Access Control on Internet of Things based on Publish/Subscribe using Authentication Server and Secure Protocol

Aulia Arif Wardana, Riza Satria Perdana
{"title":"Access Control on Internet of Things based on Publish/Subscribe using Authentication Server and Secure Protocol","authors":"Aulia Arif Wardana, Riza Satria Perdana","doi":"10.1109/ICITEED.2018.8534855","DOIUrl":null,"url":null,"abstract":"This study proposes a prototype model from access control security system in the Internet of Things (IoT) that uses the Message Queuing Telemetry Transport (MQTT) protocol as its communication and fog computing as its architecture with the authentication server and secure protocol. In the MQTT protocol, there are security mechanism issues such as publisher (device) authentication and data privacy protection is still not good. This causes the integrity and confidentiality of a data used by the subscriber to be less secure. Device nodes and gateway devices in IoT that become publishers will be authenticated to obtain tokens using authentication server via HTTPS. Tokens are embedding with sensor data inside secure payload format and publish to MQTT broker. Authentication server will perform management and validation credentials on all publishers and secure payload in MQTT broker. In addition, SSL certificates are applied to the MQTT protocol to secure their communications. Based on evaluation and security analysis, the application of access control mechanisms can be implemented on the MQTT protocol and can secure the integrity and confidentiality of data that sent from the device to the cloud over the internet. In the overhead analysis, there is a significant increase in payload because of the payload data sent with the token, but the latency of delivery time, CPU, memory usage is still up to a reasonable limit of not more than 50%.","PeriodicalId":142523,"journal":{"name":"2018 10th International Conference on Information Technology and Electrical Engineering (ICITEE)","volume":"19 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-07-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"19","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 10th International Conference on Information Technology and Electrical Engineering (ICITEE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICITEED.2018.8534855","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 19

Abstract

This study proposes a prototype model from access control security system in the Internet of Things (IoT) that uses the Message Queuing Telemetry Transport (MQTT) protocol as its communication and fog computing as its architecture with the authentication server and secure protocol. In the MQTT protocol, there are security mechanism issues such as publisher (device) authentication and data privacy protection is still not good. This causes the integrity and confidentiality of a data used by the subscriber to be less secure. Device nodes and gateway devices in IoT that become publishers will be authenticated to obtain tokens using authentication server via HTTPS. Tokens are embedding with sensor data inside secure payload format and publish to MQTT broker. Authentication server will perform management and validation credentials on all publishers and secure payload in MQTT broker. In addition, SSL certificates are applied to the MQTT protocol to secure their communications. Based on evaluation and security analysis, the application of access control mechanisms can be implemented on the MQTT protocol and can secure the integrity and confidentiality of data that sent from the device to the cloud over the internet. In the overhead analysis, there is a significant increase in payload because of the payload data sent with the token, but the latency of delivery time, CPU, memory usage is still up to a reasonable limit of not more than 50%.
基于认证服务器和安全协议发布/订阅的物联网访问控制
本研究提出了一个物联网(IoT)访问控制安全系统的原型模型,该模型使用消息队列遥测传输(MQTT)协议作为其通信,雾计算作为其架构,并使用认证服务器和安全协议。在MQTT协议中,存在发布者(设备)身份验证和数据隐私保护还不够好的安全机制问题。这会导致订阅者使用的数据的完整性和机密性不那么安全。物联网中成为发布者的设备节点和网关设备将通过HTTPS使用身份验证服务器进行身份验证以获取令牌。令牌与传感器数据一起嵌入在安全有效负载格式中,并发布到MQTT代理。身份验证服务器将对MQTT代理中的所有发布者和安全有效负载执行管理和验证凭据。此外,将SSL证书应用于MQTT协议以保护它们的通信。基于评估和安全分析,访问控制机制的应用可以在MQTT协议上实现,并且可以确保通过internet从设备发送到云的数据的完整性和机密性。在开销分析中,由于与令牌一起发送的有效负载数据,因此有效负载显著增加,但交付时间、CPU、内存使用的延迟仍然达到不超过50%的合理限制。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信