Billions of sensors, cameras, meters and controllers at the edge of the internet now handle data that must stay secret for years, and a quiet race is underway to make sure that when large quantum computers finally arrive, none of that information becomes readable overnight. A team of researchers at Maulana Azad National Institute of Technology in Bhopal, India, has unveiled a new encryption design aimed squarely at this problem. In a study published in Cluster Computing, Saima Hasib, Akhtar Rasool and Manasi Gyanchandani describe a post-quantum attribute-based encryption scheme, which they call PQC-CLWE-ABE, that promises to protect resource-constrained edge and Internet of Things devices against both quantum adversaries and the messy operational realities of large multi-user networks.
Attribute-based encryption, or ABE, is a family of techniques that flips traditional public-key cryptography on its head. Instead of encrypting a message for one named recipient, the sender encrypts it against a policy written in terms of attributes, such as hospital, cardiologist or night shift, and only users whose private keys carry matching attributes can decrypt. This makes ABE a natural fit for the Internet of Things, where a single gateway may broadcast readings to dozens of authorized consumers with different access rights. The catch is that most practical ABE schemes rely on elliptic-curve pairings, mathematical operations that a sufficiently powerful quantum computer running Shor’s algorithm could break. Lattice-based constructions are the leading quantum-resistant alternative, but existing lattice ABE schemes have struggled with three shortcomings the Indian team set out to fix: they rarely support tracing users who leak their keys, they handle revocation inefficiently, and they often leak the sensitive attribute values embedded in access policies.
The heart of the new scheme is a mathematical problem called Cyclic Learning With Errors, or CLWE, a variant of the Learning With Errors problem that underpins much of modern lattice cryptography. In Learning With Errors, an attacker is handed noisy linear equations and must recover the hidden secret despite random error terms; the task is believed to be intractable even for quantum computers. The cyclic variant ties the problem to cyclic division algebras, algebraic structures that have previously been used to build high-performance lattices in wireless communication theory. By grounding their scheme in the Decisional CLWE assumption, the authors can prove security in the standard model, meaning the proof does not depend on idealized random-oracle heuristics that sometimes fail to survive real-world implementation.
One of the scheme’s distinguishing features is how it represents attributes. Rather than storing attribute names as plain strings that travel with the ciphertext, the design uses a two-dimensional representation in which each attribute is described by a label and a value pair, and the value component is concealed. This preserves attribute privacy: an eavesdropper who intercepts encrypted traffic can learn something about the broad category of who may read the data, but not the specific sensitive values, such as a particular ward, employer or clearance level, that appear in the policy. In deployments like smart healthcare or industrial control, where the access policy itself can reveal commercially or medically sensitive context, hiding these values closes a leak that many earlier lattice ABE constructions left open.
Revocation, the process of cutting off a user who leaves an organization or whose device is compromised, has long been a pain point for attribute-based systems. Reissuing keys for every remaining user is prohibitively expensive at Internet-of-Things scale, and naive approaches leave revoked users able to keep decrypting old ciphertexts. The proposed scheme tackles this with a binary tree-based revocation model. Users are assigned leaves of a tree, and keys are bound to tree nodes so that revoking a user requires updating only a logarithmic number of key components rather than the entire system. Crucially, when a user is revoked, the scheme performs ciphertext re-randomization, refreshing previously encrypted data so that the revoked party’s key no longer works against it. That combination of real-time revocation and retroactive protection is rare in lattice-based designs and is particularly valuable in edge environments where devices may be physically accessible to attackers.
Traitor tracing addresses the complementary threat: what happens when a legitimate user deliberately shares their private key, or a device is cloned and its key material appears in pirated decoders? The new scheme embeds traceable global user identifiers, or GIDs, into every private key it issues. When pirated content or an unauthorized decoder surfaces, the authority can extract the embedded identifier and pinpoint which key was responsible. Because the identifiers are woven into the lattice key structure, tracing works without degrading decryption performance, and the scheme supports full traitor tracing rather than the weaker black-box or partial tracing guarantees offered by many predecessors.
Underneath the access-control machinery sits an unusual cryptographic ingredient: extended Shamir secret sharing performed over cyclic division algebras. Shamir’s classic (t, n) threshold scheme splits a secret into n shares such that any t of them can reconstruct it, and it is a standard tool for building flexible access policies in ABE. The authors extend this sharing mechanism into the algebraic setting of cyclic division algebras, which are rings that support the lattice operations the scheme needs while contributing to the compactness of the resulting key material. This integration is what allows the encryption algorithm to enforce dynamic, threshold-style policies over attributes while keeping the underlying hardness assumption rooted in the CLWE problem, so confidentiality holds even as users join and leave the system continuously.
Efficiency is where the scheme makes its most headline-friendly claim. For comparable parameter settings, the authors report that PQC-CLWE-ABE achieves up to a seventy percent reduction in key sizes relative to existing lattice-based and pairing-based ABE systems, alongside meaningful cuts in the system public key size, the per-user private key size, and the ciphertext expansion rate, which measures how much longer an encrypted message is compared with its plaintext. These metrics matter enormously at the edge. A battery-powered sensor with kilobytes of memory and a low-bandwidth radio cannot afford the multi-megabyte keys and bloated ciphertexts that early post-quantum constructions sometimes produce. Smaller keys mean faster transmission, lower energy per cryptographic operation, and room to store more credentials on constrained hardware, all of which determine whether post-quantum protection is deployable in practice or confined to whitepapers.
The security analysis is carried out in the standard model under the Decisional CLWE assumption, and the performance evaluation compares the scheme against a range of prior lattice-based and pairing-based ABE designs across the usual yardsticks of key size, ciphertext length and computational cost. The authors state that no datasets were generated or analyzed during the study, indicating the contribution is a cryptographic construction with analytical and simulation-based evaluation rather than a field deployment. The work arrives amid a broader surge of interest in quantum-safe protection for connected systems, from quantum-resistant TLS protocols and hybrid key exchange to blockchain-assisted encryption for IoT networks, and it positions itself as a piece of that larger puzzle: a way to bring fine-grained, accountable access control into the post-quantum toolkit rather than treating quantum resistance as the only requirement.
If the reported performance holds up under independent implementation and standardization scrutiny, designs of this kind could shape how critical infrastructure, smart cities and industrial networks encrypt data in the coming decade, when agencies worldwide are already mandating migrations to post-quantum algorithms. The scheme’s blend of quantum-resistant hardness, hidden attribute values, efficient tree-based revocation and built-in traitor tracing addresses a cluster of operational needs that quantum-safe key exchange alone does not cover. For the vast population of small devices sitting at the network’s edge, the study offers a concrete signal that the post-quantum transition need not come at the price of functionality: it may be possible to be quantum-proof, privacy-preserving and lightweight at the same time, provided the underlying mathematics is chosen with the constraints of the edge in mind.
Subject of Research: Post-quantum lattice-based attribute-based encryption for securing edge and IoT devices
Article Title: Post-quantum lattice-based attribute encryption with user revocation and privacy for edge-IoT devices
Article References: Hasib, S., Rasool, A., & Gyanchandani, M. (2026). Post-quantum lattice-based attribute encryption with user revocation and privacy for edge-IoT devices. Cluster Computing, 29(13), Article 748. https://doi.org/10.1007/s10586-026-06582-z
Image Credits: AI Generated
DOI: 10.1007/s10586-026-06582-z
Keywords: post-quantum cryptography, attribute-based encryption, lattice cryptography, CLWE, IoT security, edge computing, user revocation, traitor tracing, attribute privacy, Shamir secret sharing, cyclic division algebras, Cluster Computing
News Source: Katie Riggs. (October 9, 2026). Quantum-Proof Encryption for Smart Devices Gets Smaller, Faster and More Private. Scienmag.



