IMACO: A Security-Floor-Constrained Adaptive Cryptography Framework for Constrained CoAP-Class IoT

Adnan H. Al-Helali, Judy Ammar Jaradat · Zenodo (CERN European Organization for Nuclear Research) · 2026

Constrained CoAP-class Internet of Things (IoT) devices, including deployments protected by OSCORE, must maintain authenticated protection while operating under changing energy, memory, latency, and packet overhead limits. Controller-driven adaptation may improve efficiency, but it can also create a security-downgrade path when a gateway influences the selection decision. This study proposes IMACO, a security-floor-constrained adaptive cryptography framework that keeps final authority on the endpoint. The method stores a small, signed catalog of approved authenticated encryption profiles, assigns each profile a security label and predicted resource costs, filters candidates against a locally enforced security floor and current device budgets, and ranks only the remaining safe and feasible profiles. Gateway observations may refine cost or utility estimates but cannot modify the local floor or profile labels. Formal analysis under a network adversary that may control the gateway shows that every profile returned by the selector satisfies the device's minimum-security requirement. Cost-estimation errors may reduce efficiency or availability, but they do not authorize selection below the floor; when no safe feasible profile exists, the device uses a signed fallback or suspends the protected service. These results establish a clear separation between security enforcement and performance optimization. The framework therefore provides a defensible basis for future Contiki-NG and Cooja experiments measuring energy, latency, memory, packet overhead, and adaptation behavior.

Read the paper · More papers on PaperTik