Abstract Resource-constrained IoT devices require secure communication protocols that minimize both latency and energy consumption while maintaining cryptographic security guarantees. This paper presents a hardware-accelerated implementation of TLS 1. 3 with 0-RTT (zero round-trip time) session resumption for IoT devices using ARM CryptoCell-310 cryptographic acceleration. Our implementation addresses the fundamental challenge of enabling immediate encrypted communication upon reconnection without sacrificing forward secrecy or replay protection. The system leverages hardware-isolated key derivation, temporal nonce validation, and efficient PSK caching to achieve sub-100 ms connection establishment while maintaining security properties equivalent to full TLS 1. 3 handshakes after ephemeral key exchange completion. Experimental evaluation with 30 nRF9161 devices equipped with integrated CryptoCell-310 demonstrates average connection establishment latency of 73ms (standard deviation 8. 2 ms), representing an 87% reduction compared to full TLS 1. 3 handshakes. Hardware acceleration provides 4. 2× speedup over software-only cryptographic operations for PSK derivation (45 ms vs 190 ms. Our replay protection mechanism using hardware-accelerated nonce validation adds only 12 ms overhead while preventing replay attacks with probability greater than 1–2^-64. The implementation achieves forward secrecy through rapid ephemeral key exchange within the first 100 ms of connection, with hardware-enforced key zeroization preventing recovery of early traffic keys even under device compromise scenarios. Security analysis demonstrates resilience against network-level adversaries performing eavesdropping, replay attacks, and man-in-the-middle attacks, with formal treatment of cryptographic properties including confidentiality, integrity, authenticity, and forward secrecy. Performance comparisons with existing 0-RTT implementations show competitive latency characteristics while providing stronger security guarantees through hardware key isolation. The implementation provides practical evidence that resource-constrained IoT devices can support 0-RTT TLS with full security properties when cryptographic operations are hardware-accelerated and carefully optimized for power efficiency.
Minasyan et al. (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: