Why are ECC and RSA considered unsuitable for firmware authentication on constrained IoT devices, and what replaces them?
On some small microcontrollers, public-key arithmetic exceeds the code or latency budget. Hash-based signatures can reduce verifier complexity, with trade-offs in signature size and, for stateful schemes, key management.
The cost of conventional public-key cryptography on a small device is not one number but three:
- Code size — an RSA or elliptic-curve implementation, with its big-integer arithmetic, consumes flash that a device with tens of kilobytes cannot spare.
- Latency — verification takes time, and on a boot path that runs on every power-up, that time is user-visible and energy-costly.
- Energy — every cycle spent verifying comes out of the same battery that has to last years.
Hash-based signature schemes are the substitute because their security rests only on the properties of a hash function — which the device needs anyway for the image fingerprint — rather than on number-theoretic problems requiring heavyweight arithmetic. A hash function is small, fast and already present, so verification can reuse existing code. The actual cost depends on the scheme and parameters; larger signatures also consume bandwidth and storage.
There is a broader point behind this specific swap: it is the same move made everywhere else in the constrained stack. CoAP over UDP/DTLS can serve workloads that do not need TCP, 6LoWPAN compresses IPv6 over constrained links, and hash-based signatures offer an alternative to arithmetic-based signatures. In each case the security or functional goal is kept and the implementation cost is attacked. That is what lightweight cryptographic primitives means as a research area — not weaker cryptography, but cryptography re-engineered for a budget.
Tip: hash-based signatures have had a second life for an unrelated reason — they are believed to resist quantum attacks, since they rest on hash properties rather than on factoring or discrete logarithms. Stateful schemes such as LMS must never reuse a one-time signing key: losing or rolling back the signing state can break their security. ECC remains a practical choice on many IoT devices.
Go deeper:
Wikipedia — Hash-based cryptography — the replacement family in detail, from Merkle trees through XMSS and LMS to SPHINCS+, including the limit on how many messages one key may sign.
Wikipedia — Cryptographic hash function — the single primitive the whole scheme rests on, and the three resistance properties it has to provide.
RFC 8554 — LMS hash-based signatures — the concrete signing and verification algorithms, signature sizes and mandatory one-time-key state management.