Software-Defined Runtime Reconfiguration of Cryptographic Service Chains for IIoT Edge Nodes
Abstract
In Industrial Internet of Things (IIoT) environments, the security requirements of edge nodes change dynamically, whereas conventional cryptographic deployment relies on static configurations that require firmware upgrades or system reboots for algorithm updates, severely limiting flexibility and maintainability. To address this issue, this paper proposes a software-defined runtime reconfiguration mechanism for cryptographic service chains on OS-capable IIoT edge nodes. By decoupling cryptographic processing logic definition from its execution environment, the control plane generates integrity-protected executable service chains, which are dynamically loaded and executed at runtime on the edge node. A prototype implemented on a Raspberry Pi edge node supports dynamic composition and switching among AES, SM4, SHA-256, and SM3, and incorporates HMAC-based integrity verification, version-based rollback prevention, and a smooth transition mechanism supported by kernel buffering. Experimental results show millisecond-level processing latency and a middleware overhead of 3.9–5.2% relative to a static baseline in the same Python interpreter environment, while the reconfiguration latency satisfies the real-time constraints of typical IIoT edge applications. The security and deployment boundaries of the proposed approach are also analyzed.