{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,24]],"date-time":"2025-08-24T01:22:07Z","timestamp":1755998527618},"reference-count":27,"publisher":"Engineering and Technology Publishing","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["jcm"],"published-print":{"date-parts":[[2021]]},"abstract":"<jats:p>Security of Internet of Things (IoT) has been one of the most critical topics since IoT devices took part in daily life. Due to resource constrained nature of IoT networks, meeting requirements of a secure infrastructure always becomes a challenge. The most prevalent method is to rely on conventional application layer protocols to secure IoT network traffic but due to IoT device capabilities, limited mobile network resources and battery powered structure of IoT nodes, most of them are not applicable in practice. Provisioning a new node into a running network also suffers from these challenges. In this study, we investigate whether pure algorithm based protocols can be used to solve secure provisioning of resource limited IoT devices problem. Trusted IoT node provisioning requires new node authentication, authorization for network credentials, secret key generation for data privacy, and distribution of secret keys. Besides that, key management for rejoining nodes should be considered due to mobility of IoT nodes. We propose an Elliptic Curve Cryptography (ECC) based solution to cover these security requirements. Our design environment has also ability to analyze power consumption of each node during node enabling into a secure network.<\/jats:p>","DOI":"10.12720\/jcm.16.8.341-346","type":"journal-article","created":{"date-parts":[[2021,10,20]],"date-time":"2021-10-20T03:51:00Z","timestamp":1634701860000},"page":"341-346","source":"Crossref","is-referenced-by-count":5,"title":["End-to-End Secure IoT Node Provisioning"],"prefix":"10.12720","author":[{"name":"Department of Electronics and Communication Engineering, Istanbul Technical University, Istanbul, 34469, Turkey","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ilker","family":"Yavuz","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Berna","family":"Ors","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"4977","published-online":{"date-parts":[[2021]]},"reference":[{"key":"ref0","unstructured":"[1] M. Sethi, B. Sarikaya, and D. Garcia-Carillo, \"Secure IoT Bootstrapping: A Survey,\" Internet Engineering Task Force, 2020."},{"key":"ref1","doi-asserted-by":"publisher","unstructured":"[2] N. Koblitz, \"Elliptic curve cryptosystems,\" Mathematics of Computation, vol. 48, pp. 203-209, 1 1987.","DOI":"10.1090\/S0025-5718-1987-0866109-5"},{"key":"ref2","doi-asserted-by":"publisher","unstructured":"[3] L. Lamport, \"Password authentication with insecure communication,\" Commun. ACM, vol. 24, pp. 770-772, 1981.","DOI":"10.1145\/358790.358797"},{"key":"ref3","doi-asserted-by":"publisher","unstructured":"[4] C. Adams, \"Replay attack,\" in Encyclopedia of Cryptography and Security, H. C. A. van Tilborg and S. Jajodia, Eds., Boston, MA: Springer US, 2011, pp. 1042-1042.","DOI":"10.1007\/978-1-4419-5906-5_92"},{"key":"ref4","doi-asserted-by":"publisher","unstructured":"[5] J. H\u00f6glund, S. Lindemer, M. Furuhed, and S. Raza, \"PKI4IoT: Towards public key infrastructure for the internet of things,\" Comput. Secur., vol. 89, 2020.","DOI":"10.1016\/j.cose.2019.101658"},{"key":"ref5","unstructured":"[6] R. Cragie, Y. Ohba, R. S. Moskowitz, Z. Cao, and B. Sarikaya, Security Bootstrapping Solution for Resource-Constrained Devices, 2012."},{"key":"ref6","doi-asserted-by":"publisher","unstructured":"[7] B. Aboba, L. Blunk, J. Vollbrecht, J. Carlson, and H. Levkowetz, Extensible Authentication Protocol (EAP), RFC Editor, 2004.","DOI":"10.17487\/rfc3748"},{"key":"ref7","unstructured":"[8] D. Garcia-Carrillo and R. L\u00f3pez, EAP-based Authentication Service for CoAP, 2017."},{"key":"ref8","doi-asserted-by":"publisher","unstructured":"[9] D. Forsberg, B. Patil, H. Tschofenig, and A. Yegin, Protocol for Carrying Authentication for Network Access (PANA), RFC Editor, 2008.","DOI":"10.17487\/rfc5191"},{"key":"ref9","unstructured":"[10] B. Sarikaya, Y. Ohba, Z. Cao, and R. Cragie, \"Security bootstrapping of resource-constrained devices,\" Internet Engineering Task Force, 2010."