Effect of payload security in MQTT protocol over transport and application layer
Arunima Varma, Srija UniKrishnan · IOP Conference Series Materials Science and Engineering · 2021
Abstract Digital revolution has made our life dependent on devices that are can be connected to the internet. Hence, making Internet of things (Iot) an inevitable part for now and years to come. The transition from normal devices to those devices that can be connected to internet, has been exponential, in contrast, the technique used by the protocols in those devices to prevent cyber-attacks and keep user data intact has not been in the same pace as that of its usage. This concerns the end user as it risks the data, allowing it to be misused. In this paper we discuss, MQTT (message queue telemetry transport) a lightweight messaging protocol, wherein the payload is acting as the driver for the data to be carried. This payload can include all sort of information, private as well as public. The paper experiments with the vulnerability of the payload when exposed to a cyber-attack, here, Man in the middle (MITM) attack when the same payload is provided with 2 different types of security. Initially at the transport layer and later at the application layer. At first a channel-based security using Transport security layer (TLS) is provided to the payload and later, an object-based security using Advanced Encryption Scheme (AES) is provided to the same payload. Both of these payload encryption technique for MQTT protocol is discussed elaborately.