{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:00:15Z","timestamp":1777806015867,"version":"3.51.4"},"reference-count":74,"publisher":"SAGE Publications","issue":"2","license":[{"start":{"date-parts":[[2017,4,21]],"date-time":"2017-04-21T00:00:00Z","timestamp":1492732800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2017,5,2]]},"abstract":"<jats:p>The number of devices connected through the Internet of Things (IoT) will significantly grow in the next few years while security of their interconnections is going to be a major challenge. For many devices in IoT scenarios, the necessary resources to send and receive bytes are extremely high and when such devices are powered with battery the amount of exchanged bytes directly impacts their life time. As a result, compression of existing protocols is a widely accepted technique to make IoT benefit from the protocols developed over the last decades.<\/jats:p>\n                  <jats:p>This paper presents ESP Header Compression (EHC), a framework that enables compression of packets protected with Encapsulating Security Payload (ESP). EHC is composed of EHC Rules, targeting the compression of a specific field and organized according to EHC Strategies. Further, the paper presents Diet-ESP, an EHC Strategy that highly reduces the networking overhead of ESP packets to address the IoT security and bandwidth requirements. Diet-ESP results in sending fewer bytes which in turn reduces the number of required radio frames and thus battery consumption. The measurements showed that sending 10 byte application data on IEEE 802.15.4 radio networks secured with the standard ESP requires sending an additional frame. This results into a 95% energy overhead compared to the unprotected data, while Diet-ESP results only in a 3% overhead compared to unprotected data.<\/jats:p>\n                  <jats:p>This small overhead is achievable with some compressions being performed within the ESP stack which requires altering the same. Nevertheless, Diet-ESP remains fully security compliant to ESP and performs better than any other compression framework as far as ESP is considered.<\/jats:p>","DOI":"10.3233\/jcs-16857","type":"journal-article","created":{"date-parts":[[2017,4,21]],"date-time":"2017-04-21T10:39:55Z","timestamp":1492771195000},"page":"173-203","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":3,"title":["Diet-ESP: IP layer security for IoT"],"prefix":"10.1177","volume":"25","author":[{"given":"Daniel","family":"Migault","sequence":"first","affiliation":[{"name":"Ericsson Security Research, Montr\u00e9al, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tobias","family":"Guggemos","sequence":"additional","affiliation":[{"name":"MNM-Team, Ludwig-Maximilians-Universit\u00e4t, M\u00fcnchen, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Sylvain","family":"Killian","sequence":"additional","affiliation":[{"name":"Universit\u00e9 Pierre et Marie Curie (UPMC), Paris, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maryline","family":"Laurent","sequence":"additional","affiliation":[{"name":"SAMOVAR, T\u00e9l\u00e9com SudParis, CNRS, Universit\u00e9 Paris-Saclay, EVRY, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guy","family":"Pujolle","sequence":"additional","affiliation":[{"name":"Universit\u00e9 Pierre et Marie Curie (UPMC), Paris, France"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jean Philippe","family":"Wary","sequence":"additional","affiliation":[{"name":"Orange Labs, Issy-les-Moulineaux, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2017,4,21]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"B.\u00a0Aboba, D.\u00a0Simon and P.\u00a0Eronen, Extensible Authentication Protocol (EAP) key management framework. RFC 5247, Aug. 2008.","DOI":"10.17487\/rfc5247"},{"key":"ref002","unstructured":"L.\u00a0Alliance, The LoRA Allicance, 2016."