MARAS: Mutual Authentication and Role-Based Authorization Scheme for Lightweight Internet of Things Applications

被引:5
|
作者
Seker, Oezlem [1 ,2 ]
Dalkilic, Goekhan [2 ]
cabuk, Umut Can [3 ]
机构
[1] Dokuz Eylul Univ, Grad Sch Nat & Appl Sci, TR-35390 Izmir, Turkiye
[2] Dokuz Eylul Univ, Dept Comp Engn, TR-35390 Izmir, Turkiye
[3] San Diego State Univ, Dept Elect & Comp Engn, San Diego, CA 92182 USA
关键词
authorization; HOTP; IoT; MQTT; mutual authentication; SECURITY; MQTT;
D O I
10.3390/s23125674
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The Internet of things (IoT) accommodates lightweight sensor/actuator devices with limited resources; hence, more efficient methods for known challenges are sought after. Message queue telemetry transport (MQTT) is a publish/subscribe-based protocol that allows resource-efficient communication among clients, so-called brokers, and servers. However, it lacks viable security features beyond username/password checks, yet transport-layer security (TLS/HTTPS) is not efficient for constrained devices. MQTT also lacks mutual authentication among clients and brokers. To address the issue, we developed a mutual authentication and role-based authorization scheme for lightweight Internet of things applications (MARAS). It brings mutual authentication and authorization to the network via dynamic access tokens, hash-based message authentication code (HMAC)-based one-time passwords (HOTP), advanced encryption standard (AES), hash chains, and a trusted server running OAuth2.0 along with MQTT. MARAS merely modifies "publish" and "connect" messages among 14 message types of MQTT. Its overhead to "publish" messages is 49 bytes, and to "connect" messages is 127 bytes. Our proof-of-concept showed that the overall data traffic with MARAS remains lower than double the traffic without it, because "publish" messages are the most common. Nevertheless, tests showed that round-trip times for a "connect" message (and its "ack") are delayed less than a percentile of a millisecond; for a "publish" message, the delays depend on the size and frequency of published information, but we can safely say that the delay is upper bounded by 163% of the network defaults. So, the scheme's overhead to the network is tolerable. Our comparison with similar works shows that while our communication overhead is similar, MARAS offers better computational performance as it offloads computationally intensive operations to the broker side.
引用
收藏
页数:36
相关论文
共 50 条
  • [31] A Molecular-Based Authentication and Authorization for Internet of Things Systems
    Lu, Zhirui
    Amin, Osama
    Shihada, Basem
    2024 IEEE WIRELESS COMMUNICATIONS AND NETWORKING CONFERENCE, WCNC 2024, 2024,
  • [32] Blockchain based lightweight authentication scheme for internet of things using lattice encryption algorithm
    Kuang, Yingpan
    Wu, Qiwen
    Chen, Riqing
    Liu, Xiaolong
    COMPUTER STANDARDS & INTERFACES, 2025, 93
  • [33] A lightweight certificate-based authentication scheme for 6LoWPAN-based internet of things
    Thungon, Leki Chom
    Sahana, Subhas Chandra
    Hussain, Md. Iftekhar
    JOURNAL OF SUPERCOMPUTING, 2023, 79 (11): : 12523 - 12548
  • [34] A lightweight certificate-based authentication scheme for 6LoWPAN-based internet of things
    Leki Chom Thungon
    Subhas Chandra Sahana
    Md. Iftekhar Hussain
    The Journal of Supercomputing, 2023, 79 : 12523 - 12548
  • [35] Research on Lightweight Mutual Authentication for the Product Authorization Chain
    Ding, Hanqing
    Zhang, Qing
    Yin, Yifeng
    Gan, Yong
    Liu, Weihua
    SECURITY AND COMMUNICATION NETWORKS, 2021, 2021
  • [36] Mutual Authentication Scheme in Secure Internet of Things Technology for Comfortable Lifestyle
    Park, Namje
    Kang, Namhi
    SENSORS, 2016, 16 (01):
  • [37] LAMT: Lightweight and Anonymous Authentication Scheme for Medical Internet of Things Services
    Lee, Hyang Jin
    Kook, Sangjin
    Kim, Keunok
    Ryu, Jihyeon
    Lee, Youngsook
    Won, Dongho
    SENSORS, 2025, 25 (03)
  • [38] Lightweight authentication scheme for edge control systems in Industrial Internet of Things
    Shang, Wenli
    Wen, Xudong
    Chen, Zhuo
    Xiong, Wenze
    Chang, Zhiwei
    Cao, Zhong
    FRONTIERS OF INFORMATION TECHNOLOGY & ELECTRONIC ENGINEERING, 2024, 25 (11) : 1466 - 1478
  • [39] A secure and lightweight authentication scheme for digital forensics in industrial internet of things
    Xiao, Nan
    Wang, Zhaoshun
    Sun, Xiaoxue
    ALEXANDRIA ENGINEERING JOURNAL, 2025, 121 : 117 - 127
  • [40] A Lightweight Multifactor Authentication Scheme for Wireless Sensor Networks in the Internet of Things
    Sarbini, Izzatul Nabila
    Khan, Adnan Shahid
    Mohamad, Nurul Zawiyah
    Yusup, Norfadzlan
    2022 INTERNATIONAL CONFERENCE ON GREEN ENERGY, COMPUTING AND SUSTAINABLE TECHNOLOGY (GECOST), 2022, : 482 - 486