An adaptive, hybrid, and lightweight cryptography system for optimized IoT security and performance.

The hybrid M-AES/ECC cryptographic system with a reinforcement learning agent optimizes IoT security by dynamically adjusting encryption parameters, addressing inefficiencies in conventional methods and improving energy efficiency and threat detection in IoT devices.

DE202025106725U1Active Publication Date: 2026-02-26GHARAT NEHA MUMBAI +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE202025106725
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2025-11-06
Publication Date
2026-02-26
Estimated Expiration
2035-11-30

AI Technical Summary

Technical Problem

Conventional cryptographic mechanisms are inefficient for IoT devices due to high computational effort and energy consumption, and existing resource-efficient methods lack adaptability to dynamic IoT conditions, leading to over-provisioning or under-provisioning of resources.

Method used

A hybrid cryptographic system combining Modified Advanced Encryption Standard (M-AES) with Elliptic Curve Cryptography (ECC) and a reinforcement learning security agent that dynamically adjusts encryption parameters based on device trust, network conditions, and power availability.

Benefits of technology

The system achieves adaptive cryptographic strength and resource efficiency, reducing energy consumption and computational overhead while maintaining robust security, enhancing threat detection and resilience in dynamic IoT environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

An adaptive, hybrid, and resource-efficient crypto system for optimized IoT security and performance, consisting of: a variety of IoT devices; The IoT gateway is communicatively connected to the multitude of IoT devices; a trust assessment module configured to calculate trust scores for each IoT device in real time based on anomaly detection results, historical security events, energy consumption patterns, and network activity patterns; a modified Advanced Encryption Standard (M-AES) encryption module configured to perform encryption operations using an XOR triplet diffusion mechanism consisting of four XOR operations that combine different bytes of state data to achieve diffusion; an Elliptic Curve Cryptography (ECC) module configured to perform Elliptic Curve Diffie-Hellman key exchange operations for secure key generation; A Reinforcement Learning Security Agent (RLSA) module configured to: monitor a multidimensional state space encompassing the power level, network load, trust level, and key age of IoT devices; select actions from an action space that includes maintaining current encryption keys, initiating key rotation, and changing encryption strength; optimize security configurations using the Q-Learning algorithm with a reward function that balances security benefits and energy consumption; a key management module configured to perform dynamic key rotation based on trust values ​​and energy thresholds determined by the reinforcement learning security agent; and a communication interface configured to enable encrypted data transmission between IoT devices and the IoT gateway using the hybrid cryptographic operations M-AES and ECC.
Need to check novelty before this filing date? Find Prior Art

Description

AREA OF INVENTION

[0001] The present disclosure relates to an adaptive, hybrid, and resource-efficient cryptosystem for optimizing security and performance in the Internet of Things (IoT). In particular, the invention relates to an optimized, extended hybrid cryptosystem that combines the Modified Advanced Encryption Standard (M-AES) with Elliptic Curve Cryptography (ECC) and is optimized in real time for IoT security by means of a reinforcement learning (RL) agent. BACKGROUND OF THE INVENTION

[0002] The Internet of Things (IoT) connects smart devices such as household appliances, industrial machinery, vehicles, and sensor networks. These devices operate in a wide variety of environments and perform functions such as real-time monitoring, autonomous control, and decision support. With the expansion of IoT networks, the security and privacy of transmitted data have become central concerns, particularly in areas such as healthcare, smart infrastructure, and industrial automation.

[0003] While conventional cryptographic mechanisms are effective in traditional computer systems, they reach their limits in IoT applications due to the limited resources of IoT devices. The high computational effort and energy consumption of conventional algorithms such as Advanced Encryption Standard (AES) and Rivest-Shamir-Adleman (RSA) make them unsuitable for real-time IoT applications where computing power, storage capacity, and power availability are limited.

[0004] To address these limitations, resource-efficient cryptographic methods such as SPECK, PRESENT, and Ascon have been proposed. While these methods reduce computational and energy costs, they are designed for fixed-strength configurations and cannot adapt to changing operating and environmental conditions. Therefore, statically allocating cryptographic strength either leads to over-provisioning of resources, causing inefficiency, or under-provisioning, resulting in inadequate protection as threats increase.

[0005] Hybrid cryptographic solutions have also been investigated, such as combinations of AES with elliptic curve cryptography (ECC). However, these approaches are implemented in static configurations and do not respond to the dynamic conditions of IoT environments, such as fluctuating power reserves, variable network traffic, and changing device trustworthiness. In such systems, a uniform encryption strength is applied regardless of the real-time conditions of the devices or the security requirements.

[0006] Previous work on reinforcement learning in IoT security has primarily focused on anomaly and intrusion detection. The dynamic optimization of cryptographic parameters for IoT devices has not been considered in this work. Therefore, existing resource-efficient cryptographic systems lack the ability to adaptively adjust security strength and resource efficiency to the specific device and network conditions.

