{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,29]],"date-time":"2026-07-29T22:10:43Z","timestamp":1785363043925,"version":"3.55.0"},"reference-count":33,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2025,1,18]],"date-time":"2025-01-18T00:00:00Z","timestamp":1737158400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"National Science and Technology Council","award":["NSTC 113-2221-E-035-075"],"award-info":[{"award-number":["NSTC 113-2221-E-035-075"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>5G technology and IoT devices are improving efficiency and quality of life across many sectors. IoT devices are often used in open environments where they handle sensitive data. This makes them vulnerable to side-channel attacks (SCAs), where attackers can intercept and analyze the electromagnetic signals emitted by microcontroller units (MCUs) to expose encryption keys and compromise sensitive data. To address this critical vulnerability, this study proposes a novel dynamic key replacement mechanism specifically designed for lightweight IoT microcontrollers. The mechanism integrates Moving Target Defense (MTD) with a lightweight Diffie\u2013Hellman (D-H) key exchange protocol and AES-128 encryption to provide robust protection against SCAs. Unlike traditional approaches, the proposed mechanism dynamically updates encryption keys during each cryptographic cycle, effectively mitigating the risk of key reuse\u2014a primary vulnerability exploited in SCAs. The lightweight D-H key exchange ensures that even resource-constrained IoT devices can securely perform key exchanges without significant computational overhead. Experimental results demonstrate the practicality and security of the proposed mechanism, achieving key updates with minimal time overhead, ranging from 12 to 50 milliseconds per encryption transmission. Moreover, the approach shows strong resilience against template attacks, with only two out of sixteen AES-128 subkeys compromised after 20,000 attack attempts\u2014a notable improvement over existing countermeasures. The key innovation of this study lies in the seamless integration of MTD with lightweight cryptographic protocols, striking a balance between security and performance. This dynamic key replacement mechanism offers an effective, scalable, and resource-efficient solution for IoT applications, particularly in scenarios that demand robust protection against SCAs and low-latency performance.<\/jats:p>","DOI":"10.3390\/fi17010043","type":"journal-article","created":{"date-parts":[[2025,1,20]],"date-time":"2025-01-20T10:32:15Z","timestamp":1737369135000},"page":"43","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Dynamic Key Replacement Mechanism for Lightweight Internet of Things Microcontrollers to Resist Side-Channel Attacks"],"prefix":"10.3390","volume":"17","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-0847-4966","authenticated-orcid":false,"given":"Chung-Wei","family":"Kuo","sequence":"first","affiliation":[{"name":"Department of Information Engineering and Computer Science, Feng-Chia University, Taichung City 407, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Wei","sequence":"additional","affiliation":[{"name":"Department of Information Engineering and Computer Science, Feng-Chia University, Taichung City 407, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chun-Chang","family":"Lin","sequence":"additional","affiliation":[{"name":"Department of Information Engineering and Computer Science, Feng-Chia University, Taichung City 407, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu-Yi","family":"Hong","sequence":"additional","affiliation":[{"name":"Department of Information Engineering and Computer Science, Feng-Chia University, Taichung City 407, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jia-Ruei","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Information Engineering and Computer Science, Feng-Chia University, Taichung City 407, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kuo-Yu","family":"Tsai","sequence":"additional","affiliation":[{"name":"Department of Information Engineering and Computer Science, Feng-Chia University, Taichung City 407, Taiwan"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,1,18]]},"reference":[{"key":"ref_1","unstructured":"(2024, December 27). Global Cellular IoT Connections Surpassed 4 Billion in 2024, Driven by 5G and LTE Cat 1 Bis. Available online: https:\/\/iot-analytics.com\/global-cellular-iot-connections\/."