Cert Bind-DKEP: A Certificate- Hash-Bound Dual-Curve Ephemeral Key Establishment Protocol for Lightweight MQTT-IoT Security

Main Article Content

DVPS Pranavi, Saliha Bathool

Abstract

Internet of Things (IoT) deployments have rapidly grown over time, necessitating the development of lightweight and efficient authentication methods suited for such systems. Although MQTT has become the de facto communication standard within the scope of IoT ecosystems, many issues require solutions regarding the establishment of secure session keys and lightweight authentication. In this paper, the proposed protocol, 3L-EKEP, which provides both lightweight authentication and session-key establishment capabilities for secure MQTT-based communications within IoT devices, will be presented. This protocol includes certificate-hash bindings, pre-shared-key challenge validation, dual Elliptic Curve Diffie-Hellman key exchanges with P-256 and X25519, HKDF-SHA256-derived session keys, and AES-GCM data transfer. The protocol was implemented via the Python programming language and evaluated experimentally. The security of the protocol was examined based on factors including authentication binding, session-key uniqueness, session-key independence, avalanche effect, and ciphertext tampering detection. Based on the experimental results, it was determined that the protocol generated 1000 unique session keys in 1000 executions without any collisions. On the other hand, the average percentage of bits different from the previous session key in the independence tests was around 50%, and the avalanche effect tests revealed that the average number of bits changed was 48.83%. With respect to the performance of the protocol, it was determined that during 1000 protocol executions, the average latency was found to be 2.224 ms, with 2.532 ms and 2.862 ms being the P95 and P99 latencies.

Article Details

Section
Articles