[0007] The preceding discussion clearly demonstrates the need for a cryptographic framework that is resource-efficient, flexible, and context-sensitive, and capable of dynamically adjusting its cryptographic strength to balance resource utilization and security requirements. This framework must integrate robust encryption algorithms with adaptive mechanisms that consider device trust levels, network traffic conditions, and power availability in real time. The present invention addresses these limitations through a hybrid cryptographic system that combines a modified Advanced Encryption Standard (AES) with Elliptic Curve Cryptography (ECC). This system is connected to a trust-aware reinforcement learning agent that optimizes cryptographic parameters in real time based on the contextual conditions of IoT devices. SUMMARY OF THE INVENTION

[0008] This disclosure relates to an adaptive, hybrid, and resource-efficient cryptographic system for optimized security and performance in the Internet of Things (IoT). The system integrates a modified Advanced Encryption Standard (M-AES) with Elliptic Curve Cryptography (ECC) and is dynamically optimized for IoT applications by a reinforcement learning security agent. Instead of the conventional MixColumns transformation, the system uses an XOR triplet diffusion mechanism to reduce computational complexity while maintaining cryptographic strength. A trust evaluation module continuously assesses device reliability, and a reinforcement learning agent adaptively adjusts the encryption parameters based on real-time contextual variables such as power level, network load, trust values, and key age to achieve an optimal balance between security and resource efficiency.

[0009] One objective of this disclosure is to provide an adaptive, hybrid, and resource-efficient cryptography system for optimized IoT security and performance. The system comprises: multiple IoT devices; an IoT gateway that communicates with these IoT devices; a trust scoring module that calculates real-time trust scores for each IoT device based on anomaly detection results, historical security events, energy consumption patterns, and network activity patterns; a modified Advanced Encryption Standard (M-AES) encryption module that performs encryption operations using an XOR triplet diffusion mechanism comprising four XOR operations that combine different bytes of state data to achieve diffusion; and an Elliptic Curve Cryptography (ECC) module that performs Elliptic Curve Diffie-Hellman key exchange operations for secure key generation.A Reinforcement Learning Security Agent (RLSA) module that includes: monitoring the multidimensional state space encompassing energy levels, network load, trust levels, and key age of IoT devices; selecting actions from an action space that includes maintaining current encryption keys, initiating key rotation, and changing encryption strength; optimizing security configurations using a Q-learning algorithm with a reward function that balances security benefits and energy consumption; and a key management module configured to perform dynamic key rotation based on trust levels and energy thresholds determined by the Reinforcement Learning Security Agent.and a communication interface configured to enable encrypted data transmission between IoT devices and the IoT gateway using the hybrid cryptographic operations M-AES and ECC.

[0010] The purpose of this disclosure is to provide an adaptive, hybrid, and resource-efficient cryptography system for optimized IoT security and performance.

[0011] Another objective of the present disclosure is to provide an adaptive cryptographic framework that dynamically balances security strength and resource efficiency in real time based on context variables of IoT devices, thereby eliminating the limitations of static encryption approaches.

[0012] Another objective of the present disclosure is to reduce energy consumption and computational effort in resource-constrained IoT environments while maintaining robust security through a modified AES algorithm using resource-saving XOR triplet diffusion mechanisms.

[0013] Another objective of the present disclosure is the implementation of intelligent, threat-aware security management using reinforcement learning algorithms that continuously optimize cryptographic parameters based on device trust ratings and environmental conditions.

[0014] To further clarify the advantages and features of the present disclosure, the invention is described in more detail with reference to specific embodiments illustrated in the accompanying drawings. It is understood that these drawings merely show typical embodiments of the invention and are therefore not to be understood as limiting its scope of protection. The invention is described and explained in more detail and with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE IMAGES

[0015] These and other features, aspects and advantages of the present disclosure will be better understood when the following detailed description is read with reference to the accompanying drawings, in which identical symbols represent identical parts, wherein: Fig.Figure 1 shows a block diagram of an adaptive, hybrid and resource-efficient cryptographic system for optimized IoT security and performance according to an embodiment of the present disclosure; Fig. Figure 2 shows a block diagram illustrating the implementation of reinforcement learning on a Raspberry Pi 3 B+ according to an embodiment of the present disclosure; and Fig. Figure 3 shows a table with the results of hybrid cryptography using a modified AES 128+ ECC 256-bit key according to an embodiment of the present disclosure.

[0016] Furthermore, those skilled in the art will recognize that the elements in the drawings are simplified and not necessarily drawn to scale. For example, the flowcharts illustrate the process by highlighting the main steps to facilitate understanding of this disclosure. With regard to the construction of the device, one or more components may be represented in the drawings by conventional symbols. The drawings may show only those specific details relevant to understanding the embodiments of this disclosure, so as not to clutter the drawings with details that are already apparent to those skilled in the art from the description contained herein. DETAILED DESCRIPTION:

[0017] To facilitate understanding of the principles of the invention, reference is made below to the embodiment illustrated in the drawings, which is described using specific terms. It is understood, however, that this does not limit the scope of protection of the invention. Rather, modifications and further developments of the illustrated system, as well as further applications of the inventive principles depicted therein, are conceivable, insofar as they would typically occur to a person skilled in the art in the field of the invention.

[0018] It will be clear to those skilled in the art that the foregoing general description and the following detailed description are exemplary and explanatory of the invention and are not to be understood as a limitation thereof.

[0019] References to “an aspect”, “another aspect”, or similar phrases in this description mean that a particular feature, structure, or property described in connection with the embodiment is included in at least one embodiment of the present disclosure. Therefore, phrases such as “in one embodiment”, “in another embodiment”, and similar expressions in this description may, but do not necessarily, all refer to the same embodiment.

