CMXsafe: A Proxy Layer for Securing Internet-of-Things Communications

被引:1
|
作者
de Hoz Diego, Jorge David [1 ]
Madi, Taous [1 ]
Konstantinou, Charalambos [1 ]
机构
[1] King Abdullah Univ Sci & Technol, Comp Elect & Math Sci & Engn Div, Thuwal 23955, Saudi Arabia
关键词
Internet-of-Things; secure communications; socket proxy; secure proxy session; security context;
D O I
10.1109/TIFS.2024.3404258
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Security in Internet-of-Things (IoT) environments has become a major concern. This is partly due to a large number of remotely exploitable IoT vulnerabilities in service authentication and access control combined with the lack of timely technical support. To reduce the threat surface of remote vulnerability exploitation, we propose CMXsafe, a secure-by-design application-agnostic proxy layer that can be updated and managed independently of the IoT device application. CMXsafe places IoT devices behind gateways operating as 4th OSI transport layer relayers to offload security concerns of IoT network communications into the proxy layer. Specifically, the proxy layer produces secure communication paths between IoT applications and platforms while enforcing mutual authentication and access control to proxied services. We evaluate the performance of our architecture on the MQTT protocol used in a standard publisher-broker-subscriber configuration provided by Eclipse Mosquitto. We compare the performance penalty on the protocol when securing communications with TLS following a monolithic implementation and with CMXsafe. The experimental results suggest that CMXsafe outperforms integrated security by providing at least a 25% latency reduction and a 22% bandwidth improvement.
引用
收藏
页码:5767 / 5782
页数:16
相关论文
共 50 条
  • [31] An Internet-of-Things Educational Platform
    Alsukayti, Ibrahim S.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2019, 19 (07): : 127 - 136
  • [32] Connection models for the Internet-of-Things
    He, Kangli
    Hermanns, Holger
    Wu, Hengyang
    Chen, Yixiang
    FRONTIERS OF COMPUTER SCIENCE, 2020, 14 (03)
  • [33] Metamaterial-loaded multiband antenna for embedded automotive Internet-of-Things communications
    Malathy, E. M.
    Thanikachalam, V
    Ruby, D.
    Manikandan, N.
    INTERNATIONAL JOURNAL OF COMMUNICATION SYSTEMS, 2021, 34 (15)
  • [34] Panel on Cloud and Internet-of-Things
    Fox, Geoffrey
    2015 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E 2015), 2015, : 234 - 234
  • [35] Connection models for the Internet-of-Things
    Kangli He
    Holger Hermanns
    Hengyang Wu
    Yixiang Chen
    Frontiers of Computer Science, 2020, 14
  • [36] Educating the Internet-of-Things Generation
    Kortuem, Gerd
    Bandara, Arosha K.
    Smith, Neil
    Richards, Mike
    Petre, Marian
    COMPUTER, 2013, 46 (02) : 53 - 61
  • [37] A Secure Key Exchange and Authentication Scheme for Securing Communications in the Internet of Things Environment
    Peivandizadeh, Ali
    Adarbah, Haitham Y.
    Molavi, Behzad
    Mohajerzadeh, Amirhossein
    Al-Badi, Ali H.
    FUTURE INTERNET, 2024, 16 (10)
  • [38] Securing the Internet of Things (IoT)
    El bekkali, Abla
    Boulmalf, Mohammed
    Essaaidi, Mohammad
    Mezzour, Ghita
    2018 6TH INTERNATIONAL CONFERENCE ON WIRELESS NETWORKS AND MOBILE COMMUNICATIONS (WINCOM), 2018, : 211 - 216
  • [39] Challenges to Securing the Internet of Things
    Stout, William M. S.
    Urias, Vincent E.
    2016 IEEE INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2016, : 1 - 8
  • [40] Relay-Energy Access Points for Internet-of-Things Wireless Energy Harvesting and Communications
    George, Jithin
    Yeoh, Phee Lep
    Krongold, Brian S.
    ICC 2019 - 2019 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2019,