New Group-Key-Based Over the Air (OTA) Update Model Facilitating Security and Efficiency Using MQTT 5
摘要
The booming development of Internet-of-Things (IoT) has deployed many IoT systems globally, and this trend is continuously accelerating. However, as many IoT devices are widely deployed, the system-update maintenance is a huge challenge. Over The Air (OTA) update is one promising mechanism for securely updating the firmware of the remote IoT devices. Message Queue Telemetry Transport (MQTT) is one of the most adopted IoT communication protocols globally. It has also been popularly adopted as the communication protocol for delivering the OTA update messages, in addition to delivering normal IoT messages. This paper focuses on MQTT-based OTA models. Even though there exist several MQTT-based OTA models and schemes, we find that no one can simultaneously satisfying user convenience, efficiency and high security. Some sacrifices the privacy against the MQTT broker to achieve user convenience, and some focuses on the privacy while sacrificing the convenience. This paper sorts out the existent models and proposes a new model that distributes the group keys among the manager and the IoT devices, allows the manager deposit the group-key-encrypting firmware on the broker, and then each device can separately access the encrypted OTA images from the broker. We design the scheme using MQTT 5.0 (the new MQTT standard). The analysis and the evaluation show that the new model achieves better privacy protection and gains efficient communication performance.