Research on Security Enhancement Methods of Internet of Things Communication-Based on Whitelist and Encryption Key Exchange

Tse-Chuan Hsu, Han-Sheng Lu · 2024

In IoT communication, to facilitate the management of the status of all devices and ensure availability under limited network performance, the MQTT communication protocol is used to construct a data exchange mechanism. However, MQTT's transmission mechanism needs built-in encryption, effectively displaying the transmission content in clear text to everyone, raising concerns about information security. At the same time, MQTT's subscription mechanism helps to manage many devices quickly, but this mechanism lacks a set of management protocols to limit the devices that can be subscribed. In the case where any node can subscribe, this study proposes a framework that uses the device's IP and port combined with a whitelist mechanism to distinguish legitimate and illegal subscriptions. After the device requests a subscription, it will be recorded in the Broker, and the message will be broadcast within the topic. However, if the node information is not stored in the whitelist, the message cannot be read because the information transmission process uses asymmetric public key encryption. This situation is called an illegal subscription unless the whitelist is updated and the node is allowed to receive the topic key content, thereby becoming a legitimate subscribing device. In this way, if there are more devices under this topic, you can effectively limit which devices can communicate with these different devices, eliminating concerns about information security. Proposing a new framework to improve the MQTT subscription mechanism not only maintains the convenience of the original protocol but also significantly enhances the protection of the information transmission process. In addition, through experimental content, it is proved that the low latency of the framework can ensure the real-time delivery of messages.

Read the paper · More papers on PaperTik