Securing CoAP with DTLS and OSCORE
Emil Suleymanov, Erkin Kirdan, Marc‐Oliver Pahl · 2022
The Constrained Application Protocol (CoAP) is a lightweight protocol commonly deployed in the Internet of Things (IoT). It is designed to be encrypted with Datagram Transport Layer Security (DTLS). However, DTLS adds a considerable overhead and breaks the end-to-end encryption in gateways and proxies. Thus, Object Security for Constrained RESTful Environments (OSCORE) is introduced as a new alternative with lower overhead. This paper evaluates the two options for securing CoAP: DTLS and OSCORE. OSCORE has a privacy problem caused by plain-text header fields, which expose the communication meta-data. However, it always holds end-to-end encryption, unlike DTLS. The evaluation includes the comparison of the total frame lengths for the same CoAP messages. The results show that OSCORE has a smaller bandwidth overhead than DTLS. Furthermore, server response time for a request, which represents CPU usage, is also measured. The CPU-favourable protocol depends on the message exchange rate; DTLS is a better option in long-lived sessions, otherwise OSCORE.