AI-Driven Adaptive Encryption Framework for a Modular Hardware-Based Data Security Device: Conceptual Architecture, Formal Foundations, and Security Analysis
Abstract
1. Introduction
- A tri-modular hardware architecture—Secure Input Module (SIM), AI-Enhanced Central Processing Unit (AI-CPU), and Secure Output Module (SOM)—mapped to the registered industrial design.
- A formal MDP formulation for the reinforcement learning-based adaptive encryption policy, with a complete state space, action space, transition dynamics, and reward structure.
- Three algorithmic specifications: ATAM decision pipeline, adaptive key rotation, and authentication escalation protocols.
- An information-theoretic security proof demonstrating strictly higher ciphertext entropy for adaptive encryption versus static systems.
- A theoretical performance model with latency and throughput estimates based on published TinyML benchmarks.
- A worked numerical scenario illustrating system behaviour under a multi-stage attack.
2. Related Work
2.1. Static Encryption and Hardware Security Modules
2.2. AI in Cybersecurity
2.3. Adaptive Encryption and Modular Hardware
3. Hardware Design and Functional Mapping
3.1. Design Overview
3.2. Module Descriptions
3.3. Interconnection Architecture
4. AI-Encryption Framework Architecture
4.1. Component Mapping
4.2. Cryptographic Execution Unit
4.3. Formal MDP Formulation for Adaptive Encryption Policy
4.4. ATAM Sub-Components
4.5. Algorithmic Specifications
| Algorithm 1: ATAM Decision Pipeline |
| Input: data_stream D, sensor_inputs X, current_state s Output: action vector a, updated state s′ 1: T ← NNTC.classify(D, X.camera) //threat vector 2: s_threat ← max(T [0..n−2]) //max non-benign 3: anomaly_score ← ADE.evaluate(D, X) 4: if anomaly_score > θ then 5: s_threat ← max(s_threat, 0.8) //elevate threat 6: end if 7: s_auth ← compute_auth_confidence(X) 8: s ← (s_threat, s_resource, s_sensitivity, s_auth, s_latency) 9: a ← RLPE.select_action(s) //ε-greedy DQN 10: if a ∉ SAFE_CONFIGS then 11: a ← FALLBACK_CONFIG //HW-enforced 12: end if 13: CEU.apply(a.α, a.key_len, a.mode) 14: AKMS.set_rotation(a.f_rot) 15: return a, s |
| Algorithm 2: Adaptive Key Rotation Protocol |
| Input: threat_level s_threat, base_frequency f_base, λ Output: rotation event or no-op 1: f_rot ← f_base × (1 + λ × s_threat) 2: t_next ← 1/f_rot //seconds 3: if time_since_last_rotation ≥ t_next then 4: K_new ← TRNG.generate(key_len) 5: K_new ← K_new ⊕ NPU.pseudo_random(key_len)//hybrid 6: H(K_new) ← estimate_entropy(K_new) 7: if H(K_new) < entropy_threshold then 8: K_new ← TRNG.generate(key_len) //fallback 9: end if 10: AKMS.install_key(K_new) 11: AKMS.schedule_zeroise(K_old, delay = 2 s) 12: end if |
| Algorithm 3: Authentication Escalation Protocol |
| Input: threat_level s_threat, current_auth_level L_curr Output: required_auth_level L_req 1: if s_threat < 0.3 then 2: L_req ← 1 //PIN only 3: else if s_threat < 0.7 then 4: L_req ← 2 //PIN + biometric 5: else 6: L_req ← 3 //PIN + biometric + token 7: end if 8: if L_req > L_curr then 9: SIM.request_pin_reentry() 10: if L_req ≥ 2 then AI-CPU.request_biometric() 11: if L_req ≥ 3 then SOM.request_token() 12: C_auth ← fuse_auth_signals() 13: if C_auth < min_confidence[L_req] then 14: CEU.lock(); raise ALERT 15: end if 16: end if 17: return L_req |
4.6. Key Lifecycle Management and Communication
Neural Entropy Augmentation: Rationale and Safeguards
4.7. Anti-Downgrade Safeguards
5. Theoretical Security Analysis
5.1. Formal Threat Model
5.2. Information-Theoretic Security Analysis
5.3. Operational Complexity Analysis
5.4. Side-Channel and Physical Security
5.5. Adversarial ML Resilience
5.6. Post-Quantum Transition Strategy
- Phase 1 (Current): Classical-Primary with PQ Monitoring. The system operates primarily with classical algorithms (AES-256, ChaCha20) while the ATAM monitors external quantum threat intelligence feeds. CRYSTALS algorithms are available in L but not selected unless the quantum threat score exceeds a configurable threshold.
