IoTsafe, Decoupling Security From Applications for a Safer IoT

The use of robust security solutions is a must for the Internet of Things (IoT) devices and their applications: regulators in different countries are creating frameworks for certifying those devices with an acceptable security level. However, even for already certified devices, security protocols ha...

Full description

Bibliographic Details
Main Authors: Jorge David De Hoz Diego, Jose Saldana, Julian Fernandez-Navajas, Jose Ruiz-Mas
Format: Article
Language:English
Published: IEEE 2019-01-01
Series:IEEE Access
Subjects:
Online Access:https://ieeexplore.ieee.org/document/8649577/
_version_ 1819174713962790912
author Jorge David De Hoz Diego
Jose Saldana
Julian Fernandez-Navajas
Jose Ruiz-Mas
author_facet Jorge David De Hoz Diego
Jose Saldana
Julian Fernandez-Navajas
Jose Ruiz-Mas
author_sort Jorge David De Hoz Diego
collection DOAJ
description The use of robust security solutions is a must for the Internet of Things (IoT) devices and their applications: regulators in different countries are creating frameworks for certifying those devices with an acceptable security level. However, even for already certified devices, security protocols have to be updated when a breach is found or a certain version becomes obsolete. Many approaches for securing IoT applications are nowadays based on the integration of a security layer [e.g., using transport layer security, (TLS)], but this may result in difficulties when upgrading the security algorithms, as the whole application has to be updated. This fact may shorten the life of IoT devices. As a way to overcome these difficulties, this paper presents IoTsafe, a novel approach relying on secure socket shell (SSH), a feasible alternative to secure communications in IoT applications based on hypertext transfer protocol (HTTP and HTTP/2). In order to illustrate its advantages, a comparison between the traditional approach (HTTP with TLS) and our scheme (HTTP with SSH) is performed over low-power wireless personal area networks (6loWPAN) through 802.15.4 interfaces. The results show that the proposed approach not only provides a more robust and easy-to-update solution, but it also brings an improvement to the overall performance in terms of goodput and energy consumption. Core server stress tests are also presented, and the server performance is also analyzed in terms of RAM consumption and escalation strategies.
first_indexed 2024-12-22T20:43:21Z
format Article
id doaj.art-8b80c4d1e2eb4f11afe6f2ab8eef8cbc
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2024-12-22T20:43:21Z
publishDate 2019-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-8b80c4d1e2eb4f11afe6f2ab8eef8cbc2022-12-21T18:13:17ZengIEEEIEEE Access2169-35362019-01-017299422996210.1109/ACCESS.2019.29009398649577IoTsafe, Decoupling Security From Applications for a Safer IoTJorge David De Hoz Diego0https://orcid.org/0000-0001-7738-5517Jose Saldana1https://orcid.org/0000-0002-6977-6363Julian Fernandez-Navajas2Jose Ruiz-Mas3I3A, University of Zaragoza, Zaragoza, SpainI3A, University of Zaragoza, Zaragoza, SpainI3A, University of Zaragoza, Zaragoza, SpainI3A, University of Zaragoza, Zaragoza, SpainThe use of robust security solutions is a must for the Internet of Things (IoT) devices and their applications: regulators in different countries are creating frameworks for certifying those devices with an acceptable security level. However, even for already certified devices, security protocols have to be updated when a breach is found or a certain version becomes obsolete. Many approaches for securing IoT applications are nowadays based on the integration of a security layer [e.g., using transport layer security, (TLS)], but this may result in difficulties when upgrading the security algorithms, as the whole application has to be updated. This fact may shorten the life of IoT devices. As a way to overcome these difficulties, this paper presents IoTsafe, a novel approach relying on secure socket shell (SSH), a feasible alternative to secure communications in IoT applications based on hypertext transfer protocol (HTTP and HTTP/2). In order to illustrate its advantages, a comparison between the traditional approach (HTTP with TLS) and our scheme (HTTP with SSH) is performed over low-power wireless personal area networks (6loWPAN) through 802.15.4 interfaces. The results show that the proposed approach not only provides a more robust and easy-to-update solution, but it also brings an improvement to the overall performance in terms of goodput and energy consumption. Core server stress tests are also presented, and the server performance is also analyzed in terms of RAM consumption and escalation strategies.https://ieeexplore.ieee.org/document/8649577/SSHIoTTLSHTTPHTTP/2
spellingShingle Jorge David De Hoz Diego
Jose Saldana
Julian Fernandez-Navajas
Jose Ruiz-Mas
IoTsafe, Decoupling Security From Applications for a Safer IoT
IEEE Access
SSH
IoT
TLS
HTTP
HTTP/2
title IoTsafe, Decoupling Security From Applications for a Safer IoT
title_full IoTsafe, Decoupling Security From Applications for a Safer IoT
title_fullStr IoTsafe, Decoupling Security From Applications for a Safer IoT
title_full_unstemmed IoTsafe, Decoupling Security From Applications for a Safer IoT
title_short IoTsafe, Decoupling Security From Applications for a Safer IoT
title_sort iotsafe decoupling security from applications for a safer iot
topic SSH
IoT
TLS
HTTP
HTTP/2
url https://ieeexplore.ieee.org/document/8649577/
work_keys_str_mv AT jorgedaviddehozdiego iotsafedecouplingsecurityfromapplicationsforasaferiot
AT josesaldana iotsafedecouplingsecurityfromapplicationsforasaferiot
AT julianfernandeznavajas iotsafedecouplingsecurityfromapplicationsforasaferiot
AT joseruizmas iotsafedecouplingsecurityfromapplicationsforasaferiot