A Decentralized, Lightweight, and Resilient Group Key Agreement Protocol Using Shamir Secret Sharing and Hash-Based Message Authentication Code for IoT Devices

Kavya Sri Yakkala, Naga Mohith Reddy Konireddy, Kavita Agrawal, Suresh Chittineni, P. V. G. D. Prasad Reddy · 2025

The Internet of Things is rapidly expanding and the need for lightweight and secure communication protocols is paramount, especially in resource-constrained environments. Current approaches like centralized key management approaches provide strong security but require very high computation resources or rely on a single entity for key management making them prone to single points of failure. Alternative symmetric encryption methods are much more efficient, but they do not include sufficient measures of authentication and are not tamper-resistant. To tackle these, we propose a decentralized, lightweight, and resilient group key agreement protocol based on Shamir Secret Sharing Scheme (SSS) and Hash-Based Message Authentication Code (HMAC) to create secure communication in IoT networks. The proposed design eliminates the need for third-party authority, such that no single device holds the entire group key, which reduces vulnerability. Reconstruction based on threshold and integrity validation based on HMAC provides fault tolerance and secure, tamper-proof communication over distributed IoT networks. The results prove that computational overhead is decreased while ensuring seamless group key integrity, which fits very well with the IoT’s strict requirements for efficiency and resilience.

Read the paper · More papers on PaperTik