- Phase 2 (Transition): Hybrid Mode. When quantum threat indicators reach moderate levels, the CEU activates hybrid encryption mode. In hybrid mode, each plaintext block is encrypted under both a classical and a post-quantum algorithm, and the ciphertext becomes the following concatenation:
- Phase 3 (Post-Transition): PQ-Primary. When classical algorithms are assessed as no longer providing adequate security margins, the ATAM transitions to PQ-primary operation, retaining classical algorithms only as a fallback.
5.7. Theoretical Performance Model
5.8. Worked Scenario: Multi-Stage Attack Response
- Stage 0 (Baseline, t = 0): System operates under normal conditions. State: s = (0.05, 0.30, 3, 0.92, 0.83). Action: a = (AES-256, 256, f2, GCM, 1). The system uses AES-256-GCM with standard rotation and single-factor authentication. Throughput: ~1.18 MB/s.
- Stage 1 (DDoS Onset, t = 12 min): NNTC detects traffic anomaly consistent with volumetric DDoS. Threat vector T = (0.78, 0.05, 0.02, …, 0.10). State updates: s = (0.78, 0.55, 3, 0.92, 1.20). RLPE selects the following: a = (AES-256, 256, f4, GCM, 2). Key rotation frequency increases from f2 (every 4 h) to f4 (every 30 min). Authentication escalates to two-factor (PIN + biometric). The biometric sensor requests fingerprint verification.
- Stage 2 (Side-Channel Probing Detected, t = 18 min): While DDoS continues, the ADE detects anomalous power consumption patterns (reconstruction error exceeds θ by 2.3σ), indicating potential differential power analysis. State: s = (0.91, 0.60, 3, 0.88, 1.45). RLPE selects the following: a = (ChaCha20-Poly1305, 256, f5, stream, 2). The system switches from AES to ChaCha20 (constant-time implementation resistant to timing attacks) and increases rotation to f5 (every 5 min). CEU activates dummy operation injection.
- Stage 3 (Quantum Threat Intelligence, t = 25 min): External threat feed reports an elevated quantum computing threat score. State: s = (0.95, 0.65, 3,0.88, 2.10). RLPE selects the following: a = (ChaCha20-Poly1305, 256, f6, stream, 3). The system maintains ChaCha20-Poly1305 for symmetric encryption (retaining its timing-attack resistance from Stage 2), while the AKMS independently activates hybrid key encapsulation: session keys are now established via KDF(K_ECDH || K_Kyber-768 || context) following NIST SP 800-227 hybrid key derivation. Maximum rotation frequency and three-factor authentication are engaged. The SOM requests smart card token insertion. End-to-end latency increases to ~2.85 ms but remains within operational bounds.
- Stage 4 (Threat Subsides, t = 45 min): NNTC threat scores decline to baseline. State: s = (0.12, 0.40, 3, 0.95, 0.90). RLPE gradually de-escalates: a = (AES-256, 256, f3, GCM, 1). The system returns to AES-256 with moderately elevated rotation (f3: every 2 h, slightly above baseline as a precautionary measure) and single-factor authentication. This gradual de-escalation, rather than immediate return to baseline, is a learned behaviour from the RLPE reward structure that penalises rapid oscillation.