},{"key":"ref003","doi-asserted-by":"crossref","unstructured":"J.\u00a0Arkko, E.\u00a0Carrara, F.\u00a0Lindholm, M.\u00a0Naslund and K.\u00a0Norrman, MIKEY: Multimedia Internet KEYing. RFC 3830, Aug. 2004. Updated by RFCs 4738, 6309.","DOI":"10.17487\/rfc3830"},{"key":"ref004","unstructured":"E.\u00a0Barker and Q.\u00a0Dang, Draft NIST special publication 800-57 part 3 revision 1, Recommendation for Key Management, May 2014."},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"F.\u00a0Bonomi, R.\u00a0Milito, J.\u00a0Zhu and S.\u00a0Addepalli, Fog computing and its role in the Internet of Things, 2012.","DOI":"10.1145\/2342509.2342513"},{"key":"ref006","doi-asserted-by":"crossref","unstructured":"C.\u00a0Bormann, M.\u00a0Ersue and A.\u00a0Keranen, Terminology for constrained-node networks. RFC 7228 (Informational), May 2014.","DOI":"10.17487\/rfc7228"},{"key":"ref007","doi-asserted-by":"crossref","unstructured":"L.\u00a0Catuogno and S.\u00a0Turchi, The dark side of the interconnection: Security and privacy in the web of things, 2015.","DOI":"10.1109\/IMIS.2015.86"},{"key":"ref008","unstructured":"Contiki. Contiki: The open source OS for IoT, 2015."},{"key":"ref009","unstructured":"S.\u00a0Deering and R.\u00a0Hinden, Internet protocol, Version 6 (IPv6) specification. RFC 2460 (Draft Standard), Dec. 1998. Updated by RFCs 5095, 5722, 5871, 6437, 6564, 6935, 6946, 7045, 7112."},{"key":"ref010","doi-asserted-by":"crossref","unstructured":"T.\u00a0Dierks and E.\u00a0Rescorla, The Transport Layer Security (TLS) protocol version 1.2. RFC 5246, Aug. 2008. Updated by RFCs 5746, 5878, 6176.","DOI":"10.17487\/rfc5246"},{"key":"ref011","unstructured":"On the pulse of the networked society, Jun. 2016."},{"key":"ref012","unstructured":"ETSI. Network functions virtualisation (nfv) uses cases. Etsi gs nfv 001 v1.1.1, Network Functions Virtualisation (NFV) ETSI Industry Specification Group (ISG), Oct. 2013."},{"key":"ref013","unstructured":"N.\u00a0Ferguson, Authentication weaknesses in gcm, 2005."},{"key":"ref014","unstructured":"S.\u00a0Fluhrer, Re: [IPsec] Diet-ESP, Feb. 2015."},{"key":"ref015","doi-asserted-by":"crossref","unstructured":"D.\u00a0Forsberg, Y.\u00a0Ohba, B.\u00a0Patil, H.\u00a0Tschofenig and A.\u00a0Yegin, Protocol for Carrying Authentication for Network Access (PANA). RFC 5191, May 2008. Updated by RFC 5872.","DOI":"10.17487\/rfc5191"},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"T.\u00a0Fossati and H.\u00a0Tschofenig, Transport Layer Security (TLS)\/Datagram Transport Layer Security (DTLS) profiles for the Internet of Things. RFC 7925, July 2016.","DOI":"10.17487\/RFC7925"},{"key":"ref017","doi-asserted-by":"crossref","unstructured":"S.\u00a0Frankel and H.\u00a0Herbert, The AES-XCBC-MAC-96 algorithm and its use with IPsec. RFC 3566, Sept. 2003.","DOI":"10.17487\/rfc3566"},{"key":"ref018","doi-asserted-by":"crossref","unstructured":"D.\u00a0Fu and J.\u00a0Solinas, IKE and IKEv2 authentication using the Elliptic Curve Digital Signature Algorithm (ECDSA). RFC 4754, Jan. 2007.","DOI":"10.17487\/rfc4754"},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"O.\u00a0Garcia-Morchon, S.L.\u00a0Keoh, S.\u00a0Kumar, P.\u00a0Moreno-Sanchez, F.\u00a0Vidal-Meca and J.H.\u00a0Ziegeldorf, Securing the ip-based Internet of Things with hip and dtls, in: Proceedings of the Sixth ACM Conference on Security and Privacy in Wireless and Mobile Networks, WiSec \u201913, ACM, New York, NY, USA, 2013, pp.\u00a0119\u2013124. doi:10.1145\/2462096.2462117.","DOI":"10.1145\/2462096.2462117"},{"key":"ref020","unstructured":"Gartner. Gartner Symposium\/ITxpo IoT forecast, Nov. 2015."},{"key":"ref021","unstructured":"Grand View Research. IoT market analysis by component (devices, connectivity, IT services, platforms), by application (consumer electronics, retail, manufacturing, transportation, healthcare) and segment forecasts to 2022, Apr. 2016."