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1109\/JETCAS.2021.3074608","article-title":"Power Side-Channel Attacks on BNN Accelerators in Remote FPGAs","volume":"11","author":"Moini","year":"2021","journal-title":"IEEE J. Emerg. Sel. Top. Circuits Syst."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"776","DOI":"10.1109\/TIFS.2019.2929018","article-title":"Electromagnetic Side Channel Information Leakage Created by Execution of Series of Instructions in a Computer Processor","volume":"15","author":"Yilmaz","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1930","DOI":"10.1109\/TVLSI.2021.3111407","article-title":"Applying Thermal Side-Channel Attacks on Asymmetric Cryptography","volume":"29","author":"Aljuffri","year":"2021","journal-title":"IEEE Trans. Very Large Scale Integr. (VLSI) Syst."},{"key":"ref_5","unstructured":"Schaumont, P., and Tiri, K. (2007, January 10\u201313). Masking and Dual-Rail Logic Don\u2019t Add Up. Proceedings of the Cryptographic Hardware and Embedded Systems (CHES 2007), Vienna, Austria."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Schramm, K., and Paar, C. (2006, January 13\u201317). Higher Order Masking of the AES. Proceedings of the Topics in Cryptology-CT-RSA 2006, San Jos\u00e9, CA, USA.","DOI":"10.1007\/11605805_14"},{"key":"ref_7","unstructured":"Baseri, Y., Chouhan, V., and Ghorbani, A. (2024). Cybersecurity in the Quantum Era: Assessing the Impact of Quantum Computing on Infrastructure. arXiv."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"100167","DOI":"10.1016\/j.chbr.2022.100167","article-title":"Hacker types, motivations and strategies: A comprehensive framework","volume":"5","author":"Chng","year":"2022","journal-title":"Comput. Hum. Behav. Rep."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Munoz, P.S., Tran, N., Craig, B., Dezfouli, B., and Liu, Y. (2018, January 12\u201315). Analyzing the Resource Utilization of AES Encryption on IoT Devices. Proceedings of the Asia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC 2018), Honolulu, HI, USA.","DOI":"10.23919\/APSIPA.2018.8659779"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Fatima, S., Rehman, T., Fatima, M., Khan, S., and Ali, M.A. (2022, January 25\u201326). Comparative Analysis of Aes and Rsa Algorithms for Data Security in Cloud Computing, In Proceedings of the 7th International Electrical Engineering Conference (IEEC 2022). Karachi, Pakistan.","DOI":"10.3390\/engproc2022020014"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Devi, M., and Majumder, A. (2021). Side-Channel Attack in Internet of Things: A Survey, In Applications of Internet of Things, Springer.","DOI":"10.1007\/978-981-15-6198-6_20"},{"key":"ref_12","first-page":"2546","article-title":"Enhanced Message Authentication Encryption Scheme Based on Physical-Layer Key Generation in Resource-Limited Internet of Things","volume":"18","author":"Xing","year":"2024","journal-title":"KSII Trans. Internet Inf. Syst. (TIIS)"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Rawat, J., Kumar, I., Mohd, N., Rana, K.K.S., Pathak, N., and Gupta, R.K. (2023, January 17\u201318). IoT-Based Home Automation System Using ESP8266. Proceedings of the International Conference on Innovative Computing and Communications (ICICC 2023), New Delhi, India.","DOI":"10.1007\/978-981-99-3315-0_53"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"1810","DOI":"10.1109\/JSYST.2019.2922589","article-title":"Moving Target Defense Mechanism for Side-Channel Attacks","volume":"14","author":"Vuppala","year":"2020","journal-title":"IEEE Syst. J."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Daemen, J., and Rijmen, V. (2020). The Design of Rijndael, Springer. [2nd ed.].","DOI":"10.1007\/978-3-662-60769-5"},{"key":"ref_16","first-page":"1","article-title":"Implementation and Analysis of Side-Channel Attack Mitigation Based on Autoencoder","volume":"29","author":"Kuo","year":"2023","journal-title":"Commun. CCISA"},{"key":"ref_17","unstructured":"(2023, July 23). Lightweight Cryptography Standardization Process: NIST Selects Ascon, Available online: https:\/\/csrc.nist.gov\/News\/2023\/lightweight-cryptography-nist-selects-ascon."