Enhancing IoT Security with EAP-PWD: A Resource-Efficient Authentication Solution for Manufacturer Usage Description (MUD)-Based Environments
摘要
The Internet of Things (IoT) has significantly transformed both daily life and industrial pro-cesses, demanding secure and efficient authentication mechanisms for a wide range of devices with varying hardware capabilities. This thesis explores the effectiveness of the Extensible Authentica-ion Protocol - Password (EAP-PWD) in addressing these challenges. EAP-PWD is a lightweight framework designed to balance strong security with minimal resource consumption, making it ideal for IoT applications. This study evaluates EAP-PWD against traditional authentication methods and contemporary solutions, particularly in the context of Manufacturer Usage Descrip-tion (MUD) file retrieval. EAP-PWD employs password-based authentication combined with Elliptic Curve Cryptography (ECC) to provide robust security while mitigating risks such as eavesdropping and man-in-the-middle attacks. In comparison to simpler protocols like Cleartext and EAP-PSK, as well as more resource-intensive approaches such as X.509 certificates, EAP-PWD offers a practical balance of security and operational efficiency. With a transport time of 110 ms and efficient resource usage (15 MB RAM and 7% CPU), it outperforms more complex protocols such as X.509 certificates (324 ms) while maintaining compa-rable performance to EAP-TLS and EAP-MD5. This research demonstrates that EAP-PWD is a viable and preferable solution for IoT environments, where both security and resource limita-tions are critical factors. The findings highlight EAP-PWD’s potential as a secure, lightweight authentication protocol capable of meeting the unique demands of resource-constrained IoT devices.