CMXsafe: A Proxy Layer for Securing Internet-of-Things Communications

被引:1
|
作者
de Hoz Diego, Jorge David [1 ]
Madi, Taous [1 ]
Konstantinou, Charalambos [1 ]
机构
[1] King Abdullah Univ Sci & Technol, Comp Elect & Math Sci & Engn Div, Thuwal 23955, Saudi Arabia
关键词
Internet-of-Things; secure communications; socket proxy; secure proxy session; security context;
D O I
10.1109/TIFS.2024.3404258
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Security in Internet-of-Things (IoT) environments has become a major concern. This is partly due to a large number of remotely exploitable IoT vulnerabilities in service authentication and access control combined with the lack of timely technical support. To reduce the threat surface of remote vulnerability exploitation, we propose CMXsafe, a secure-by-design application-agnostic proxy layer that can be updated and managed independently of the IoT device application. CMXsafe places IoT devices behind gateways operating as 4th OSI transport layer relayers to offload security concerns of IoT network communications into the proxy layer. Specifically, the proxy layer produces secure communication paths between IoT applications and platforms while enforcing mutual authentication and access control to proxied services. We evaluate the performance of our architecture on the MQTT protocol used in a standard publisher-broker-subscriber configuration provided by Eclipse Mosquitto. We compare the performance penalty on the protocol when securing communications with TLS following a monolithic implementation and with CMXsafe. The experimental results suggest that CMXsafe outperforms integrated security by providing at least a 25% latency reduction and a 22% bandwidth improvement.
引用
收藏
页码:5767 / 5782
页数:16
相关论文
共 50 条
  • [21] Securing the Insecure Link of Internet-of-Things Using Next-Generation Smart Gateways
    Hussain, Syed Rafiul
    Bertino, Elisa
    Nirjon, Shahriar
    2019 15TH INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING IN SENSOR SYSTEMS (DCOSS), 2019, : 66 - 73
  • [22] An Energy-Efficient Reconfigurable DTLS Cryptographic Engine for Securing Internet-of-Things Applications
    Banerjee, Utsav
    Wright, Andrew
    Juvekar, Chiraag
    Waller, Madeleine
    Arvind
    Chandrakasan, Anantha P.
    IEEE JOURNAL OF SOLID-STATE CIRCUITS, 2019, 54 (08) : 2339 - 2352
  • [23] Embedded Intelligence in the Internet-of-Things
    Dick, Robert P.
    Shang, Li
    Wolf, Marilyn
    Yang, Shao-Wen
    IEEE DESIGN & TEST, 2020, 37 (01) : 7 - 27
  • [24] Architectural Survey on Internet-of-Things
    Bharti, Monika
    Kumar, Raj Esh
    Saxena, Sharad
    2019 FIFTH INTERNATIONAL CONFERENCE ON IMAGE INFORMATION PROCESSING (ICIIP 2019), 2019, : 437 - 442
  • [25] Securing Things in the Healthcare Internet of Things
    MacDermott, Aine
    Kendrick, Phillip
    Idowu, Ibrahim
    Ashall, Mal
    Shi, Qi
    2019 GLOBAL IOT SUMMIT (GIOTS), 2019,
  • [26] How to Agentify the Internet-of-Things?
    Maamar, Zakaria
    Faci, Noura
    Boukadi, Khouloud
    Ugljanin, Emir
    Sellami, Mohamed
    Baker, Thar
    Angarita, Rafael
    2018 12TH INTERNATIONAL CONFERENCE ON RESEARCH CHALLENGES IN INFORMATION SCIENCE (RCIS), 2018,
  • [27] Instrumentation and measurement in the Internet-of-Things
    Jardim-Goncalves, Ricardo
    IEEE INSTRUMENTATION & MEASUREMENT MAGAZINE, 2019, 22 (06) : 3 - 3
  • [28] The Obligatory Internet-of-Things Column
    Davidson, Scott
    IEEE DESIGN & TEST, 2014, 31 (04) : 71 - 72
  • [29] Proxy-Based Adaptive Transmission of MP-QUIC in Internet-of-Things Environment
    Firmansyah, Muhammad Hafidh
    Jung, Joong-Hwa
    Koh, Seok-Joo
    ELECTRONICS, 2021, 10 (17)
  • [30] Cognitive Machine-to-Machine Communications for Internet-of-Things: A Protocol Stack Perspective
    Aijaz, Adnan
    Aghvami, A. Hamid
    IEEE INTERNET OF THINGS JOURNAL, 2015, 2 (02): : 103 - 112