[0020] The terms "includes," "comprehensive," or similar expressions denote non-exclusive inclusion. Thus, a procedure or method containing a list of steps does not only include those steps but may also include further steps not explicitly listed or inherent in the procedure or method. Likewise, the statement "includes..." for one or more devices, subsystems, elements, structures, or components, without further limitations, does not preclude the existence of other devices, subsystems, elements, structures, or components.

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meanings generally known to those skilled in the art in the field to which this invention belongs. The systems, methods, and examples described herein serve only for illustration and are not to be understood as limiting.

[0022] Embodiments of the present disclosure are described in detail below with reference to the accompanying drawings.

[0023] The functional units described in this specification are referred to as devices. A device may be implemented in programmable hardware such as processors, digital signal processors, central processing units, FPGAs, PALs, PLDs, cloud processing systems, or similar. Devices may also be implemented in software for execution by various processor types. An identified device may contain executable code and, for example, comprise one or more physical or logical blocks of computer instructions, which may be organized as an object, procedure, function, or other construct. However, the executable files of an identified device need not be physically related; they may consist of different instructions stored in different locations that, when logically combined, constitute the device and fulfill its purpose.

[0024] The executable code of a device or module can consist of a single instruction or multiple instructions and can even extend across different code sections, applications, and storage media. Similarly, operational data within the device can be identified and represented, and can exist in any suitable form and be organized in any data structure. The operational data can be captured as a single data record or distributed across various storage media and may exist, at least partially, as electronic signals within a system or network.

[0025] References to “a selected embodiment”, “an embodiment”, or “an embodiment” in this description mean that a particular feature, structure, or property described in connection with the embodiment is included in at least one embodiment of the disclosed subject matter. Therefore, the phrases “a selected embodiment”, “in an embodiment”, or “in an embodiment” appearing at different points in this description do not necessarily refer to the same embodiment.

[0026] Furthermore, the described features, structures, or properties can be combined in one or more embodiments in any suitable manner. The following description contains numerous specific details to enable a comprehensive understanding of the embodiments of the disclosed subject matter. However, a person skilled in the art will recognize that the disclosed subject matter can also be realized without one or more of the specific details or with other methods, components, materials, etc. In other cases, known structures, materials, or processes are not presented or described in detail so as not to obscure aspects of the disclosed subject matter.

[0027] According to the exemplary embodiments, the disclosed computer programs or modules can be executed in a variety of ways, for example, as an application running in the memory of a device or as a hosted application running on a server and communicating with the device application or browser via various standard protocols such as TCP / IP, HTTP, XML, SOAP, REST, JSON, and other suitable protocols. The disclosed computer programs can be written in programming languages ​​that run either in the device's memory or on a hosted server, such as BASIC, COBOL, C, C++, Java, Pascal, or scripting languages ​​such as JavaScript, Python, Ruby, PHP, Perl, or other suitable programming languages.

[0028] Some of the described embodiments involve data transmission over a network, such as the transmission of various inputs or files. The network may include, for example, the internet, wide area networks (WANs), local area networks (LANs), analog or digital wired and wireless telephone networks (e.g., PSTN, ISDN, cellular networks, and xDSL), radio, television, cable, satellite, and / or other transmission or tunneling mechanisms for data. It may include multiple networks or subnetworks, each of which may, for example, have a wired or wireless data path. The network may include a circuit-switched voice network, a packet-switched data network, or another network for transmitting electronic data. For example, it may be based on the Internet Protocol (IP) or Asynchronous Transfer Mode (ATM) and support voice communication using VoIP, Voice over ATM, or similar protocols.In one embodiment, the network comprises a mobile network configured for the exchange of text or SMS messages.

[0029] Examples of networks include Personal Area Networks (PAN), Storage Area Networks (SAN), Home Area Networks (HAN), Campus Area Networks (CAN), Local Area Networks (LAN), Wide Area Networks (WAN), Metropolitan Area Networks (MAN), Virtual Private Networks (VPN), Enterprise Private Networks (EPN), the Internet, Global Area Networks (GAN), and so on.

[0030] Fig. Figure 1 shows a block diagram of an adaptive, hybrid and resource-efficient cryptographic system (100) for optimized IoT security and performance according to an embodiment of the present disclosure;

[0031] According to Fig.1 The system comprises: several IoT devices (102); an IoT gateway (104) that communicates with these IoT devices (102); a trust scoring module (106) that calculates trust scores in real time for each IoT device (102) based on anomaly detection results, historical security events, energy consumption patterns, and network activity patterns; a modified Advanced Encryption Standard (M-AES) encryption module (108) that performs encryption operations using an XOR triplet diffusion mechanism comprising four XOR operations that combine different bytes of state data to achieve diffusion; an Elliptic Curve Cryptography (ECC) module (110) configured for secure key exchange using Elliptic Curve Diffie-Hellman;a Reinforcement Learning Security Agent (RLSA) module (112) that monitors the multidimensional state space of the IoT devices, encompassing energy levels, network load, trust levels, and key age; selects actions from an action space that includes maintaining current encryption keys, initiating key rotation, and changing encryption strength; optimizes security configurations using a Q-learning algorithm with a reward function that balances security benefits and energy consumption; a key management module (114) configured to perform dynamic key rotation based on trust levels and energy thresholds determined by the Reinforcement Learning Security Agent;and a communication interface (116) configured to enable encrypted data transmission between IoT devices and the IoT gateway using the hybrid cryptographic operations M-AES and ECC.

