Lightweight Cryptographic Framework for Secure Firmware Updates in Resource-Constrained IoT-Based Industrial Automation Systems
Keywords:
Industrial Internet of Things (IIoT), Secure Firmware Update, Lightweight Cryptography, Embedded Security, Industrial Automation, Over-the-Air UpdateAbstract
Industrial automation is increasingly reliant on Internet of Things (IoT) devices, such as programmable sensors, actuators, controllers, gateways, intelligent meters, motor-control units, and embedded monitoring systems. These devices often function for extended durations in geographically dispersed and operationally vital settings. Consequently, firmware updates are crucial for rectifying vulnerabilities, enhancing functionality, ensuring interoperability, and addressing newly identified threats. However, securely updating firmware in resource-limited industrial IoT environments poses challenges, as many embedded devices have restricted processor capacity, memory, storage, energy availability, and communication bandwidth. Traditional cryptographic methods can introduce substantial computational and storage burdens, while inadequate update mechanisms may leave industrial systems vulnerable to malicious firmware injection, rollback attacks, replay attacks, unauthorized modifications, interrupted updates, and denial-of-service situations.
This research introduces a Lightweight Cryptographic Firmware Update Framework (LCFUF) for secure over-the-air firmware updates in resource-constrained IoT-based industrial automation systems. The proposed framework incorporates lightweight authenticated encryption, compact digital signatures, cryptographic hashing, version control, anti-rollback protection, secure boot validation, chunk-level integrity verification, and fail-safe recovery. A hierarchical architecture is designed, comprising an update authority, industrial gateway, secure communication layer, embedded bootloader, verification engine, and protected firmware storage. The framework employs a hybrid cryptographic strategy, utilizing public-key cryptography mainly for update authorization and symmetric lightweight cryptography for efficient payload protection. This approach minimizes the costly use of asymmetric operations while maintaining robust authentication and integrity features.
The study employs a design-and-evaluation methodology. A prototype architecture is developed for representative constrained industrial devices and assessed against traditional heavyweight update schemes and a baseline static hybrid approach. The evaluation considers firmware verification time, cryptographic processing latency, memory consumption, communication overhead, energy usage, update success rate, and resilience against common firmware attacks. Experimental results demonstrate that the proposed framework can reduce average update-processing latency by approximately 32–46%, decrease cryptographic memory requirements by about 35–50%, and lower communication overhead through compact manifests and chunk authentication. The framework also offers protection against unauthorized firmware installation, tampering, replay, rollback, and incomplete-update failures.
The results indicate that lightweight cryptography should not be viewed merely as the use of smaller algorithms. Effective secure firmware updating necessitates the coordinated optimization of cryptographic primitives, metadata structures, trust anchors, bootloader behavior, communication protocols, and recovery mechanisms. The proposed framework provides a practical security architecture tailored to industrial IoT devices with limited resources. It also conceptually aligns with established IoT cybersecurity guidance and standardized firmware-update architectures, emphasizing software update capability, authenticated firmware, integrity protection, manifest-driven updates, and lifecycle security.
References
1. Fagan, M., Megas, K., Scarfone, K., & Smith, M. (2020). IoT Device Cybersecurity Capability Core Baseline. NIST Interagency or Internal Report 8259A. National Institute of Standards and Technology.
2. National Institute of Standards and Technology. (2026). NISTIR 8259 Series: IoT Cybersecurity Guidance for Device Manufacturers. NIST Cybersecurity for IoT Program.
3. Moran, B., Tschofenig, H., Brown, D., & Meriac, M. (2021). A Firmware Update Architecture for Internet of Things. RFC 9019. Internet Engineering Task Force.
4. Moran, B., Tschofenig, H., & Birkholz, H. (2022). A Manifest Information Model for Firmware Updates in Internet of Things (IoT) Devices. RFC 9124. Internet Engineering Task Force.
5. National Institute of Standards and Technology. (2026). IoT Device Cybersecurity Requirements Catalog. NIST Cybersecurity for IoT Program.
6. National Institute of Standards and Technology. (2018). Platform Firmware Resiliency Guidelines. NIST Special Publication 800-193.
7. National Institute of Standards and Technology. (2025). Security for IoT Device Manufacturers: NIST Guidance and Cybersecurity Capabilities. NIST Cybersecurity for IoT Program.
8. National Institute of Standards and Technology. (2026). Frequently Asked Questions for the NIST Cybersecurity for IoT Program. NIST.
9. National Institute of Standards and Technology. (2020). Recommendations for IoT Device Manufacturers and Federal IoT Cybersecurity Profiles. NIST.
10. Stallings, W. (2023). Cryptography and Network Security: Principles and Practice. Pearson.
11. Paar, C., & Pelzl, J. (2010). Understanding Cryptography: A Textbook for Students and Practitioners. Springer.
12. Kocher, P., Jaffe, J., & Jun, B. (1999). Differential Power Analysis. Advances in Cryptology—CRYPTO '99, 388–397.
13. Rescorla, E. (2018). The Transport Layer Security (TLS) Protocol Version 1.3. RFC 8446. Internet Engineering Task Force.
14. Eastlake, D., & Hansen, T. (2006). US Secure Hash Algorithms (SHA and HMAC-SHA). RFC 4634. Internet Engineering Task Force.
15. Roman, R., Zhou, J., & Lopez, J. (2013). On the Features and Challenges of Security and Privacy in Distributed Internet of Things. Computer Networks, 57(10), 2266–2279.
16. Sicari, S., Rizzardi, A., Grieco, L. A., & Coen-Porisini, A. (2015). Security, Privacy and Trust in Internet of Things: The Road Ahead. Computer Networks, 76, 146–164.
17. Alaba, F. A., Othman, M., Hashem, I. A. T., & Alotaibi, F. (2017). Internet of Things Security: A Survey. Journal of Network and Computer Applications, 88, 10–28.
18. Cha, S.-C., Hsu, T.-Y., Xiang, Y., & Yeh, K.-H. (2019). A Hierarchical Blockchain-Enabled Security Framework for IoT Systems. Sustainable Computing: Informatics and Systems, 21, 137–146.
19. Bormann, C., Ersue, M., & Keranen, A. (2014). Terminology for Constrained-Node Networks. RFC 7228. Internet Engineering Task Force.
20. National Institute of Standards and Technology. (2020–2026). NIST Cybersecurity for IoT Program: Technical and Manufacturer Capability Guidance. NIST.
Downloads
Published
Issue
Section
Categories
License
Copyright (c) 2026 International Journal of Computer Engineering and Embedded Technologies

This work is licensed under a Creative Commons Attribution 4.0 International License.
Licensing Terms
© 2026
International Journal of Computer Engineering and Embedded Technologies.
This is an open-access article distributed under the terms of the Creative Commons Attribution 4.0 International License (CC BY 4.0), which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.