The relevance of the research is driven by the need for continuous improvement of security assessment mechanisms for cryptographic key distribution protocols amid the annual growth of cyberattacks (15–20%) and the expanding use of low-resource devices (microprocessor cards, IoT). Existing protocol comparison methods often focus only on individual aspects, failing to provide a comprehensive view of their efficiency. The aim of the article is to develop and verify a software-based approach for quantitative comparison of protocol efficiency, taking into account security properties (G1–G9), resistance to attacks (A1–A7), and hardware constraints (memory, number of messages). The proposed approach is based on multi‑criteria evaluation with weight coefficients, which reduces subjectivity when selecting a protocol for specific operating conditions. Using modifications of the Diffie–Hellman protocol (STS, MTI, DH1, DH2) as examples, generalised efficiency indicators were obtained, with the highest for DH1 (0.754). For practical verification, a Python program using the cryptography and hashlib libraries was developed, implementing RSA‑2048, DH‑2048, and ECDH‑P256. Experiments show that ECDH‑P256 provides the shortest shared secret computation time (0.000713 s), which is 21 times faster than DH‑2048. Modelling of an FPGA‑based hardware accelerator demonstrated a 4‑fold speedup for ECDH operations compared to pure software implementation. The results confirm the applicability of the developed approach for selecting optimal protocols under severe hardware constraints. The findings are intended for specialists in secure information systems and IoT device developers, and can also be used to create standardised methods for evaluating cryptographic protocols.
ILIPOV M.M.
Master of physics and computer technologies, senior lecturer at the department of computer science, deputy director for educational and social work, Saken Seifullin Kazakh agrotechnical research university, Astana, Kazakhstan.
E-mail: Marlen.ilipov@mail.ru, https://orcid.org/0009-0005-8224-8847
AMANGELDI N.N.
2nd year student of the educational program «Business Informatics», Saken Seifullin Kazakh agrotechnical research university, Astana, Kazakhstan.
E-mail: nurshatamangeldi@gmail.com, https://orcid.org/0009-0006-4626-4513
- D(HE)at Attack Project Page. D(HE)at: A Denial-of-Service Attack on the Finite Field Diffie-Hellman Key Exchange Protocol. URL: https://dheatattack.gitlab.io/ (date of request: 07.04.2026).
- CVE-2022-40735. The Diffie-Hellman Key Agreement Protocol allows use of long exponents. National Vulnerability Database. URL: https://nvd.nist.gov/vuln/detail/CVE-2022-40735
- Barker E. B., Johnson D. B., Smid M. E. SP 800-56A. Recommendation for Pair-Wise Key Establishment Schemes Using Discrete Logarithm Cryptography (Revised). National Institute of Standards and Technology (NIST). 2007. URL: https://www.nist.gov/publications/recommendation-pair-wise-key-establishment-using-discrete-logarithm-cryptography
- Высокоскоростные устройства для приведения чисел по модулю. Вестник АУЭС. 2022. URL: https://vestnik.aues.kz/ (дата обращения: 07.04.2026).
- Черемушкин А.В. Криптографические протоколы. Основные свойства и уязвимости. Москва: академия, 2009. 272 с. URL: https://search.library.dvfu.ru/Record/239952
- A systematic review of lightweight cryptographic schemes for security and privacy in IoT. Discover Computing. 2025. Vol. 28. Article number 266. URL: https://link.springer.com/article/10.1007/s10791-025-09755-3 DOI: https://doi.org/10.1007/s10791-025-09755-3
- Al-shmailawi H. A., Al-Hemiary E. H., Sikora A. Comprehensive Review of NIST Lightweight Cryptography Algorithms for IoT: Performance Evaluation, Attacks, Optimizations, and Protocol Integration. Iraqi Journal of Information and Communication Technology. 2025. Vol. 8, № 3. URL: https://www.ijict.edu.iq/index.php/ijict/article/view/336 DOI: https://doi.org/10.31987/ijict.8.3.336
- The Python Cryptography Authors. Cryptography Documentation. Release 43.0.1. 2024. URL: https://cryptography.io/ (date of request: 07.04.2026).
- Gheorghies A. S., Lazaroi D. M., Simion E. A Comparative Study of Cryptographic Key Distribution Protocols. IACR Cryptology ePrint Archive. 2021. Vol. 2021. P. 31. URL: https://eprint.iacr.org/2021/031.
- CVE-2024-41996. Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol... National Vulnerability Database. URL: https://nvd.nist.gov/vuln/detail/CVE-2024-41996
- Python Software Foundation. Python 3.12.3 Documentation. URL: https://docs.python.org/3/ (date of request: 07.04.2026).
- Simanjuntak P. J. N. Komposisi Efisiensi Metode Autentikasi Berbasis ECDHE-ECDSA dan ECDHE-RSA pada SSL/TLS Protokol Komunikasi IoT pada Mikroprosesor ESP32 (Master's thesis). Universitas Sumatera Utara, 2023. URL:https://repositori.usu.ac.id/handle/123456789/92951