[0032] In one embodiment, the modified AES encryption module (108) further comprises: a SubBytes transformation module for performing AES S-box substitution operations; a ShiftRows transformation module for cyclically shifting each row of a state matrix; an AddRoundKey module for XORing each state byte with the corresponding round key bytes and round constants; wherein the XOR triplet diffusion mechanism uses an involutory matrix, which makes it possible to use the same operations for both encryption and decryption processes.

[0033] In one embodiment, the Reinforcement Learning Security Agent (RSLA) module (112) is implemented as a Markov decision process and configured to: update Q-values ​​using the Q-learning algorithm with learning rate and discount factor parameters; perform state transitions based on received rewards and maximum future Q-values; make key rotation decisions based on the remaining energy level and current network traffic conditions; and continuously learn optimal strategies by interacting with the IoT environment.

[0034] In one embodiment, the reinforcement learning security agent module (112) is further configured to: use predetermined weighting factors for energy consumption when calculating the reward function; implement specific learning rate and discount factor values ​​for Q-learning optimization; monitor energy levels categorized as high, medium, or low; evaluate network load from low to high; and track the key age status as fresh or old to enable optimal security policy determination.

[0035] In one embodiment, the trust assessment module (106) is configured to assign trust levels to each IoT device (102), categorized as trusted, moderately trusted, or untrusted; calculate numerical trust values ​​based on an analysis of device behavior; monitor device integrity and detect unusual behavior patterns; and trigger advanced cryptographic protocols for devices with lower trust values, while enabling resource-efficient operation for devices with higher trust values.

[0036] In one embodiment, the key management module (114) is configured to: perform periodic key rotation, which is monitored by the reinforcement learning security agent; eliminate the need for full session reauthentication on key updates; generate new symmetric keys by Elliptic Curve Diffie-Hellman exchange when the reinforcement learning security agent determines that key rotation is required; and manage the freshness status of the keys as part of the multidimensional state space monitored by the reinforcement learning security agent.

[0037] In one embodiment, the reinforcement learning security agent module (112) is further configured to: continuously evaluate context variables such as device integrity, network congestion, and encryption key status; and dynamically adjust the cryptographic strength based on real-time metrics such as power consumption, network load, and calculated confidence levels.

[0038] In one embodiment, the ECC module (110) is configured to: enable seamless key generation with minimal processing overhead, suitable for resource-constrained IoT applications; integrate with the modified AES encryption module to form a hybrid cryptographic system; and support forward secrecy through dynamic key rotation managed by the reinforcement learning security agent module.

[0039] In one embodiment, the system (100) is configured to adaptively balance security strength and resource efficiency in real time based on context variables of IoT devices. Furthermore, the system offers adaptability to different IoT environment conditions through its reinforcement learning security agent.

[0040] In one embodiment, the IoT devices (102), the IoT gateway (104), the trust assessment module (106), the M-AES encryption module (108), the elliptic curve cryptography module (ECC) (110), the RLSA module (112), the key management module (114) and the communication interface (116) can be implemented in programmable hardware devices such as processors, digital signal processors, central processing units, field-programmable gate arrays, programmable array logic, programmable logic devices, cloud processing systems or the like.

[0041] The present invention relates to an adaptive, hybrid, and resource-efficient cryptography system for optimized security and performance in the Internet of Things (IoT). IoT devices equipped with the modified AES encryption module perform resource-efficient encryption using XOR triplet diffusion instead of computationally intensive MixColumns operations. The trust assessment module continuously monitors device behavior and analyzes anomaly detection results, historical security events, and energy consumption patterns to calculate trust scores in real time. The reinforcement learning security agent, implemented as a Markov decision process, monitors a multidimensional state space that includes energy levels, network load, trust levels, and key age.Based on this contextual information, the agent selects optimal actions, including maintaining the current encryption keys, initiating Elliptic Curve Diffie-Hellman key rotation, or adjusting the encryption strength. The key management module performs dynamic key rotation when the agent deems it necessary for reinforcement learning, while the ECC module ensures secure key generation. This adaptive approach allows the system to provide enhanced security in high-risk situations while conserving resources during normal operation. This results in greater energy efficiency and improved threat detection compared to static cryptographic implementations.

[0042] Fig. Figure 2 shows a block diagram illustrating the implementation of reinforcement learning on a Raspberry Pi 3 B+ according to an embodiment of the present disclosure.

