A Scalable and Secure Publish/Subscribe-Based Framework for Industrial IoT

被引:1
|
作者
Amoretti, Michele [1 ]
Pecori, Riccardo [2 ]
Protskaya, Yanina [3 ]
Veltri, Luca [1 ]
Zanichelli, Francesco [1 ]
机构
[1] Univ Parma, Dept Engn & Architecture, I-43124 Parma, Italy
[2] Univ Sannio, Dept Engn, I-82100 Benevento, Italy
[3] Maps Grp, I-43122 Parma, Italy
关键词
Standards; Authentication; Production; Authorization; Informatics; authorization; broker bridging; industrial Internet of Things (IIoT); Message Queuing Telemetry Transport (MQTT); security;
D O I
10.1109/TII.2020.3017227
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In the emerging industrial Internet of Things (IIoT) scenario, machine-to-machine communication is a key technology to set up environments, wherein sensors, actuators, and controllers can exchange information autonomously. However, many current communication frameworks do not provide enough dynamic interoperability and security. Hence, in this article, we propose a novel communication framework based on Message Queuing Telemetry Transport (MQTT) broker bridging, which, in an IIoT scenario, can foster dynamic interoperability across different production lines or industrial sites, guaranteeing, at the same time, a higher degree of isolation and control over the information flows, thereby increasing the overall security of the whole scenario. The solution we propose also supports dynamic authentication and authorization and has been practically implemented and evaluated in a proper small-scale IIoT testbed, encompassing PLCs, IIoT gateways, and MQTT brokers with novel and extended capabilities. The evaluation results demonstrate a linear time complexity for all the considered implementations and bridging modes of the extended brokers. Moreover, all considered access token encapsulation techniques demonstrate a minimum overhead in comparison with standard MQTT brokers.
引用
收藏
页码:3815 / 3825
页数:11
相关论文
共 50 条
  • [1] A Comprehensive Security Framework for Publish/Subscribe-Based IoT Services Communication
    Duan, Li
    Sun, Chang-Ai
    Zhang, Yang
    Ni, Wei
    Chen, Junliang
    [J]. IEEE ACCESS, 2019, 7 : 25989 - 26001
  • [2] Benchmarking Publish/Subscribe-Based Messaging Systems
    Sachs, Kai
    Appel, Stefan
    Kounev, Samuel
    Buchmann, Alejandro
    [J]. DATABASE SYSTEMS FOR ADVANCED APPLICATIONS, 2010, 6193 : 203 - +
  • [3] Secure publish/subscribe-based certificate status validations in mobile ad hoc networks
    Masdari, Mohammad
    Jabbehdari, Sam
    Bagherzadeh, Jamshid
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (06) : 1063 - 1076
  • [4] Realizing IoT service's policy privacy over publish/subscribe-based middleware
    Duan, Li
    Zhang, Yang
    Chen, Shiping
    Wang, Shiyao
    Cheng, Bo
    Chen, Junliang
    [J]. SPRINGERPLUS, 2016, 5
  • [5] A Publish/Subscribe-based Programming Language for Sensor Networks
    Dong, Biao
    Chen, Jinhui
    [J]. PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON LOGISTICS, ENGINEERING, MANAGEMENT AND COMPUTER SCIENCE (LEMCS 2015), 2015, 117 : 1805 - 1809
  • [6] A Cross-Layer Security Solution for Publish/Subscribe-based IoT Services Communication Infrastructure
    Zhang, Yang
    Duan, Li
    Sun, Chang-ai
    Cheng, Bo
    Chen, Junliang
    [J]. 2017 IEEE 24TH INTERNATIONAL CONFERENCE ON WEB SERVICES (ICWS 2017), 2017, : 580 - 587
  • [7] An efficient and scalable framework for content-based publish/subscribe systems
    Zhu, Yingwu
    Shen, Haiying
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2008, 1 (01) : 3 - 17
  • [8] An efficient and scalable framework for content-based publish/subscribe systems
    Yingwu Zhu
    Haiying Shen
    [J]. Peer-to-Peer Networking and Applications, 2008, 1 : 3 - 17
  • [9] Scalable Ranked Publish/Subscribe
    Machanavajjhala, Ashwin
    Vee, Erik
    Garofalakis, Minos
    Shanmugasundaram, Jayavel
    [J]. PROCEEDINGS OF THE VLDB ENDOWMENT, 2008, 1 (01): : 451 - 462
  • [10] Towards a semantic-driven and scalable publish/subscribe framework
    Chaabane, Amina
    Diop, Code
    Louati, Wassef
    Jmaiel, Mohamed
    Gomez-Montalvo, Jorge
    Exposito, Ernesto
    [J]. INTERNATIONAL JOURNAL OF INTERNET PROTOCOL TECHNOLOGY, 2013, 7 (03) : 165 - 175