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Kocher, P., Jaffe, J., and Jun, B. (1999, January 15\u201319). Differential Power Analysis. Proceedings of the Advances in Cryptology\u2014CRYPTO\u2019 99, Santa Barbara, CA, USA.","DOI":"10.1007\/3-540-48405-1_25"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Brier, E., Clavier, C., and Olivier, F. (2004, January 11\u201313). Correlation Power Analysis with a Leakage Model. Proceedings of the Cryptographic Hardware and Embedded Systems\u2014CHES 2004, Cambridge, MA, USA.","DOI":"10.1007\/978-3-540-28632-5_2"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Messerges, T.S. (2000, January 17\u201318). Using Second-Order Power Analysis to Attack DPA Resistant Software. Proceedings of the Cryptographic Hardware and Embedded Systems\u2014CHES 2000, Worcester, MA, USA.","DOI":"10.1007\/3-540-44499-8_19"},{"key":"ref_21","first-page":"1","article-title":"Side-Channel Attacks and Countermeasures for Identity-Based Cryptographic Algorithm SM9","volume":"2018","author":"Zhang","year":"2018","journal-title":"Secur. Commun. Netw."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","article-title":"New Directions in Cryptography","volume":"22","author":"Diffie","year":"1976","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Santoso, F.K., and Vun, N.C.H. (2015, January 24\u201326). Securing IoT for smart home system. Proceedings of the International Symposium on Consumer Electronics (ISCE 2015), Madrid, Spain.","DOI":"10.1109\/ISCE.2015.7177843"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"2988","DOI":"10.1109\/JSAC.2015.2481203","article-title":"A Novel Energy Management Approach for Smart Homes Using Bluetooth Low Energy","volume":"33","author":"Collotta","year":"2015","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1221","DOI":"10.1109\/TCE.2009.5277979","article-title":"InfoPods: Zigbee-Based Remote Information Monitoring Devices for Smart-Homes","volume":"55","author":"Zualkernan","year":"2009","journal-title":"IEEE Trans. Consum. Electron."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"146348","DOI":"10.1109\/ACCESS.2019.2941972","article-title":"Low-Power AES Data Encryption Architecture for a LoRaWAN","volume":"7","author":"Tsai","year":"2019","journal-title":"IEEE Access"},{"key":"ref_27","unstructured":"Mangard, S., Oswald, E., and Popp, T. (2007). Power Analysis Attacks, Springer. [1st ed.]."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1109\/TVLSI.2021.3073946","article-title":"Physical attack protection techniques for IC chip level hardware security","volume":"30","author":"Nagata","year":"2022","journal-title":"IEEE Trans. Very Large Scale Integr. (VLSI) Syst."},{"key":"ref_29","unstructured":"Bogdanov, A., Knudsen, L.R., Leander, G., Paar, C., Poschmann, A., Robshaw, M.J.B., Seurin, Y., and Vikkelsoe, C. (2007, January 10\u201313). PRESENT: An ultra-lightweight block cipher. Proceedings of the Cryptographic Hardware and Embedded Systems\u2014CHES 2007: 9th International Workshop, Vienna, Austria."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"45325","DOI":"10.1109\/ACCESS.2018.2852563","article-title":"AES-128 based secure low power communication for LoRaWAN IoT environments","volume":"6","author":"Tsai","year":"2018","journal-title":"IEEE Access"},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Kuo, C.W., Lin, C.C., Hong, Y.Y., Liu, J.R., Yeh, C.H., and Tsai, K.Y. (2024, January 20\u201322). Research and Analysis of the Effects of Different Shielding Materials on Resisting Side-Channel Attacks on IoT Device Microcontroller. Proceedings of the 8th International Conference on Cryptography, Security and Privacy (CSP 2024), Osaka, Japan.","DOI":"10.1109\/CSP62567.2024.00021"},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Peng, S.Y., Hong, W.C., Li, J.T., and Huang, S.J. (2018, January 13\u201317). Framework for efficient SCA resistance verification of IoT devices. Proceedings of the IEEE International Conference on Applied System Invention (ICASI 2018), Chiba, Japan.","DOI":"10.1109\/ICASI.2018.8394287"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"413","DOI":"10.46586\/tches.v2022.i3.413-437","article-title":"The best of two worlds: Deep learning-assisted template attack","volume":"3","author":"Wu","year":"2022","journal-title":"IACR Trans. Cryptogr. Hardw. Embed. Syst."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/1\/43\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T10:31:26Z","timestamp":1759919486000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/1\/43"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,18]]},"references-count":33,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,1]]}},"alternative-id":["fi17010043"],"URL":"https:\/\/doi.org\/10.3390\/fi17010043","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,18]]}}}