On Cross-Domain Security Architecture for MQTT-SN in Constrained IoT Systems
En cours de chargement...
Date
Authors
Nom de la revue
ISSN de la revue
Titre du volume
Éditeur
Université d'Ottawa | University of Ottawa
Résumé
The rapid growth of limited Internet of Things (IoT) devices has made it even more important to have lightweight, reliable, and secure communication protocols that can operate in environments with limited processing power, memory, and energy. MQTT-SN is a version of MQTT that works with sensor networks that do not use IP. It has a good publish-subscribe model, but lacks key security features, making IoT applications vulner-
able. MQTT-SN inherits almost all the properties and features of MQTT, along with its vulnerabilities, and the MQTT-SN specification does not specify how to address the security requirements of MQTT-SN components. This gap drives a thorough examination of MQTT-SN’s security in real-world deployments critical to safety and privacy. This thesis introduces a cohesive security framework for MQTT-SN, formulated and corroborated within three illustrative IoT domains: Vehicle-to-Vehicle and Vehicle-to-Emergency-Services (V2S) communication, smart lock systems, and continuous glucose monitoring (CGM) healthcare devices.
The thesis presents an adapted SREP/SQUARE methodology specifically designed for IoT ecosystems, facilitating the systematic identification of assets, threats, and security requirements. This framework is utilized for all three use cases, generating comprehensive threat models and prioritized security requirements that account for the limitations and risks associated with constrained devices and publish-subscribe architectures.
Later, the thesis presents comprehensive security architectures for V2S, smart lock, and CGM systems. These include protocols for onboarding, key establishment, message
protection, and access control, in detail. We use Scyther for formal verification, timing and energy analysis on limited hardware, and comparisons with existing technologies and commercial products to test these architectures. The results show that the proposed designs offer strong authentication, privacy, integrity, authorization, and replay protection. This work improves the security of IoT communication by providing the first complete, cross-domain security architecture for MQTT-SN. It shows that MQTT-SN can be a strong, scalable, and efficient way for different IoT applications to communicate, as long as it is properly secured. These applications can include smart homes, healthcare, and vehicle safety systems.
Description
Mots-clés
MQTT-SN, Security, Constrained Devices, Internet of Things

