Return
MQTT-E: E2E encryption in MQTT via proxy re-encryption avoiding broker overloading
DOI:10.1016/j.adhoc.2025.103878.png)
Abstract
En 中文
A smart traffic monitoring system in smart city surveillance requires publisher and subscriber MQTT-enabled vehicles to share sensitive vehicle and route data with semi-trusted RSU nodes as brokers. To ensure end-to-end confidentiality, we propose the use of an RSU broker as a proxy to perform re-encryption of the exchanged messages between publisher and subscriber vehicles. The RSU brokers are implemented as serverless edge devices with the proxy re-encryption functions designed as function-as-a-service. In peak traffic scenarios, the RSU proxy brokers can become overloaded and drop the re-encryption operations. Additionally, a malicious actor can send counterfeit re-encryption requests to overload the brokers leading to Denial-of-Service attacks. In this paper, we propose a novel solution to mitigate DoS attacks by balancing the re-encryption functions from overloaded brokers. This problem is modeled as an online optimization problem, solved using a greedy heuristic approach, and compared with a baseline approach. The objective function is to reallocate the minimum number of clients when brokers are overloaded since this operation brings additional overhead for clients. Our experimental analysis shows that the greedy approach manages to move up to 5 times fewer clients than the baseline approach, depending on the scenario considered.
Keywords:
MQTT
Smart traffic monitoring
Proxy re-encryption
Broker overloading
End-to-end confidentiality
AI Summary
Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.
Journal
IF:
4.8
Papers:
486
Citations:
6.2K

