Message Queue Telemetry Transport (MQTT) is a lightweight publish/subscribe protocol widely adopted in industrial and IoT scenarios, where end-to-end protection of application data is a key requirement. However, conventional MQTT deployments provide only hop-by-hop security by protecting communications between clients and brokers at the transport or network layer using protocols such as TLS, DTLS, or IPsec. As a result, if the broker is not fully trusted, true end-to-end security cannot be guaranteed. This paper presents SMQTT, an application-layer framework that enables group-based end-to-end security for MQTT communications without requiring modifications to the standard broker. The framework relies on a dedicated key server that handles client authentication, authorization, and group key distribution. The distributed key material is then used by authorized publishers and subscribers to securely exchange application data, ensuring authenticity, confidentiality, and replay protection, while forward and backward secrecy are provided by the update and slotted methods. Protected data is transmitted as standard MQTT payloads and transparently forwarded by the broker. A reference implementation has been developed and tested with both standard and embedded clients, demonstrating the framework's feasibility on general-purpose and resource-constrained systems.
SMQTT: An End-to-End Security Framework for MQTT-Based Industrial IoT Communications / Yousaf, F., Veltri, L., Penzotti, G., Zanichelli, F.. - (2026), pp. 1-7. (2026 6th International Conference on Electrical, Computer and Energy Technologies (ICECET) ) [10.1109/ICECET65726.2026.11632926].
SMQTT: An End-to-End Security Framework for MQTT-Based Industrial IoT Communications
Yousaf F.
;Veltri L.
;Penzotti G.;Zanichelli F.
2026-01-01
Abstract
Message Queue Telemetry Transport (MQTT) is a lightweight publish/subscribe protocol widely adopted in industrial and IoT scenarios, where end-to-end protection of application data is a key requirement. However, conventional MQTT deployments provide only hop-by-hop security by protecting communications between clients and brokers at the transport or network layer using protocols such as TLS, DTLS, or IPsec. As a result, if the broker is not fully trusted, true end-to-end security cannot be guaranteed. This paper presents SMQTT, an application-layer framework that enables group-based end-to-end security for MQTT communications without requiring modifications to the standard broker. The framework relies on a dedicated key server that handles client authentication, authorization, and group key distribution. The distributed key material is then used by authorized publishers and subscribers to securely exchange application data, ensuring authenticity, confidentiality, and replay protection, while forward and backward secrecy are provided by the update and slotted methods. Protected data is transmitted as standard MQTT payloads and transparently forwarded by the broker. A reference implementation has been developed and tested with both standard and embedded clients, demonstrating the framework's feasibility on general-purpose and resource-constrained systems.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