5.8.1. Simulation Validation
5.8.2. DQN Validation over Continuous State Space
5.9. Comparative Security Properties
6. Discussion
6.1. Theoretical Advantages
6.2. Limitations
6.3. Regulatory Context
7. Future Work
8. Conclusions
9. Patents
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Acknowledgments
Conflicts of Interest
References
- Stallings, W. Cryptography and Network Security, 8th ed.; Pearson: London, UK, 2022. [Google Scholar]
- Schneier, B. Applied Cryptography, 20th ed.; Wiley: Hoboken, NJ, USA, 2015. [Google Scholar]
- Goodfellow, I.; Bengio, Y.; Courville, A. Deep Learning; MIT Press: Cambridge, MA, USA, 2016. [Google Scholar]
- LeCun, Y.; Bengio, Y.; Hinton, G. Deep learning. Nature 2015, 521, 436–444. [Google Scholar] [CrossRef] [PubMed]
- Taherdoost, H.; Slimani, K. Cryptographic Techniques in AI Security: A Bibliometric Review. Cryptography 2025, 9, 17. [Google Scholar] [CrossRef]
- Buczak, A.L.; Guven, E. A Survey of Data Mining and Machine Learning Methods for Cyber Security Intrusion Detection. IEEE Commun. Surv. Tutor. 2016, 18, 1153–1176. [Google Scholar] [CrossRef]
- Daemen, J.; Rijmen, V. The Design of Rijndael: AES; Springer: Berlin/Heidelberg, Germany, 2002. [Google Scholar]
- FIPS 140-3; Security Requirements for Cryptographic Modules. NIST: Gaithersburg, MD, USA, 2019.
- Anderson, R. Security Engineering, 3rd ed.; Wiley: Indianapolis, IN, USA, 2020. [Google Scholar]
- NIST. Post-Quantum Cryptography Standardization. Available online: https://csrc.nist.gov/projects/post-quantum-cryptography (accessed on 15 January 2026).
- Shor, P.W. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer. SIAM J. Comput. 1997, 26, 1484–1509. [Google Scholar] [CrossRef]
- Bernstein, D.J.; Lange, T. Post-quantum cryptography. Nature 2017, 549, 188–194. [Google Scholar] [CrossRef] [PubMed]
- Al-Garadi, M.A.; Mohamed, A.; Al-Ali, A.K.; Du, X.; Guizani, M. A Survey of Machine Learning and Deep Learning in Cybersecurity of IoT. IEEE Commun. Surv. Tutor. 2020, 22, 1646–1685. [Google Scholar] [CrossRef]
- Xin, Y.; Kong, L.; Liu, Z.; Chen, Y.; Li, Y.; Zhu, H.; Gao, M.; Hou, H.; Wang, C. Machine Learning and Deep Learning Methods for Cybersecurity. IEEE Access 2018, 6, 35365–35381. [Google Scholar] [CrossRef]
- Mahdavifar, S.; Ghorbani, A.A. Application of deep learning to cybersecurity. Neurocomputing 2019, 347, 149–176. [Google Scholar] [CrossRef]
- Nguyen, T.T.; Reddi, V.J. Deep Reinforcement Learning for Cyber Security. IEEE Trans. Neural Netw. Learn. Syst. 2023, 34, 3779–3795. [Google Scholar] [CrossRef] [PubMed]
- Garrett, A.; Hamilton, J.; Dozier, G. Genetic Algorithm Techniques for the Cryptanalysis of the Tiny Encryption Algorithm. Int. J. Intell. Control Syst. 2007, 12, 325–330. [Google Scholar]
- De Bernardi, M.; Khouzani, M.H.R.; Malacaria, P. Pseudo-Random Number Generation Using Generative Adversarial Networks. In Proceedings of ECML PKDD 2018, Dublin, Ireland, 10–14 September 2018; Springer: Cham, Switzerland, 2019; pp. 191–200. [Google Scholar]
- Kim, J.; Kim, J.; Le Thi Thu, H.; Kim, H. Long Short Term Memory Recurrent Neural Network Classifier for Intrusion Detection. In Proceedings of PlatCon 2016, Jeju, Republic of Korea, 15–17 February 2016; IEEE: New York, NY, USA, 2016; pp. 1–5. [Google Scholar]
- Yang, Y.; Wu, L.; Yin, G.; Li, L.; Zhao, H. Security and Privacy Issues in IoT. IEEE Internet Things J. 2017, 4, 1250–1258. [Google Scholar] [CrossRef]
- Al-Turjman, F.; Zahmatkesh, H.; Shahroze, R. An overview of security and privacy in smart cities’ IoT. Trans. Emerg. Telecommun. Technol. 2022, 33, e3677. [Google Scholar] [CrossRef]
- Elkhodr, M. AI-Driven Framework for Integrated Security and Privacy in Internet of Things Using Quantum-Resistant Blockchain. Future Internet 2025, 17, 246. [Google Scholar] [CrossRef]
- Ukil, A.; Sen, J.; Koilakonda, S. Embedded Security for IoT. In Proceedings of INMIC 2011, Shillong, India, 4–5 March 2011; IEEE: New York, NY, USA, 2011; pp. 1–6. [Google Scholar]
- Kocher, P.; Jaffe, J.; Jun, B. Differential Power Analysis. In Proceedings of CRYPTO 1999, Santa Barbara, CA, USA, 15–19 August 1999; Springer: Berlin/Heidelberg, Germany, 1999; pp. 388–397. [Google Scholar]
- Sutton, R.S.; Barto, A.G. Reinforcement Learning: An Introduction, 2nd ed.; MIT Press: Cambridge, MA, USA, 2018. [Google Scholar]
- Altman, E. Constrained Markov Decision Processes; Chapman and Hall/CRC: Boca Raton, FL, USA, 1999. [Google Scholar]
- SP 800-90B; Recommendation for the Entropy Sources Used for Random Bit Generation. NIST: Gaithersburg, MD, USA, 2018.