},{"key":"ref022","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2013.01.010"},{"key":"ref023","unstructured":"T.\u00a0Guggemos, D.\u00a0Migault and C.\u00a0Bormann, Requirements for Diet-ESP the IPsec\/ESP protocol for IoT. Internet-draft draft-mglt-6lo-diet-esp-requirements-02, Internet Engineering Task Force, July 2016. Work in progress."},{"key":"ref024","unstructured":"T.\u00a0Guggemos, D.\u00a0Migault and Y.\u00a0Nir, Implicit IV for counter-based ciphers in IPsec. Internet-draft draft-mglt-ipsecme-implicit-iv-02, Internet Engineering Task Force, Nov. 2016. Work in progress."},{"key":"ref025","doi-asserted-by":"publisher","DOI":"10.1007\/s11277-011-0385-5"},{"key":"ref026","doi-asserted-by":"crossref","unstructured":"R.\u00a0Housley, Using advanced encryption standard (AES) counter mode with IPsec encapsulating security payload (ESP). RFC 3686, Jan. 2004.","DOI":"10.17487\/rfc3686"},{"key":"ref027","unstructured":"IANA. Internet Key Exchange version 2 (IKEv2) parameters, 2015."},{"key":"ref028","unstructured":"IEEE Computer Society. IEEE standard for local and metropolitan area networks\u00a0\u2013 Part 15.4: Low-Rate Wireless Personal Area Networks (LR-WPANs). IEEE Std 802.15.4 2011 (Revision of IEEE Std 802.15.4 2006), pages 1\u2013314, 2011."},{"key":"ref029","unstructured":"IoT-Lab. IoT experimentation at a large scale, 2015."},{"key":"ref030","unstructured":"IoT-Lab. IoT-LAB M3 nodes, 2015."},{"key":"ref031","doi-asserted-by":"crossref","unstructured":"M.W.J.\u00a0Mattsson, Authentication key recovery on galois counter mode (gcm), Cryptology ePrint Archive, Report 2015\/477, 2015.","DOI":"10.1007\/978-3-319-31517-1_7"},{"key":"ref032","unstructured":"V.\u00a0Jutvik, Implementation of IPsec in Contiki OS, 2011."},{"key":"ref033","doi-asserted-by":"crossref","unstructured":"C.\u00a0Kaufman, P.\u00a0Hoffman, Y.\u00a0Nir, P.\u00a0Eronen and T.\u00a0Kivinen, Internet Key Exchange Protocol version 2 (IKEv2). RFC 7296 (INTERNET STANDARD), Oct. 2014.","DOI":"10.17487\/rfc7296"},{"key":"ref034","doi-asserted-by":"crossref","unstructured":"S.\u00a0Kent, IP Encapsulating Security Payload (ESP). RFC 4303, Dec. 2005.","DOI":"10.17487\/rfc4303"},{"key":"ref035","doi-asserted-by":"crossref","unstructured":"S.\u00a0Kent and K.\u00a0Seo, Security architecture for the Internet protocol. RFC 4301, Dec. 2005. Updated by RFC 6040.","DOI":"10.17487\/rfc4301"},{"key":"ref036","doi-asserted-by":"crossref","unstructured":"T.\u00a0Kivinen, Minimal Internet Key Exchange version 2 (IKEv2) initiator implementation. RFC 7815, Mar. 2016.","DOI":"10.17487\/RFC7815"},{"key":"ref037","doi-asserted-by":"crossref","unstructured":"T.\u00a0Kothmayr, C.\u00a0Schmitt, W.\u00a0Hu, M.\u00a0Br\u00fcnig and G.\u00a0Carle, DTLS based security and two-way authentication for the Internet of Things.\n                      Ad Hoc Networks\n                      , 2013.","DOI":"10.1016\/j.adhoc.2013.05.003"},{"key":"ref038","doi-asserted-by":"publisher","DOI":"10.3390\/info7030044"},{"key":"ref039","unstructured":"S.\u00a0Lucero, IoT platforms: Enabling the Internet of Things, Mar. 2016."},{"key":"ref040","unstructured":"M.\u00a0Maternia and S.\u00a0Eddine, 5G PPP use cases and performance evaluation models, Apr. 2016."},{"key":"ref041","unstructured":"D.\u00a0Migault, Diet-ESP context IKEv2 extension. Internet-draft draft-mglt-6lo-diet-esp-context-ikev2-extension-02, Internet engineering task force, Feb. 2015. Work in progress."},{"key":"ref042","unstructured":"D.\u00a0Migault, T.\u00a0Guggemos and C.\u00a0Bormann, ESP header compression and diet-ESP. Internet-draft draft-mglt-ipsecme-diet-esp-03, Internet Engineering Task Force, Nov. 2016. Work in progress."},{"key":"ref043","unstructured":"D.\u00a0Migault, J.\u00a0Mattsson, P.\u00a0Wouters, Y.\u00a0Nir and T.