Towards improving the Privacy in the MQTT Protocol

Marten Fischer, Daniel Kümper, R. Tönjes
{"title":"Towards improving the Privacy in the MQTT Protocol","authors":"Marten Fischer, Daniel Kümper, R. Tönjes","doi":"10.1109/GIOTS.2019.8766366","DOIUrl":null,"url":null,"abstract":"The Internet of Things (IoT) is growing rapidly as more and more household appliances, sensors and actuators are connected to the internet and communicate with each other. Because these IoT devices usually have only limited processing and communication capabilities, an efficient communication protocol is required to reduce the protocol overhead. The Message Queue Telemetry Transport (MQTT) protocol provides such properties. MQTT is a publish/subscribe protocol, where each client can subscribe to a message topic in order to receive all messages published under that topic. The payload of a message (i.e., the content) can be encrypted to hide private information. However, to forward messages, the topic of a message needs to be read by the broker and thus cannot be encrypted and might reveal private information. This paper presents methods to avoid this problem. It features and evaluates a one-time password approach to provide a fully obfuscated communication method for MQTT topics. Thereby, the user tracking and the generation of profiles is prevented.","PeriodicalId":149504,"journal":{"name":"2019 Global IoT Summit (GIoTS)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-06-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 Global IoT Summit (GIoTS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/GIOTS.2019.8766366","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

Abstract

The Internet of Things (IoT) is growing rapidly as more and more household appliances, sensors and actuators are connected to the internet and communicate with each other. Because these IoT devices usually have only limited processing and communication capabilities, an efficient communication protocol is required to reduce the protocol overhead. The Message Queue Telemetry Transport (MQTT) protocol provides such properties. MQTT is a publish/subscribe protocol, where each client can subscribe to a message topic in order to receive all messages published under that topic. The payload of a message (i.e., the content) can be encrypted to hide private information. However, to forward messages, the topic of a message needs to be read by the broker and thus cannot be encrypted and might reveal private information. This paper presents methods to avoid this problem. It features and evaluates a one-time password approach to provide a fully obfuscated communication method for MQTT topics. Thereby, the user tracking and the generation of profiles is prevented.
MQTT协议中保密性的改进
随着越来越多的家用电器、传感器和执行器连接到互联网并相互通信,物联网(IoT)正在迅速发展。由于这些物联网设备通常只有有限的处理和通信能力,因此需要有效的通信协议来减少协议开销。消息队列遥测传输(MQTT)协议提供了这些属性。MQTT是一种发布/订阅协议,其中每个客户机都可以订阅消息主题,以便接收在该主题下发布的所有消息。消息的有效载荷(即内容)可以加密以隐藏私有信息。然而,要转发消息,消息的主题需要由代理读取,因此不能加密,并且可能会泄露私有信息。本文提出了避免这一问题的方法。它提供并评估了一次性密码方法,为MQTT主题提供了完全模糊化的通信方法。从而避免了用户跟踪和概要文件的生成。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信