DOI: 10.3390/app16199562 ISSN: 2076-3417

AQ-TESLA: Adaptive Hybrid QKD–TESLA Authentication for Edge-Assisted 6G Internet of Things Networks

Eman Abouelkheir, Abdalilah Alhalangy

Future sixth-generation (6G) Internet of Things (IoT) environments require scalable authentication for large populations of constrained devices while remaining resilient to quantum-capable adversaries. Quantum key distribution (QKD) can provide high-assurance key material between suitable infrastructure nodes, but direct QKD termination at every low-power endpoint is impractical and the secret-key supply is finite. This paper presents AQ-TESLA, an edge-assisted hybrid authentication architecture that combines infrastructure-facing QKD, ML-KEM fallback, quantum-derived TESLA epoch seeds, delayed key disclosure, authenticated edge synchronization, CoAP transport, and a runtime security controller. The controller jointly evaluates packet loss, attack evidence, congestion, device trust, message criticality, and QKD key-pool status to continue the current TESLA chain, shorten the disclosure interval, or trigger hybrid rekeying. A reproducible systems simulation generated 180,000 events across routine, dense-urban, industrial, emergency, and adversarial scenarios and compared AQ-TESLA with DTLS-CoAP, PQC-CoAP, classical TESLA-CoAP, and Static QKD-TESLA. AQ-TESLA achieved a mean authentication latency of 12.91 ms, P95 latency of 21.24 ms, attack rejection of 97.30%, and authentication success of 98.93%, while consuming 76.9% less QKD key material than static quantum rekeying in the reference workload. Ablation, threshold-sensitivity, bootstrap, and scalability analyses show that pool awareness and adaptive escalation reduce depletion and unnecessary quantum operations. These findings are systems-model results; they are not a physical QKD experiment, a 6G field trial, or a hardware security certification.