Mendel, and M. Schläffer, ‘Ascon v1.2: Lightweight Authenticated Encryption and Hashing,’ Journal of
Cryptology, vol. 34, art. 33, 2021, doi: 10.1007/s00145-021-09398-9.
[3] National Institute of Standards and Technology, Advanced Encryption Standard (AES), FIPS 197-upd1, May 2023, doi:
10.6028/NIST.FIPS.197-upd1.
[4] M. Dworkin, Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC, NIST SP 800-38D, Nov.
2007, doi: 10.6028/NIST.SP.800-38D.
[5] Y. Nir and A. Langley, ChaCha20 and Poly1305 for IETF Protocols, RFC 8439, Jun. 2018, doi: 10.17487/RFC8439.
[6] G. Selander, J. Mattsson, F. Palombini, and L. Seitz, Object Security for Constrained RESTful Environments (OSCORE), RFC 8613, Jul.
2019, doi: 10.17487/RFC8613.
[7] G. Selander, J. Preuß Mattsson, and F. Palombini, Ephemeral Diffie-Hellman Over COSE (EDHOC), RFC 9528, Mar. 2024, doi:
10.17487/RFC9528.
[8] E. Rescorla, H. Tschofenig, and N. Modadugu, The Datagram Transport Layer Security (DTLS) Protocol Version 1.3, RFC 9147, Apr. 2022,
doi: 10.17487/RFC9147.
[9] M. Gunnarsson, J. Brorsson, F. Palombini, L. Seitz, and M. Tiloca, ‘Evaluating the performance of the OSCORE security protocol in
constrained IoT environments,’ Internet of Things, vol. 13, art. 100333, 2021, doi: 10.1016/j.iot.2020.100333.
[10] S. Hristozov, M. Huber, L. Xu, J. Fietz, M. Liess, and G. Sigl, ‘The Cost of OSCORE and EDHOC for Constrained Devices,’ in Pro
c. 11th ACM Conference on Data and Application Security and Privacy (CODASPY), 2021, pp. 245-250, doi: 10.1145/3422337.3447834.
[11] C. Jacomme, E. Klein, S. Kremer, and M. Racouchot, ‘A comprehensive, formal and automated analysis of the EDHOC protocol,’ in Proc.
32nd USENIX Security Symposium, 2023, pp. 5881-5898.
[12] U. Farooq, N. U. Hasan, I. Baig, and N. Shehzad, ‘Efficient adaptive framework for securing the Internet of Things devices,’ EURASIP
Journal on Wireless Communications and Networking, vol. 2019, art. 210, 2019, doi: 10.1186/s13638-019-1531-0.
[13] E. Gilliard and J. Liu, ‘CALIS: AI-driven context-aware encryption for SDN-enabled smart-home IoT,’ Journal of King Saud University –
Computer and Information Sciences, 2026, doi: 10.1007/s44443-025-00404-9.
[14] A. Alsirhani, S. Ali, and M. Humayun, ‘CAEM-ESAC: context-aware encryption model for enhancing security and access control through
contextual factors,’ Cluster Computing, 2026, doi: 10.1007/s10586-026-06241-3.
[15] P. Sundaravadivel, R. A. Isaac, K. Premnath, and C. H. Vasanth Kumar, ‘Adaptive encryption and transmission in Lora networks using
reinforcement learning for effective security of IOT devices in end-to-end transmission,’ Discover Artificial Intelligence, 2026, doi:
10.1007/s44163-026-01400-2.
[16] M. Gunnarsson, K. M. Malarski, R. Höglund, and M. Tiloca, ‘Performance Evaluation of Group OSCORE for Secure Group Communication
in the Internet of Things,’ ACM Transactions on Internet of Things, vol. 3, no. 3, art. 19, 2022, doi: 10.1145/3523064.
[17] M. S. Turan et al., Status Report on the Final Round of the NIST Lightweight Cryptography Standardization Process, NIST IR 8454, Jun.
2023, doi: 10.6028/NIST.IR.8454.
[18] R. Kalaria, A. S. M. Kayes, W. Rahayu, E. Pardede, and A. S. Shahraki, ‘Adaptive context-aware access control for IoT environments
leveraging fog computing,’ International Journal of Information Security, vol. 23, no. 4, pp. 3089-3107, 2024, doi: 10.1007/s10207-024
00866-4.
[19] J. Schaad, CBOR Object Signing and Encryption (COSE): Initial Algorithms, RFC 9053, Aug. 2022, doi: 10.17487/RFC9053.
[20] Z. Shelby, K. Hartke, and C. Bormann, The Constrained Application Protocol (CoAP), RFC 7252, Jun. 2014, doi: 10.17487/RFC7252.
[21] A. Langley, M. Hamburg, and S. Turner, Elliptic Curves for Security, RFC 7748, Jan. 2016, doi: 10.17487/RFC7748.
[22] S. Josefsson and I. Liusvaara, Edwards-Curve Digital Signature Algorithm (EdDSA), RFC 8032, Jan. 2017, doi: 10.17487/RFC8032.

📋 How to Cite This Paper

Adnan H. Al-Helali, Judy Ammar Jaradat (2026). IMACO: A Security-Floor-Constrained Adaptive Cryptography Framework for Constrained CoAP-Class IoT. International Journal of Computer Techniques, 13(4), 276–286. ISSN: 2394-2231. DOI: https://doi.org/10.5281/zenodo.22083850
© 2026 International Journal of Computer Techniques (IJCT). All rights reserved. · ijctjournal.org
Submit Your Paper