Paper 2025/1735

Edge Encryption using Iterative Management Framework

Manoja Shridhar, Michigan State University
Bala Puruvana, Michigan State University
Alex Cravill, Ohio State University
Joey Wolff, Ohio State University
Abstract

Securing data in heterogeneous, latency-sensitive edge environments demands encryption that adapts to device churn, intermittent connectivity, and evolving threat models without sacrificing real-time performance. We present an Iterative Management Framework (IMF) for edge encryption that closes the loop between policy intent, cryptographic configuration, runtime telemetry, and automated remediation. IMF organizes encryption management as a continuous control cycle—model, deploy, observe, and refine—spanning device, edge-cluster, and cloud control planes. Concretely, IMF (i) encodes encryption policies as declarative, verifiable profiles; (ii) performs constraint-aware rollout and staged key rotation using topology- and load-aware schedulers; (iii) leverages streaming telemetry (cryptographic error rates, handshake retries, path RTT, and drift in device trust scores) to trigger bounded updates; and (iv) resolves conflicts via policy iteration with formal safety checks to prevent downgrade, orphaned keys, or split-brain trust roots. The framework supports heterogeneous primitives—including AEAD ciphers, forward-secure rekeying, TEE/HSM-anchored key custody, and post-quantum negotiation—while tolerating partial connectivity through opportunistic convergence and cryptographic state caching at the edge. In a prototype across 1,200 edge nodes, IMF sustained line-rate encryption with ≤1.8% median throughput overhead and <35 ms p95 added latency during rolling rekeys, reduced key-exposure windows by 57% via adaptive rotation, and cut control traffic by 41% using differential rollout plans. These results indicate that iterative, telemetry-driven management can deliver robust encryption at the edge while preserving tight performance envelopes.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Keywords
mutual TLSencryptionedge computingperformancekey management
Contact author(s)
manoja sridh @ gmail com
bala puruvana @ msu edu
alex c @ osu edu
j wolff @ gmail com
History
2025-09-24: revised
2025-09-23: received
See all versions
Short URL
https://ia.cr/2025/1735
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/1735,
      author = {Manoja Shridhar and Bala Puruvana and Alex Cravill and Joey Wolff},
      title = {Edge Encryption using Iterative Management Framework},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/1735},
      year = {2025},
      url = {https://eprint.iacr.org/2025/1735}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.