IoTsafe, Decoupling Security From Applications for a Safer IoT
The use of robust security solutions is a must for the Internet of Things (IoT) devices and their applications: regulators in different countries are creating frameworks for certifying those devices with an acceptable security level. However, even for already certified devices, security protocols ha...
Main Authors: | , , , |
---|---|
Format: | Article |
Language: | English |
Published: |
IEEE
2019-01-01
|
Series: | IEEE Access |
Subjects: | |
Online Access: | https://ieeexplore.ieee.org/document/8649577/ |
_version_ | 1819174713962790912 |
---|---|
author | Jorge David De Hoz Diego Jose Saldana Julian Fernandez-Navajas Jose Ruiz-Mas |
author_facet | Jorge David De Hoz Diego Jose Saldana Julian Fernandez-Navajas Jose Ruiz-Mas |
author_sort | Jorge David De Hoz Diego |
collection | DOAJ |
description | The use of robust security solutions is a must for the Internet of Things (IoT) devices and their applications: regulators in different countries are creating frameworks for certifying those devices with an acceptable security level. However, even for already certified devices, security protocols have to be updated when a breach is found or a certain version becomes obsolete. Many approaches for securing IoT applications are nowadays based on the integration of a security layer [e.g., using transport layer security, (TLS)], but this may result in difficulties when upgrading the security algorithms, as the whole application has to be updated. This fact may shorten the life of IoT devices. As a way to overcome these difficulties, this paper presents IoTsafe, a novel approach relying on secure socket shell (SSH), a feasible alternative to secure communications in IoT applications based on hypertext transfer protocol (HTTP and HTTP/2). In order to illustrate its advantages, a comparison between the traditional approach (HTTP with TLS) and our scheme (HTTP with SSH) is performed over low-power wireless personal area networks (6loWPAN) through 802.15.4 interfaces. The results show that the proposed approach not only provides a more robust and easy-to-update solution, but it also brings an improvement to the overall performance in terms of goodput and energy consumption. Core server stress tests are also presented, and the server performance is also analyzed in terms of RAM consumption and escalation strategies. |
first_indexed | 2024-12-22T20:43:21Z |
format | Article |
id | doaj.art-8b80c4d1e2eb4f11afe6f2ab8eef8cbc |
institution | Directory Open Access Journal |
issn | 2169-3536 |
language | English |
last_indexed | 2024-12-22T20:43:21Z |
publishDate | 2019-01-01 |
publisher | IEEE |
record_format | Article |
series | IEEE Access |
spelling | doaj.art-8b80c4d1e2eb4f11afe6f2ab8eef8cbc2022-12-21T18:13:17ZengIEEEIEEE Access2169-35362019-01-017299422996210.1109/ACCESS.2019.29009398649577IoTsafe, Decoupling Security From Applications for a Safer IoTJorge David De Hoz Diego0https://orcid.org/0000-0001-7738-5517Jose Saldana1https://orcid.org/0000-0002-6977-6363Julian Fernandez-Navajas2Jose Ruiz-Mas3I3A, University of Zaragoza, Zaragoza, SpainI3A, University of Zaragoza, Zaragoza, SpainI3A, University of Zaragoza, Zaragoza, SpainI3A, University of Zaragoza, Zaragoza, SpainThe use of robust security solutions is a must for the Internet of Things (IoT) devices and their applications: regulators in different countries are creating frameworks for certifying those devices with an acceptable security level. However, even for already certified devices, security protocols have to be updated when a breach is found or a certain version becomes obsolete. Many approaches for securing IoT applications are nowadays based on the integration of a security layer [e.g., using transport layer security, (TLS)], but this may result in difficulties when upgrading the security algorithms, as the whole application has to be updated. This fact may shorten the life of IoT devices. As a way to overcome these difficulties, this paper presents IoTsafe, a novel approach relying on secure socket shell (SSH), a feasible alternative to secure communications in IoT applications based on hypertext transfer protocol (HTTP and HTTP/2). In order to illustrate its advantages, a comparison between the traditional approach (HTTP with TLS) and our scheme (HTTP with SSH) is performed over low-power wireless personal area networks (6loWPAN) through 802.15.4 interfaces. The results show that the proposed approach not only provides a more robust and easy-to-update solution, but it also brings an improvement to the overall performance in terms of goodput and energy consumption. Core server stress tests are also presented, and the server performance is also analyzed in terms of RAM consumption and escalation strategies.https://ieeexplore.ieee.org/document/8649577/SSHIoTTLSHTTPHTTP/2 |
spellingShingle | Jorge David De Hoz Diego Jose Saldana Julian Fernandez-Navajas Jose Ruiz-Mas IoTsafe, Decoupling Security From Applications for a Safer IoT IEEE Access SSH IoT TLS HTTP HTTP/2 |
title | IoTsafe, Decoupling Security From Applications for a Safer IoT |
title_full | IoTsafe, Decoupling Security From Applications for a Safer IoT |
title_fullStr | IoTsafe, Decoupling Security From Applications for a Safer IoT |
title_full_unstemmed | IoTsafe, Decoupling Security From Applications for a Safer IoT |
title_short | IoTsafe, Decoupling Security From Applications for a Safer IoT |
title_sort | iotsafe decoupling security from applications for a safer iot |
topic | SSH IoT TLS HTTP HTTP/2 |
url | https://ieeexplore.ieee.org/document/8649577/ |
work_keys_str_mv | AT jorgedaviddehozdiego iotsafedecouplingsecurityfromapplicationsforasaferiot AT josesaldana iotsafedecouplingsecurityfromapplicationsforasaferiot AT julianfernandeznavajas iotsafedecouplingsecurityfromapplicationsforasaferiot AT joseruizmas iotsafedecouplingsecurityfromapplicationsforasaferiot |