[0043] This disclosure relates to an adaptive, hybrid, and resource-efficient cryptosystem for optimized IoT security and performance. Existing hybrid encryption approaches, such as AES-ECC combinations, are typically implemented with static configurations that cannot adapt to the dynamically changing conditions of IoT environments. These conditions include fluctuating power availability in resource-constrained IoT devices, varying network loads, and shifting levels of trust between connected devices. The use of static configurations in such cryptosystems often leads to over-provisioning, where unnecessary security measures consume valuable resources, or under-provisioning, where inadequate security measures are applied under heightened risk conditions.Previous reinforcement learning-based methods in IoT security were largely limited to modules for anomaly and intrusion detection, without extending reinforcement learning to the dynamic, real-time optimization of cryptographic parameters. As in... Fig.As shown in Figure 2, the proposed system offers a flexible and context-sensitive cryptographic framework that dynamically balances security strength and resource efficiency based on real-time operational metrics from IoT devices. The system integrates strong encryption mechanisms with resource-efficient operation. Encryption strength is adaptively adjusted to parameters such as device trustworthiness, network utilization, and available power consumption. The adaptive hybrid architecture presented here introduces two key innovations: a module for modified Advanced Encryption Standard (M-AES) encryption and a module for a Reinforcement Learning Security Agent (RLSA) with integrated trust assessment and key management capabilities. The M-AES encryption module modifies the standard AES algorithm by replacing the conventional MixColumns transformation with a resource-efficient XOR triplet diffusion mechanism.This operation, based on multiple XOR calculations that combine different bytes of the state matrix, reduces power consumption and memory requirements while maintaining the desired cryptographic properties, including nonlinearity and avalanche effects. Cryptanalytic studies on typical IoT payloads confirm that the modified structure exhibits robustness comparable to conventional AES while ensuring operational efficiency for resource-constrained IoT devices. To enhance forward secrecy and minimize risks from long-term key compromise, the system incorporates regular key rotation controlled by the Reinforcement Learning Security Agent (RLSA) module.The RLSA implemented in the IoT gateway continuously monitors a multidimensional state space encompassing device integrity status, anomaly detection results, network utilization, energy consumption patterns, and the current age of the encryption key. Based on this analysis, the RLSA dynamically determines the need for key rotation. In cases of reduced trust levels, unusual device behavior, or the need for a new key, the RLSA initiates an Elliptic Curve Diffie-Hellman (ECDH) operation via the ECC module for secure key generation. This key management eliminates the need for full session reauthentication, enabling seamless key updates with minimal communication interruptions.The ECC module enables computationally efficient and secure key generation suitable for IoT devices, ensuring robustness against passive attackers while supporting forward secrecy. Through integration with the M-AES module, the system establishes a hybrid cryptographic mechanism that enables efficient, low-latency encryption optimized for real-time IoT environments. The coordination between the trust assessment module, RLSA module, ECC module, and key management module allows the system to achieve adaptive cryptographic strength while maintaining resource efficiency, thus providing a holistic solution for IoT security under diverse and dynamic operating conditions.

[0044] In one embodiment, the modified Advanced Encryption Standard (M-AES) encryption module is designed to reduce computational complexity for resource-constrained and embedded IoT implementations. This design omits the conventional MixColumns transformation to minimize processing overhead and memory requirements. Instead, the system employs an XOR triplet diffusion mechanism—a resource-efficient alternative based solely on bitwise XOR operations, making it computationally efficient and particularly well-suited for resource-constrained IoT environments. The XOR triplet diffusion mechanism is implemented through four equations, with intermediate variables generated using specific triples of XOR operations applied to different bytes of the encryption state.These operations effectively distribute the influence of individual input bits across the state matrix, thus contributing to the avalanche effect, a critical parameter for evaluating cryptographic strength. In addition to the XOR triplet mechanism, the AddRoundKey operation remains an integral part of the M-AES module. Here, each byte of the state is XORed with the corresponding byte of the round key. At this stage, a round constant (Ri) is also introduced to increase the variance between encryption rounds. This round constant can be extended byte-wise or column-wise to improve overall diffusion properties. Following the structural design of standard AES, the final encryption round in the M-AES module omits the XOR triplet operation, thus remaining compatible with the conventional AES framework, which omits the MixColumns step in the final round.The resulting modified AES architecture is designed to achieve an optimal balance between efficiency and security. By eliminating the computationally intensive MixColumns operation and replacing it with XOR-based transformations, the system offers resource-efficient cryptographic performance while maintaining sufficient nonlinearity, diffusion, and avalanche resistance to ensure robust security for IoT applications.

[0045] In one implementation, the modified AES algorithm is used for encryption and decryption, with the functionality of the AES algorithm for encryption and decryption being described as follows: Encryption using the AES algorithm is performed as follows: ⊕: Bitwise XOR ||: concatenation E K(•) : AES encryption with key K GF(2 8 ): Galois field used in AES S(•): AES S-box substitution Step 1: AES status and round key

[0046] Be S (r) the AES state in round r and K r be the round key: S(r)={si,j},Kr={ki.jr}for i,j∈{0,1,2,3}

[0047] These are 4×4 byte matrices. Step 2: Subbytes (Confusion)

[0048] Each byte is replaced using the AES-S box: S'(i,j)=SboxS(i,j) Step 3: ShiftRows (Diffusion)

[0049] Each row i of the state is cyclically shifted by i positions: si,j''=si,(j+1)' mod4 where shift(i) is {0,1,2,3} for the respective rows. Step 4: XOR triplet diffusion

[0050] Instead of MixColumns, a lighter XOR triplet is used: M⊕=[1101111001111011] y0=x0⊕x1⊕x3 y1=x0⊕x1⊕x2 y2=x1⊕x2⊕x3 y3=x0⊕x2⊕x3

[0051] This uses an involutivity matrix. M⊕−1=M⊕ Step 5: AddRoundKey + Rounding constant

[0052] Each state byte is XORed with the round key and extended by a round constant Ri.

