Paper 2025/2021
TreeCast: Multi-Party Key Establishment Protocol for IoT Devices
Abstract
Secure communication in the Internet of Things (IoT) requires lightweight protocols that scale across unicast, multicast, and broadcast settings. Existing solutions typically depend on centralized gateways, which introduce single points of failure and scalability limitations. We propose TreeCast, a distributed group key establishment protocol that organizes devices into a binary tree of hashed Diffie–Hellman secrets, which naturally unifies unicast, multicast, and broadcast in a single scalable hierarchical structure. This design yields logarithmic rekey costs, efficient subtree derivation with efficient device addition and revocation in large and dynamic IoT environments and strong security properties including authentication, partial forward secrecy, and post-compromise recovery. We present a detailed security analysis and to demonstrate practical viability, implement TreeCast on an Arm Cortex-M33 using only software cryptography, without any hardware accelerators. Our measurements show that TreeCast performs key establishment and rekeying within realistic IoT timing and energy budgets, achieving sub-millisecond tree updates and low memory footprint. These results establish TreeCast as a lightweight, scalable, and deployable solution for secure communication in next-generation IoT networks.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. Major revision. ICICS 2026
- Keywords
- Tree-based Group Key EstablishmentIoT SecurityDecentralized Key EstablishmentUnicastMulticastBroadcast
- Contact author(s)
-
supriyobanerjee537 @ gmail com
Sayon Duttagupta @ esat kuleuven be - History
- 2026-09-05: revised
- 2025-10-30: received
- See all versions
- Short URL
- https://ia.cr/2025/2021
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2021,
author = {Supriyo Banerjee and Sayon Duttagupta},
title = {{TreeCast}: Multi-Party Key Establishment Protocol for {IoT} Devices},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2021},
year = {2025},
url = {https://eprint.iacr.org/2025/2021}
}