Paper 2019/740

A Secure Publish/Subscribe Protocol for Internet of Things

Lukas Malina, Gautam Srivastava, Petr Dzurenda, Jan Hajny, and Radek Fujdiak


The basic concept behind the emergence of Internet of Things (IoT) is to connect as many objects to the Internet as possible in an attempt to make our lives better in some way. However, connecting everyday objects like your car or house to the Internet can open up major security concerns. In this paper, we present a novel security framework for the Message Queue Transport Telemetry (MQTT) protocol based on publish/subscribe messages in order to enhance secure and privacy-friendly Internet of Things services. MQTT has burst onto the IoT scene in recent years due to its lightweight design and ease of use implementation necessary for IoT. Our proposed solution provides 3 security levels. The first security level suits for lightweight data exchanges of non-tampered messages. The second security level enhances the privacy protection of data sources and data receivers. The third security level offers robust long-term security with mutual authentication for all parties. The security framework is based on light cryptographic schemes in order to be suitable for constrained and small devices that are widely used in various IoT use cases. Moreover, our solution is tailored to MQTT without using additional security overhead.

Note: The final publication appears in proceedings of ARES 2019.

Available format(s)
Publication info
Published elsewhere. ARES/IoT-SECFOR 2019
MQTTSecurityCryptographyIoTDigital SignaturePrivacy
Contact author(s)
malina @ feec vutbr cz
2019-06-24: received
Short URL
Creative Commons Attribution


      author = {Lukas Malina and Gautam Srivastava and Petr Dzurenda and Jan Hajny and Radek Fujdiak},
      title = {A Secure Publish/Subscribe Protocol for Internet of Things},
      howpublished = {Cryptology ePrint Archive, Paper 2019/740},
      year = {2019},
      note = {\url{}},
      url = {}
Note: In order to protect the privacy of readers, does not use cookies or embedded third party content.