[0053] Adding the round-dependent constant increases nonlinearity and round variance: s{i,j}'''=s{i,j}''⊕k{i,j}{(r)}⊕Ri

[0054] Step 6: For byte / column variance, the constant can be extended as follows: C'=[s{i,j}''⊕k{i,j}{(r)}⊕R{i,0},;s{i,j}''⊕k{i,j}{(r)}⊕R{i,1},;s{i,j}''⊕k{i,j}{(r)}⊕R{i,2},s{i,j}''⊕k{i,j}{(r)}⊕R{i,3}]

[0055] The decryption using the AES algorithm is performed as follows: a) Step 1: AES status and round key S(r)=[si,j],K(r)=[ki,j(r)],i,j∈{0,1,2,3} b) Step 2: AddRoundKey + reverse rounding constant S{i,j}'=S{i,(j+i)mod 4}

[0056] For the expanded variance per column: C=[si,j'''⊕ki,j(r)⊕Ri,0,si,j'''⊕ki,j(r)⊕Ri,1,si,j'''⊕ki,j(r)⊕Ri,2,si,j'''⊕ki,j(r)⊕Ri,3] c) Step 3: Inverse XOR triplet diffusion

[0057] Since the XOR triplet matrix is ​​involutive (M ⊕ -1 = M ⊕ M) x0=y0⊕y1⊕y3 x1=y0⊕y1⊕y2 x2=y1⊕y2⊕y3 x3=y0⊕y2⊕y3 d) Step 4: Reverse the rows

[0058] Each row i is cyclically shifted to the right by i positions: si,j'=si,(j−i)mod4 e) Step 5: Inverse SubBytes (Removing Confusion)

[0059] Apply the inverse AES-S box to each byte: si,j=s−1(si,j')

[0060] In one embodiment, the system includes a Reinforcement Learning Security Agent (RLSA) module implemented as a Markov Decision Process (MDP) for dynamically optimizing the security configurations of IoT devices. The RLSA module uses a multidimensional state space with energy levels (high, medium, low), network loads (low, high), trust levels (trusted, moderate, untrusted), and key age (new, old). Based on the observed system state, the RLSA selects actions from a defined action space. These include maintaining the current encryption key, initiating ECDH (Elliptic Curve Diffie-Hellman) key rotation, or adjusting the encryption strength, for example, switching between AES-128 and AES-256.The RLSA uses a reward function that balances security benefits, such as increased trust and key freshness, with resource costs, such as energy consumption and computational effort. Parameters like the learning rate and discount factor can be adjusted to achieve a balance between security guarantees and operational efficiency. Q-learning is used to update the Q-values, with the agent determining the optimal action for each state.

[0061] By continuously evaluating the states of connected IoT devices, RLSA constantly optimizes its policies and issues adaptive instructions to adjust encryption strength or change keys. This adaptive mechanism increases resilience against new threats while ensuring operational efficiency in decentralized and resource-constrained IoT environments.

[0062] Providing real-time trust scores for IoT devices. These scores are based on anomaly detection results, historical security events, unexpected energy consumption, and network activity patterns. Devices with lower trust scores are protected by stricter cryptographic safeguards, while devices with higher trust scores operate more energy-efficiently. In this way, the system achieves adaptive cryptographic strength while optimizing resource utilization. This adaptive, reinforcement learning-based approach strikes a balance between energy efficiency and security. As described in Fig. As shown in Figure 2, this adaptive, RL-based approach effectively protects IoT systems from threats.

[0063] During operation, the system prepares IoT nodes for data transmission and simultaneously collects status data such as energy levels, network conditions, and trust values. The RLSA evaluates this data to determine the optimal cryptographic configuration. Encrypted transmission is performed using the hybrid Modified AES (M-AES) and Elliptic Curve Cryptography (ECC) algorithm or an alternative security configuration chosen by the RLSA. The encrypted and signed data is then transmitted via the IoT gateway. After successful decryption and verification, the RLSA updates its Q-values ​​by rewarding actions that achieve the desired balance between security and efficiency. If the system detects high battery consumption, heavy data traffic, anomalous device behavior, or reduced trust values, the RLSA initiates an ECDH-based key rotation or strengthens the encryption parameters.If no anomalies are detected, the system continues to operate with the existing parameters while the RLSA learns from the collected interactions. The reward function governs this decision-making. Through this continuous adaptation via reinforcement learning, the RLSA ensures that IoT devices operate with optimal cryptographic configurations, thus maintaining a dynamic balance between energy efficiency and security strength in heterogeneous IoT environments.

[0064] Fig. Figure 3 shows a table with the results of hybrid cryptography using a modified AES 128+ ECC 256-bit key according to an embodiment of the present disclosure.

[0065] The proposed hybrid, resource-efficient cryptographic algorithms are evaluated using simulations implemented in Python on a Raspberry Pi 3 B+ using Kaggle. The evaluation uses a healthcare IoT dataset. Modified AES-128 is used for symmetric encryption in combination with ECC-256 for asymmetric key management. Performance is examined using key metrics such as encryption and decryption time, power consumption, throughput, memory usage, avalanche effect, and security analysis.