\u00a0Kivinen, Cryptographic algorithm implementation requirements and usage guidance for Encapsulating Security Payload (ESP) and Authentication Header (AH). Internet-draft draft-ietf-ipsecme-rfc7321bis-00, Internet Engineering Task Force, Oct. 2016. Work in progress."},{"key":"ref044","unstructured":"R.\u00a0Moskowitz and R.\u00a0Hummen, HIP Diet Exchange (DEX). Internet-draft draft-ietf-hip-dex-04, Internet Engineering Task Force, Oct. 2016. Work in progress."},{"key":"ref045","unstructured":"R.\u00a0Moskowitz, P.\u00a0Jokela, T.\u00a0Heer and T.R.\u00a0Henderson, Host Identity Protocol version 2 (HIPv2). RFC 7401, Apr. 2015."},{"key":"ref046","unstructured":"A.\u00a0Nordrum, Popular Internet of Things forecast of 50 billion devices by 2020 is outdated, Aug. 2016."},{"issue":"1","key":"ref047","first-page":"1","volume":"4","author":"Oriwoh E.","year":"2015","journal-title":"International Journal of Internet of Things"},{"key":"ref048","doi-asserted-by":"crossref","unstructured":"J.\u00a0Postel, Internet Protocol. RFC 791 (INTERNET STANDARD), Sept. 1981. Updated by RFCs 1349, 2474, 6864.","DOI":"10.17487\/rfc0791"},{"key":"ref049","unstructured":"S.\u00a0Raza, T.\u00a0Chung, S.\u00a0Duquennoy, D.\u00a0Yazar, T.\u00a0Voigt and U.\u00a0Roedig, Securing internet of Things with lightweight ipsec. SICS Technical Report, Lancaster University, Feb. 2011."},{"key":"ref050","doi-asserted-by":"crossref","unstructured":"S.\u00a0Raza, S.\u00a0Duquennoy, T.\u00a0Chung, D.\u00a0Yazar, T.\u00a0Voigt and U.\u00a0Roedig, Securing communication in 6LoWPAN with compressed IPsec, in: Distributed Computing in Sensor Systems and Workshops (DCOSS), 2011 International Conference on, 2011, pp.\u00a01\u20138. doi:10.1109\/DCOSS.2011.5982146.","DOI":"10.1109\/DCOSS.2011.5982146"},{"key":"ref051","doi-asserted-by":"crossref","unstructured":"S.\u00a0Raza, S.\u00a0Duquennoy, J.\u00a0H\u00f6glund, U.\u00a0Roedig and T.\u00a0Voigt, Secure communication for the Internet of Things\u00a0\u2013 A\u00a0comparison of link-layer security and IPsec for 6LoWPAN,\n                      Security and Communication Networks\n                      , Wiley, Jan. 2012.","DOI":"10.1002\/sec.406"},{"key":"ref052","unstructured":"S.\u00a0Raza, S.\u00a0Duquennoy and G.\u00a0Selander, Compression of IPsec AH and ESP headers for constrained environments. Internet-draft draft-raza-6lowpan-ipsec-01, Internet Engineering Task Force, Sept. 2013."},{"key":"ref053","doi-asserted-by":"publisher","DOI":"10.1109\/JSEN.2013.2277656"},{"key":"ref054","doi-asserted-by":"crossref","unstructured":"S.\u00a0Raza, D.\u00a0Trabalza and T.\u00a0Voigt, 6lowpan compressed dtls for coap, in: Distributed Computing in Sensor Systems (DCOSS), 2012 IEEE 8th International Conference on, IEEE, 2012, pp.\u00a0287\u2013289. doi:10.1109\/DCOSS.2012.55.","DOI":"10.1109\/DCOSS.2012.55"},{"key":"ref055","unstructured":"E.\u00a0Rescorla, The Transport Layer Security (TLS) protocol version 1.3. Internet-draft draft-ietf-tls-tls13-18, Internet Engineering Task Force TLS Working Group, Oct. 2016. Work in progress."},{"key":"ref056","doi-asserted-by":"crossref","unstructured":"E.\u00a0Rescorla and N.\u00a0Modadugu, Datagram transport layer security version 1.2. RFC 6347, Jan. 2012.","DOI":"10.17487\/rfc6347"},{"key":"ref057","doi-asserted-by":"crossref","unstructured":"A.R.\u00a0Sadeghi, C.\u00a0Wachsmann and M.\u00a0Waidner, Security and privacy challenges in industrial Internet of Things, in: The 52nd Annual Design Automation Conference, Unknown, ed. 2015, pp.\u00a01\u20136.","DOI":"10.1145\/2744769.2747942"},{"key":"ref058","unstructured":"S.\u00a0Lucero, Internet of Things (IoT) market by software solution (Real-time streaming analytics, security, data management, remote monitoring, and network bandwidth management), platform, service, application domain, and region\u00a0\u2013 global forecast to 2021, Apr. 2016."},{"key":"ref059","unstructured":"S.\u00a0Chakrabarti and G.