- Acharya, J.; Das, H.; Orlitsky, A.; Suresh, A.T. Estimating Entropy of Distributions over Large Alphabets. In Proceedings of the NIPS 2014, Montreal, QC, Canada, 8–13 December 2014; pp. 721–729. [Google Scholar]
- SP 800-88 Rev. 1; Guidelines for Media Sanitization. NIST: Gaithersburg, MD, USA, 2014.
- Dolev, D.; Yao, A. On the security of public key protocols. IEEE Trans. Inf. Theory 1983, 29, 198–208. [Google Scholar] [CrossRef]
- Cover, T.M.; Thomas, J.A. Elements of Information Theory, 2nd ed.; Wiley: Hoboken, NJ, USA, 2006. [Google Scholar]
- Goodfellow, I.J.; Shlens, J.; Szegedy, C. Explaining and Harnessing Adversarial Examples. In Proceedings of the ICLR 2015, San Diego, CA, USA, 7–9 May 2015. [Google Scholar]
- Biggio, B.; Roli, F. Wild patterns: Ten years after the rise of adversarial Machine Learning. Pattern Recognit. 2018, 84, 317–331. [Google Scholar] [CrossRef]
- SP 800-227 (Initial Public Draft); Recommendations for Key-Encapsulation Mechanisms. NIST: Gaithersburg, MD, USA, 2024.
- Banbury, C.R.; Reddi, V.J.; Lam, M.; Fu, W.; Fazel, A.; Holleman, J.; Huang, X.; Hurtado, R.; Kanter, D.; Lokhmotov, A.; et al. Benchmarking TinyML Systems. arXiv 2021, arXiv:2003.04821. [Google Scholar] [CrossRef]
- Avanzi, R.; Bos, J.; Ducas, L.; Kiltz, E.; Lepoint, T.; Lyubashevsky, V.; Schanck, J.M.; Schwabe, P.; Seiler, G.; Stehlé, D. CRYSTALS-Kyber: Algorithm Specifications and Supporting Documentation (Version 3.02); NIST PQC Round 3 Submission; NIST: Gaithersburg, MD, USA, 2021.













