A Secure IoT Firmware Update Framework Based on MQTT Protocol

被引:7
作者
Lo, Nai-Wei [1 ]
Hsu, Sheng-Hsiang [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Taipei, Taiwan
来源
INFORMATION SYSTEMS ARCHITECTURE AND TECHNOLOGY, ISAT 2019, PT I | 2020年 / 1050卷
关键词
MQTT; IoT; Firmware update; ECDH; AUTHENTICATION;
D O I
10.1007/978-3-030-30440-9_18
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recently massive Internet of Things have been deployed around the world. With data collected from sensors and functionalities provided by microcontroller based devices, new applications have emerged through big data analytics and autonomous real-time system responses. To support quality of service for deployed IoT devices, firmware update is a necessary task for IoT vendors. However, malicious attackers have been penetrated traditional firm-ware update processes and mechanisms to compromise deployed IoT devices, and launch destructive attacks through these controlled devices. In this paper, a secure IoT firmware update framework based on MQTT protocol is proposed. We picture a general firmware update model with IoT devices, gateway devices, firmware distribution broker servers, and firmware deployment servers of IoT vendors. Based on this model, a secure firmware update mechanism is developed to help IoT devices authenticate the source of received firmware and verify the integrity of the received firmware. MQTT protocol is adopted in the proposed framework to efficiently distribute new versions of firmware for IoT vendors. Cryptologic primitives such as Elliptic Curve based Diffie-Hellman key exchange and key-hashed message authentication code are used to secure the proposed process and corresponding protocols. Security analysis is conducted to evaluate security strength of the proposed framework.
引用
收藏
页码:187 / 198
页数:12
相关论文
共 13 条
  • [1] Bamasag O.O., 2015, 2015 WORKSH EMB SYST
  • [2] Cloud-Centric Multi-Level Authentication as a Service for Secure Public Safety Device Networks
    Butun, Ismail
    Erol-Kantarci, Melike
    Kantarci, Burak
    Song, Houbing
    [J]. IEEE COMMUNICATIONS MAGAZINE, 2016, 54 (04) : 47 - 53
  • [3] Chandra H, 2016, ASIA-PAC CONF COMMUN, P115, DOI 10.1109/APCC.2016.7581459
  • [4] Secure firmware validation and update for consumer devices in home networking
    Choi B.-C.
    Lee S.-H.
    Na J.-C.
    Lee J.-H.
    [J]. IEEE Trans Consum Electron, 1 (39-44): : 39 - 44
  • [5] Brightics-IoT: Towards Effective Industrial IoT Platforms for Connected Smart Factories
    Choi, Hyokeun
    Song, JaeSeung
    Yi, Kyuyull
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON INDUSTRIAL INTERNET (ICII 2018), 2018, : 146 - 152
  • [6] Hassan R, 2016, INT CONF E BUS ENG, P188, DOI [10.1109/ICEBE.2016.040, 10.1109/ICEBE.2016.46]
  • [7] Toward a Lightweight Authentication and Authorization Framework for Smart Objects
    Hernandez-Ramos, Jose L.
    Pawlowski, Marcin Piotr
    Jara, Antonio J.
    Skarmeta, Antonio F.
    Ladid, Latif
    [J]. IEEE JOURNAL ON SELECTED AREAS IN COMMUNICATIONS, 2015, 33 (04) : 690 - 702
  • [8] Lightweight and Secure Session-Key Establishment Scheme in Smart Home Environments
    Kumar, Pardeep
    Gurtov, Andrei
    Iinatti, Jari
    Ylianttila, Mika
    Sain, Mangal
    [J]. IEEE SENSORS JOURNAL, 2016, 16 (01) : 254 - 264
  • [9] Lavanya Natarajan, 2016, 6 INT C INT THINGS, P167
  • [10] Nilsson Dennis K., 2008, 2008 IEEE Globecom Workshops, P1, DOI 10.1109/GLOCOMW.2008.ECP.56