Lukman AB Rahim
Universiti Teknologi Petronas

Published : 2 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 2 Documents
Search

A java servlet based transaction broker for internet of things edge device communications Zainatul Yushaniza Mohamed Yusoff; Mohamad Khairi Ishak; Lukman AB Rahim
Bulletin of Electrical Engineering and Informatics Vol 11, No 1: February 2022
Publisher : Institute of Advanced Engineering and Science

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.11591/eei.v11i1.3455

Abstract

Internet of things (IoT) technology is growing exponentially in almost every sphere of life. IoT offers several innovation capabilities and features, but they are also prone to security vulnerabilities and risks. These vulnerabilities must be studied to protect these technologies from being exploited by others. Cryptography techniques and approaches are commonly used to address and deal with security vulnerabilities. In general, the message queuing telemetry transport (MQTT) is an application layer protocol vulnerable to various known and unknown security issues. One possible solution is to introduce an encryption algorithm into the MQTT communication protocol for secure transmission. This study aims to solve the security problem of IoT traffic by using a secure and lightweight communication proxy. The strategy behind this communication broker acts as a network gateway providing secure transaction keys to all IoT nodes in the network. This task uses a java servlet and elliptic curve cryptography (ECC) algorithm to generate identity encryption keys in a component-based web transaction infrastructure. This approach encrypts the data before it is sent via the MQTT protocol to secure the communication channel and raise the security device and network transactions. 
Securing IoT edge device communication with efficient ECC middleware for resource-constrained systems Zainatul Yushaniza Mohamed Yusoff; Mohamad Khairi Ishak; Lukman AB Rahim
Bulletin of Electrical Engineering and Informatics Vol 13, No 6: December 2024
Publisher : Institute of Advanced Engineering and Science

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.11591/eei.v13i6.7602

Abstract

The internet of things (IoT) rapidly grows into various parts of life. However, it has significant obstacles during setup and deployment, particularly in terms of network segmentation, administration, and security at all tiers, from physical to application. While IoT provides several advanced features and benefits, it is also vulnerable to security threats and flaws that must be thoroughly investigated to avoid misuse. Cryptographic approaches are routinely used to address these security concerns. Message queuing telemetry transport (MQTT), an application layer protocol, is vulnerable to various known and undisclosed security flaws. Integrating encryption techniques within the MQTT protocol to provide secure data flow is a potential strategy for increasing security. This study provides a middleware broker that improves authentication processes, securing connections between cloud servers and resource-constrained devices. Using a Java Servlet and the elliptic curve cryptography (ECC) technique, the study creates a system for creating encrypted identification keys within a web-based transaction framework. This system intends to provide asymmetric authentication that is energy and resource-efficient, with a focus on cost minimization. It also includes a security feature to protect users from common internet threats. The system's efficacy, including its low energy usage of only 4 mJ per device, is thoroughly tested, proving it meets the original protocol criteria.