| Sensor | Measurement | Sample Rate | ADE Output |
|---|---|---|---|
| Current sense resistor | Power rail current | 10 MHz | DPA detection |
| Near-field EM probe | Local EM emanations | 5 MHz | EM probing detection |
| Timing counters | Operation cycle counts | Per-operation | Timing attack detection |
| Temperature sensor | Die temperature | 1 kHz | Fault injection detection |
| Logical Component | Module | Hardware Elements |
|---|---|---|
| Secure Input Layer | SIM | Keypad, display, and secure bus |
| AI Threat Analysis (ATAM) | AI-CPU | NPU, touchscreen, biometrics, and camera |
| Crypto Execution (CEU) | AI-CPU | Crypto accelerator, TRNG, and secure element |
| Key Management (AKMS) | AI-CPU + SIM/SOM | Key store, distribution bus, and smart card I/F |
| Secure Output Layer | SOM | Display, printer, card reader, and audit storage |
| Pipeline Stage | Normal (ms) | Threat (ms) | Source Basis |
|---|---|---|---|
| SIM input processing | 0.05 | 0.05 | GPIO latency |
| NNTC inference | 0.45 | 0.45 | MobileNetV3 INT8 [35] |
| ADE evaluation | 0.12 | 0.12 | VAE inference [35] |
| RLPE action selection | 0.08 | 0.08 | DQN forward pass |
| CEU encryption (AES-256) | 0.03 | — | AES-NI benchmark |
| CEU encryption (Kyber) | — | 0.85 | CRYSTALS benchmark [10] |
| Key rotation (if triggered) | — | 1.20 | TRNG + install |
| SOM output processing | 0.10 | 0.10 | Bus + render |
| TOTAL | 0.83 | 2.85 |
| Stage | s_Threat | Cipher | Key (bits) | Rotation | Auth | σ(a) | Latency (ms) |
|---|---|---|---|---|---|---|---|
| 0: Baseline | 0.05 | AES-256-GCM | 256 | f3 (2 h) | 1 | 0.500 | 0.85 |
| 1: DDoS Onset | 0.78 | ChaCha20-Poly1305 | 256 | f6 (cont.) | 2 | 0.500 | 1.49 |
| 2: Side-Channel Probe | 0.91 | ChaCha20-Poly1305 | 256 | f5 (5 min) | 3 | 0.500 | 1.74 |
| 3: Peak Threat | 0.95 | ChaCha20-Poly1305 | 256 | f5 (5 min) | 3 | 0.500 | 1.74 |
| 4: Threat Subsides | 0.12 | AES-256-GCM | 256 | f3 (2 h) | 1 | 0.500 | 0.85 |
| Metric | Tabular Q-Learning | DQN |
|---|---|---|
| Final average reward (last 100 eps) | 14.63 | 10.64 |
| Standard of reward (last 100 eps) | 5.48 | 3.95 |
| Total constraint violations | 1627 | 297 (82% fewer) |
| Average violations/ep (last 100) | 2.92 | 0.06 |
| Response time to threat escalation | 8.20 steps | 1.40 steps |
| Action-switch rate | 0.694 | 0.645 (more stable) |
| Property | Static HSM | SW AI-Sec | Context-Aware | AI-AED (Ours) |
|---|---|---|---|---|
| Algorithm selection | Fixed | Limited | Partial | MDP-optimised |
| Threat response | None | ~100 ms | None | <3 ms |
| Key rotation | Fixed | Software | Rule-based | RL-driven |
| Entropy advantage | 0 bits | ~1 bit | ~1 bit | up to +1.58 bits |
| Biometrics | External | No | No | Integrated |
| PQ-ready | FW update | SW update | FW update | Autonomous |
| Module isolation | Monolithic | N/A | Monolithic | Tri-modular |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Pawar, P.; Epiphaniou, G. AI-Driven Adaptive Encryption Framework for a Modular Hardware-Based Data Security Device: Conceptual Architecture, Formal Foundations, and Security Analysis. Appl. Sci. 2026, 16, 3522. https://doi.org/10.3390/app16073522
Pawar P, Epiphaniou G. AI-Driven Adaptive Encryption Framework for a Modular Hardware-Based Data Security Device: Conceptual Architecture, Formal Foundations, and Security Analysis. Applied Sciences. 2026; 16(7):3522. https://doi.org/10.3390/app16073522
Chicago/Turabian StylePawar, Pruthviraj, and Gregory Epiphaniou. 2026. "AI-Driven Adaptive Encryption Framework for a Modular Hardware-Based Data Security Device: Conceptual Architecture, Formal Foundations, and Security Analysis" Applied Sciences 16, no. 7: 3522. https://doi.org/10.3390/app16073522
APA StylePawar, P., & Epiphaniou, G. (2026). AI-Driven Adaptive Encryption Framework for a Modular Hardware-Based Data Security Device: Conceptual Architecture, Formal Foundations, and Security Analysis. Applied Sciences, 16(7), 3522. https://doi.org/10.3390/app16073522