[0066] As can be seen from the table in Fig.As shown in section 3, the encryption exhibits an average throughput of 96.75 KB / s, with some fluctuations. Energy consumption increases proportionally to data size, from 0.033 J at 1 KB to 0.342 J at 10 KB. Throughput decreases with increasing file size, and memory consumption increases significantly with larger decryption operations, from 721 bytes to 9016 bytes. Avalanche tests confirm that Modified AES-128 achieves diffusion comparable to standard AES, but with improved rates of misflipped bits. The security analysis demonstrates resilience against eavesdropping through session-based key exchanges, protection against replay attacks through timestamps and key IDs, defense against man-in-the-middle attacks through ECC and digital signatures, and adaptive resistance to denial-of-service attacks through adjustments via reinforcement learning.Overall, the results in Table 3 confirm that the proposed hybrid Modified AES-ECC cryptography framework exhibits efficiency, scalability, and strong security characteristics suitable for resource-constrained IoT environments.

[0067] The proposed adaptive hybrid cryptographic system was experimentally validated on a Raspberry Pi 3 B+ using real-world IoT health data and demonstrated significant improvements in efficiency and security compared to conventional AES-ECC methods. The modified AES-128, enhanced by XOR-based diffusion, achieved reductions in power consumption and latency of approximately 26-32%, while simultaneously increasing encryption throughput by 35%. Avalanche effect tests confirmed strong cryptographic diffusion with bit flip rates comparable to or exceeding those of standard AES. This ensures robustness while minimizing resource consumption.

[0068] The reinforcement learning-based security agent significantly improved system adaptability by enhancing threat detection accuracy by 30% and reducing computational overhead by 40% through intelligent key rotation and dynamic encryption strength adjustment. Experimental validations also demonstrated resilience against replay and insider attacks, with a 94% success rate in key recovery while maintaining uninterrupted, secure communication. The RL agent consistently selected optimal configurations in nearly 90% of real-time scenarios, highlighting its ability to adapt security strategies to contextual IoT variables. The following table illustrates the security mode selection by the reinforcement learning algorithm. Table 1: Selection of the security mode by the reinforcement learning algorithm case Condition Server action classification A0 - Normal Benign initial condition Accepted , recommended M-AES-128 System success A1 - LowTrust Trust = 0.1 escalation on AES-256 standard System success A2 - ECC_Corner High traffic volume + high energy + large Recommended ECC System success payload A3 -Review-1 Send first (MsgID=42, TS=T) Accepted System success A3 Repetition-2 Duplicate (MsgID =42,TS=T) Rejected , Reason: Repeat or out of service System success A4 Traffic980 Medium trust, data traffic = 980 kB / s Recommended M-AES-128 System success A5 BigPayload Payload > 900 B Recommended ECC System success A6 LowTrust Low Traffic Trust level = 0.2, Data traffic = 200 kB / s Recommended AES-256 standard System success A7 MITM key manipulator ECC key changed during transport Handshake declined System success A8 Payload Manipulator Ciphertext bit-shifted Authentication / analysis failed → rejected System success A9 Delay / Jitter from 100-300 ms, rearrangement Orders in the correct order will be accepted; outdated / out-of-order orders will be rejected. . System success A10 DoS Burst > 5000 kB / s burst Escalation to ECC / Connection throttled or disconnected System success A11 Faulty JSON Invalid payload format Rejected System success A12 Energy withdrawal experiment Repeated forcing in Heavy Mode Recalibrated to M-AES-128, formerly benign System success A13 Oversized Flood Many payloads > 900 B ECC enforced / surplus rejected System success

[0069] These results confirm the system's suitability for energy- and resource-constrained environments such as the healthcare IoT, where real-time adaptability is crucial. Beyond the healthcare sector, the architecture demonstrates potential for broad application in industrial automation, smart city infrastructure, and vehicle networks. Future research will explore scalability through large-scale IoT deployments and the use of federated reinforcement learning for decentralized optimization. Furthermore, the planned integration of post-quantum cryptographic methods will extend fault tolerance into the quantum age, thus ensuring the long-term robustness of IoT security.

[0070] The drawings and the preceding description illustrate embodiments. Those skilled in the art will recognize that one or more of the described elements can be combined to form a single functional element. Alternatively, certain elements can be divided into several functional elements. Elements of one embodiment can be added to another. For example, the process flows described here can be modified and are not limited to the manner described herein. Furthermore, the actions of a flowchart need not be performed in the sequence shown; nor do all actions necessarily need to be carried out. Actions that do not depend on other actions can be performed in parallel with the other actions. The scope of protection of the embodiments is in no way limited by these specific examples. Numerous variations, whether explicitly stated in the description or not, such as...Differences in structure, dimensions, and materials are possible. The scope of protection of the embodiments is at least as comprehensive as described by the following claims.