\u00a0Montenegro, IPv6 over networks of resource-constrained nodes working group (6lo), 2016."},{"key":"ref060","doi-asserted-by":"crossref","unstructured":"Y.\u00a0Sheffer and S.\u00a0Fluhrer, Additional Diffie\u2013Hellman tests for the Internet Key Exchange Protocol version 2 (IKEv2). RFC 6989, July 2013.","DOI":"10.17487\/rfc6989"},{"key":"ref061","doi-asserted-by":"crossref","unstructured":"Z.\u00a0Shelby and C.\u00a0Bormann, 6LoWPAN: The Wireless Embedded Internet, Wiley Publishing, 2010.","DOI":"10.1002\/9780470686218"},{"key":"ref062","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2014.11.008"},{"key":"ref063","unstructured":"SigFox. SigFox, 2016."},{"key":"ref064","doi-asserted-by":"crossref","unstructured":"R.\u00a0Singh, G.\u00a0Kalyani, Y.\u00a0Nir, Y.\u00a0Sheffer and D.\u00a0Zhang, Protocol support for high availability of IKEv2\/IPsec. RFC 6311, July 2011.","DOI":"10.17487\/rfc6311"},{"issue":"1","key":"ref065","first-page":"16","volume":"2","author":"Skala K.","year":"2015","journal-title":"Open Journal of Cloud Computing (OJCC)"},{"key":"ref066","doi-asserted-by":"publisher","DOI":"10.1080\/19393551003649016"},{"key":"ref067","unstructured":"V.\u00a0Smyslov, Compact format of IKEv2 payloads. Internet-draft draft-smyslov-ipsecme-ikev2-compact-00, Internet Engineering Task Force, Oct. 2016. Work in progress."},{"key":"ref068","doi-asserted-by":"crossref","unstructured":"V.\u00a0Smyslov, Compression in the Internet Key Exchange protocol version 2 (IKEv2). Internet-draft draft-smyslov-ipsecme-ikev2-compression-02, Internet Engineering Task Force, Sept. 2016. Work in progress.","DOI":"10.17487\/RFC7791"},{"key":"ref069","unstructured":"T.Kivinen and D.\u00a0Waltermire, IP Security Maintenance and Extensions Working Group (ipsecme), 2016."},{"key":"ref070","doi-asserted-by":"crossref","unstructured":"V.\u00a0Valancius, N.\u00a0Laoutaris, L.\u00a0Massouli\u00e9, C.\u00a0Diot and P.\u00a0Rodriguez, Greening the Internet with nano data centers, 2009.","DOI":"10.1145\/1658939.1658944"},{"key":"ref071","doi-asserted-by":"crossref","unstructured":"F.\u00a0Vidal Meca, J.\u00a0Ziegeldorf, P.\u00a0Sanchez, O.\u00a0Morchon, S.\u00a0Kumar and S.\u00a0Keoh, Hip security architecture for the ip-based Internet of Things, in: Advanced Information Networking and Applications Workshops (WAINA), 2013 27th International Conference on, 2013, pp.\u00a01331\u20131336. doi:10.1109\/WAINA.2013.158.","DOI":"10.1109\/WAINA.2013.158"},{"key":"ref072","doi-asserted-by":"crossref","unstructured":"M.\u00a0Vucinic, B.\u00a0Tourancheau, F.\u00a0Rousseau, A.\u00a0Duda, L.\u00a0Damon and R.\u00a0Guizzetti, OSCAR: object security architecture for the Internet of Things,\n                      CoRR\n                      (2014), arXiv:1404.7799.","DOI":"10.1109\/WoWMoM.2014.6918975"},{"key":"ref073","doi-asserted-by":"crossref","unstructured":"D.\u00a0Whiting, R.\u00a0Housley and N.\u00a0Ferguson, Counter with CBC-MAC (CCM). RFC 3610 (Informational), Sept. 2003.","DOI":"10.17487\/rfc3610"},{"key":"ref074","doi-asserted-by":"crossref","unstructured":"T.\u00a0Xu, J.B.\u00a0Wendt and M.\u00a0Potkonjak, Security of IoT systems: Design challenges and opportunities, 2014.","DOI":"10.1109\/ICCAD.2014.7001385"}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-16857","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-16857","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-16857","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:02Z","timestamp":1777495502000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-16857"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,4,21]]},"references-count":74,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2017,5,2]]}},"alternative-id":["10.3233\/JCS-16857"],"URL":"https:\/\/doi.org\/10.3233\/jcs-16857","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,4,21]]}}}