},{"key":"ref10","unstructured":"[11] 3GPP, \"Generic Authentication Architecture (GAA),\" Technical Specification Group Services and System Aspects, 2016."},{"key":"ref11","doi-asserted-by":"publisher","unstructured":"[12] D. C. Neuman, S. Hartman, K. Raeburn, and T. Yu, The Kerberos Network Authentication Service (V5), RFC Editor, 2005.","DOI":"10.17487\/rfc4120"},{"key":"ref12","doi-asserted-by":"crossref","unstructured":"[13] T. Aura and M. Sethi, \"Nimble out-of-band authentication for EAP (EAP-NOOB),\" Internet Engineering Task Force, 2020.","DOI":"10.17487\/RFC9140"},{"key":"ref13","unstructured":"[14] O. Bergmann, S. Gerdes, and C. Bormann, Simple Keys for Simple Smart Objects, 2012."},{"key":"ref14","doi-asserted-by":"publisher","unstructured":"[15] A. Peltonen, E. Ingl\u00e9s, S. Latvala, D. Garcia-Carrillo, M. Sethi, and T. Aura, \"Enterprise security for the internet of things (IoT): Lightweight bootstrapping with EAP-NOOB,\" Sensors, vol. 20, p. 6101, 10 2020.","DOI":"10.3390\/s20216101"},{"key":"ref15","doi-asserted-by":"publisher","unstructured":"[16] G. Zorn and D. Harkins, Extensible Authentication Protocol (EAP) Authentication Using Only a Password, RFC Editor, 2010.","DOI":"10.17487\/rfc5931"},{"key":"ref16","doi-asserted-by":"publisher","unstructured":"[17] S. Cirani, M. Picone, P. Gonizzi, L. Veltri, and G. Ferrari, \"IoT-OAS: An oauth-based authorization service architecture for secure services in IoT scenarios,\" IEEE Sensors Journal, vol. 15, no. 2, pp. 1224-1234, 2015.","DOI":"10.1109\/JSEN.2014.2361406"},{"key":"ref17","doi-asserted-by":"publisher","unstructured":"[18] D. Garcia-Carrillo and R. Marin-Lopez, \"Lightweight CoAP-Based bootstrapping service for the internet of things,\" Sensors, vol. 16, p. 358, 2016.","DOI":"10.3390\/s16030358"},{"key":"ref18","doi-asserted-by":"publisher","unstructured":"[19] M. Hossain and R. Hasan, \"Boot-IoT: A privacy-aware authentication scheme for secure bootstrapping of IoT Nodes,\" in Proc. IEEE International Congress on Internet of Things, 2017.","DOI":"10.1109\/IEEE.ICIOT.2017.10"},{"key":"ref19","doi-asserted-by":"publisher","unstructured":"[20] D. Simon, R. Hurst, and D. B. D. Aboba, The EAP-TLS Authentication Protocol, RFC Editor, 2008.","DOI":"10.17487\/rfc5216"},{"key":"ref20","doi-asserted-by":"publisher","unstructured":"[21] J. Sanchez-Gomez, D. Garcia-Carrillo, R. Marin-Perez, R. Sanchez-Iborra, and A. F. S. Gomez, \"Secure bootstrapping and header compression for IoT constrained networks,\" in Global Internet of Things Summit (GIoTS), 2020.","DOI":"10.1109\/GIOTS49054.2020.9119644"},{"key":"ref21","doi-asserted-by":"publisher","unstructured":"[22] A. Ghedini and V. Vasiliev, TLS Certificate Compression, RFC Editor, 2020.","DOI":"10.17487\/RFC8879"},{"key":"ref22","doi-asserted-by":"publisher","unstructured":"[23] B. Preneel, \"New European Schemes for Signature, Integrity and Encryption (NESSIE): A status report,\" in Public Key Cryptography, Berlin, 2002.","DOI":"10.1007\/3-540-45664-3_21"},{"key":"ref23","doi-asserted-by":"publisher","unstructured":"[24] . L. Rivest, A. Shamir, and L. Adleman, \"A method for obtaining digital signatures and public-key cryptosystems,\" Commun. ACM, vol. 21, pp. 120-126, 2 1978.","DOI":"10.1145\/359340.359342"},{"key":"ref24","unstructured":"[25] T. Winter, P. Thubert, A. Brandt, J. Hui, R. Kelsey, P. Levis, K. Pister, R. Struik, J. P. Vasseur, and R. Alexander, RPL: IPv6 Routing Protocol for Low-Power and Lossy Networks, RFC Editor, 2012."},{"key":"ref25","unstructured":"[26] A. Dunkels, J. Eriksson, N. Finne, and N. Tsiftes, Powertrace: Network-level Power Profiling for Low-power Wireless Networks, 2011."},{"key":"ref26","doi-asserted-by":"publisher","unstructured":"[27] D. Harkins and D. Carrel, The Internet Key Exchange (IKE), RFC Editor, 1998.","DOI":"10.17487\/rfc2409"}],"container-title":["Journal of Communications"],"original-title":[],"link":[{"URL":"http:\/\/www.jocm.us\/uploadfile\/2021\/0720\/20210720030223778.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,12]],"date-time":"2023-01-12T18:27:41Z","timestamp":1673548061000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.jocm.us\/show-258-1678-1.html"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":27,"URL":"https:\/\/doi.org\/10.12720\/jcm.16.8.341-346","relation":{},"ISSN":["2374-4367"],"issn-type":[{"type":"print","value":"2374-4367"}],"subject":[],"published":{"date-parts":[[2021]]}}}