[0071] The advantages, other benefits, and problem solutions have been described above with reference to specific embodiments. However, the advantages, benefits, problem solutions, and any components that can effect or enhance an advantage, benefit, or solution are not to be construed as critical, necessary, or essential features or components of the claims. REFERENCES 100 An Adaptive, Hybrid and Lightweight Cryptography System for Optimized IoT Security and Performance. 102 Variety of IoT Devices 104 IoT Gateway 106 Trust Assessment Module 108 Modified Advanced Encryption Standard (M-AES) encryption module 110 Module Elliptic Curve Cryptography (ECC) 112 Reinforcement Learning Security Agent (RLSA) module 114 Key Management Module 116 Communication interface 202 IoT nodes 1 204 Initialization 206 Initialize IoT nodes / Prepare data transfer 206a Government data on energy consumption 206b Security Level of State Data 206c Last of Data Traffic in the Status Area 206d Sensor data (payload) 206e Encrypt payload status data (standard encryption M-AES) 206f Transmitting Encrypted Data 208 Communication 208a Select encryption type / key rotation 208b Calculate Reward 208c RL agent decision 208d Monitoring for anomalies in energy level, traffic load and battery level 208e Extract status data 210 Reward criteria: Required level of security 212 Reward criteria: Energy efficiency 214 Reward criteria: Traffic volume 216 Sink (Server): Decrypt and Verify Data 218 Decryption Successful 220 decrypted user data + status data 222 Communication - Action 224 Server-based Machine Learning with RL 226 servers 228 NO 230 Yes

Claims

[1] An adaptive, hybrid and resource-efficient cryptosystem for optimized IoT security and performance, consisting of: a variety of IoT devices; The IoT gateway is communicatively connected to the multitude of IoT devices; a trust assessment module configured to calculate trust scores for each IoT device in real time based on anomaly detection results, historical security events, energy consumption patterns, and network activity patterns; a modified Advanced Encryption Standard (M-AES) encryption module configured to perform encryption operations using an XOR triplet diffusion mechanism consisting of four XOR operations that combine different bytes of state data to achieve diffusion; an Elliptic Curve Cryptography (ECC) module configured to perform Elliptic Curve Diffie-Hellman key exchange operations for secure key generation; A Reinforcement Learning Security Agent (RLSA) module configured to: monitor a multidimensional state space encompassing the power level, network load, trust level, and key age of IoT devices; select actions from an action space that includes maintaining current encryption keys, initiating key rotation, and changing encryption strength; optimize security configurations using the Q-Learning algorithm with a reward function that balances security benefits and energy consumption; a key management module configured to perform dynamic key rotation based on trust values ​​and energy thresholds determined by the reinforcement learning security agent; and a communication interface configured to enable encrypted data transmission between IoT devices and the IoT gateway using the hybrid cryptographic operations M-AES and ECC. [2] System according to claim 1, wherein the modified AES encryption module further comprises: a SubBytes transformation module for performing AES S-box substitution operations; a ShiftRows transformation module for cyclically shifting each row of a state matrix; an AddRoundKey module for XORing each state byte with the corresponding round key bytes and round constants; and wherein the XOR triplet diffusion mechanism uses an involutory matrix which makes it possible to use the same operations for both encryption and decryption processes. [3] System according to claim 1, wherein the ECC module is configured to: enable seamless key generation with minimal processing overhead, suitable for resource-constrained IoT applications; integrate with the modified AES encryption module to form a hybrid cryptographic system; and support forward secrecy through dynamic key rotation managed by the reinforcement learning security agent module. [4] System according to claim 1, wherein the Reinforcement Learning Security Agent Module (RSLA) is implemented as a Markov decision process and is configured to: update Q-values ​​using the Q-Learning algorithm with learning rate and discount factor parameters; perform state transitions based on received rewards and maximum future Q-values; make key rotation decisions based on the remaining energy level and current network traffic conditions; and continuously learn optimal strategies by interacting with the IoT environment. [5] System according to claims 1 and 3, wherein the module for the reinforcement learning security agent is further configured to: use predetermined weighting factors for energy consumption when calculating the reward function; implement specific values ​​for learning rate and discount factor for Q-learning optimization; monitor energy levels categorized as high, medium or low; evaluate network load from low to high; and track the key age status as fresh or old to determine an optimal security policy. [6] System according to claim 1, wherein the reinforcement learning security agent module is further configured to: continuously evaluate context variables such as device integrity, network congestion and encryption key status; and dynamically adjust the cryptographic strength based on real-time metrics such as power consumption, network load and calculated confidence levels. [7] System according to claim 1, wherein the trust assessment module is configured to assign trust levels to each IoT device, categorized as trusted, moderately trusted or untrusted; calculates numerical trust values ​​based on an analysis of device behavior; monitors device integrity and detects unusual behavior patterns; and triggers advanced cryptographic protocols for devices with lower trust values, while enabling resource-efficient operation for devices with higher trust values. [8] System according to claim 1, wherein the key management module is configured to: perform periodic key rotation monitored by the reinforcement learning security agent; eliminate the need for full session re-authentication on key updates; generate new symmetric keys by Elliptic Curve Diffie-Hellman exchange when the reinforcement learning security agent determines that key rotation is required; and maintain the freshness status of the keys as part of the multidimensional state space monitored by the reinforcement learning security agent. [9] System according to claim 1, wherein the system is configured to adaptively balance security strength and resource efficiency in real time based on context variables of IoT devices, and wherein the system further provides adaptability to different IoT environmental conditions through the reinforcement learning security agent.