Lightweight Sensor Data Encryption on ESP32 Using the Pi Number for Dynamic Operations
Since intercepted sensor data can reveal user activities, lightweight cryptography is essential for protecting information in resource-constrained devices. Although ARX-based lightweight schemes offer high computational efficiency, their lack of inherent non-linear substitution and permutation layers motivates their integration into secure cryptographic designs. This paper proposes LSEPI (Lightweight Sensor Encryption Using PI), a lightweight stream cipher for protecting electrical sensor data. LSEPI employs a single-round substitution-permutation design that combines the AES substitution box with a key-dependent dynamic permutation and a dynamically selected XOR mask derived from the secret key and the digits of the number π. To mitigate the computational cost of pseudorandom sequence generation, the first 20 KB of the decimal expansion of π are stored on both the ESP32 and Android device. Encryption is performed on the ESP32 during the simultaneous acquisition and computation of voltage, current, power, and energy, while decryption is performed on an Android application for user-selected time intervals. Statistical evaluation shows that LSEPI achieves an entropy of 7.9971 with a single encryption round, comparable to Speck-CTR with 32 rounds (7.9970) and Ascon (7.9969), and higher than the approximately 7.18 reported for recent lightweight proposals. The encrypted data also satisfies the chi-square goodness-of-fit criterion, exhibits correlation coefficients close to zero, and achieves average avalanche effects of 50.005% for one-bit plaintext changes and 50.08% for one-bit key changes. GLCM-based texture metrics are comparable to those of Speck-CTR and Ascon. The known-plaintext analysis indicates that recovering the key-dependent masking sequence requires determining or inverting the key-dependent permutation; thus, despite the use of XOR operations, the attack does not directly succeed. From a computational perspective, LSEPI requires 135 μs per sensor record after initialization, adding only 0.04% overhead to the computation of the electrical variables on the ESP32.
Authors
- Moisés Salinas-Rosales (ORCID: https://orcid.org/0000-0002-2167-2792)
- Rolando Flores-Carapia (ORCID: https://orcid.org/0000-0002-8557-9941)
- Manuel Alejandro Cardona-López (ORCID: https://orcid.org/0000-0001-8810-9921)
- Jaime Robles García (ORCID: https://orcid.org/0009-0004-0226-4429)
- Santiago Segura-Romo (ORCID: https://orcid.org/0009-0009-4012-7042)
- Aura Luz Barcenas-Medina (ORCID: https://orcid.org/0009-0000-3358-088X)
Institutions
- Universidad La Salle (BO)
- Universidad La Salle (MX)
- Instituto Politécnico Nacional (MX)
Publication Details
- Journal
- Technologies
- Published
- 2026-09-22
- DOI
- https://doi.org/10.3390/technologies14100595
- Primary Topic
- Cryptographic Implementations and Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00