<p>In modern Internet of Things (IoT) environments, the demand for secure and efficient communication protocols is more urgent than ever due to privacy and security challenges. Current solutions often fail to adequately protect user anonymity and location privacy. The Constrained Application Protocol (CoAP), a lightweight communication protocol, is particularly suitable for resource-constrained devices in IoT and sensor networks. This paper provides a detailed analysis of CoAP’s security features using a modular symbolic model and the Tamarin prover. We identify a major flaw: insufficient anonymity, which could allow malicious attackers to track users’ location information. To address this issue, we propose CoAP<InlineEquation ID="IEq1"> <InlineMediaObject> <ImageObject Color="BlackWhite" FileRef="11227_2025_7401_Article_IEq1.gif" Format="GIF" Height="10" Rendition="HTML" Resolution="72" Type="Linedraw" Width="11" /> </InlineMediaObject> <EquationSource Format="TEX">\(^+\)</EquationSource> <EquationSource Format="MATHML"><math> <mmultiscripts> <mrow /> <mrow /> <mo>+</mo> </mmultiscripts> </math></EquationSource> </InlineEquation>, an enhanced version of the protocol that improves both anonymity and overall security. This research not only offers a practical method for analyzing the security of IoT devices but also highlights the importance of addressing anonymity concerns and suggests actionable improvement strategies.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Enhancing privacy and security in IoT: a CoAP protocol analysis and improvement approach

  • Guangying Cai,
  • Liujia Cai,
  • Xinyue Cui,
  • Siqi Lu,
  • Yongjuan Wang,
  • Xiangyu Wang,
  • Haoyuan Xue

摘要

In modern Internet of Things (IoT) environments, the demand for secure and efficient communication protocols is more urgent than ever due to privacy and security challenges. Current solutions often fail to adequately protect user anonymity and location privacy. The Constrained Application Protocol (CoAP), a lightweight communication protocol, is particularly suitable for resource-constrained devices in IoT and sensor networks. This paper provides a detailed analysis of CoAP’s security features using a modular symbolic model and the Tamarin prover. We identify a major flaw: insufficient anonymity, which could allow malicious attackers to track users’ location information. To address this issue, we propose CoAP \(^+\) + , an enhanced version of the protocol that improves both anonymity and overall security. This research not only offers a practical method for analyzing the security of IoT devices but also highlights the importance of addressing anonymity concerns and suggests actionable improvement strategies.