The rapid proliferation of Internet of Things (IoT) devices in cloud-based e-learning platforms has posed significant security risks, particularly in protecting learner information, authentication of devices, and safe communication in the highly heterogeneous learning settings. Current cryptographic solutions are largely based on classical public-key infrastructure (PKI) protocols such as RSA and ECC, which will become vulnerable with the advent of large-scale quantum computers capable of executing Shor’s algorithm. In addition, traditional perimeter-based security models are inadequate for handling the dynamics, scattered, and resource-limited characteristics of IoT-enabled educational systems. As a solution to these problems, this paper introduces ZeroTrustEdu, a scalable zero-trust cryptographic solution that combines lightweight post-quantum key management with adaptive trust scoring of cloud-connected IoT e-learning infrastructure. The proposed framework makes three fundamental contributions namely: (1) a hierarchical zero-trust security model with no implicit trust, operating across device, edge, and cloud layers; (2) a lightweight key distribution protocol based on the Module-Lattice Key Encapsulation Mechanism (ML-KEM) compliant with NIST FIPS 203 standards and (3) an adaptive behavioral trust scoring engine that dynamically adjusts device and user trust levels based on real-time interaction analytics. The architecture is evaluated using extensive NS-3 network simulations with up to 100,000 concurrent IoT nodes with formal security analysis under Chosen Plaintext Attack (CPA) and Chosen Ciphertext Attack (CCA) threat models. Comparative evaluation against RSA-2048, ECC-P256, and AES-256 baselines demonstrates that, ZeroTrustEdu delivers a 62% ± 3% (95% CI, 10 independent runs) reduction in ML-KEM encapsulation latency (12.8 ms for key encapsulation/decapsulation, contributing to a complete device authentication latency of 47.3 ms including ML-DSA signature operations), 45% reduced communication overheads, and 38% reduction in energy consumption on ARM Cortex-M4 constrained devices compared to RSA-2048 and achieves provable post-quantum security reducible to the hardness of the Module Learning With Errors (MLWE) problem. These findings demonstrate that the proposed architecture provides a viable, scalable, and quantum-resilient security solution for next-generation IoT-enabled e-learning environments. The cryptographic security of ZeroTrustEdu is guaranteed at the primitive level through NIST-standardized ML-KEM (FIPS 203) and ML-DSA (FIPS 204), with IND-CCA2 and EUF-CMA security formally proven in the respective standards; full protocol-level formal verification using automated theorem provers (ProVerif, Tamarin) is identified as valuable future work to rule out protocol-composition vulnerabilities beyond primitive-level guarantees.
Weam Gaoud Alghabban (Fri,) studied this question.