{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,4]],"date-time":"2026-02-04T16:50:51Z","timestamp":1770223851940,"version":"3.49.0"},"reference-count":21,"publisher":"MDPI AG","issue":"6","license":[{"start":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T00:00:00Z","timestamp":1654041600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Many IoT use cases can benefit from group communication, where a user requests an IoT resource and this request can be handled by multiple IoT devices, each of which may respond back to the user. IoT group communication involves one-to-many requests and many-to-one responses, and this creates security challenges. In this paper, we focus on the provenance that has been received by an authorized device. We provide an effective and flexible solution for securing IoT group communication using CoAP, where a CoAP client sends a request to a CoAP group and receives multiple responses by many IoT devices, acting as CoAP servers. We design a solution that allows CoAP servers to digitally sign their responses in a way that clients can verify that a response has been generated by an authorized member of the CoAP group. In order to achieve our goal, we leverage Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). In particular, we consider that each group is identified by a DID, and each group member has received a VC that allows it to participate in that group. The only information a client needs to know is the DID of the group, which is learned using DNSSEC. Our solution allows group members to rotate their signing keys, it achieves group member revocation, and it has minimal communication and computational overhead.<\/jats:p>","DOI":"10.3390\/fi14060173","type":"journal-article","created":{"date-parts":[[2022,6,1]],"date-time":"2022-06-01T03:33:18Z","timestamp":1654054398000},"page":"173","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["IoT Group Membership Management Using Decentralized Identifiers and Verifiable Credentials"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9100-1081","authenticated-orcid":false,"given":"Nikos","family":"Fotiou","sequence":"first","affiliation":[{"name":"Mobile Multimedia Laboratory, Department of Informatics, School of Information Sciences and Technology, Athens University of Economics and Business, 10434 Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Vasilios A.","family":"Siris","sequence":"additional","affiliation":[{"name":"Mobile Multimedia Laboratory, Department of Informatics, School of Information Sciences and Technology, Athens University of Economics and Business, 10434 Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"George","family":"Xylomenos","sequence":"additional","affiliation":[{"name":"Mobile Multimedia Laboratory, Department of Informatics, School of Information Sciences and Technology, Athens University of Economics and Business, 10434 Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0030-4808","authenticated-orcid":false,"given":"George C.","family":"Polyzos","sequence":"additional","affiliation":[{"name":"Mobile Multimedia Laboratory, Department of Informatics, School of Information Sciences and Technology, Athens University of Economics and Business, 10434 Athens, Greece"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,6,1]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","unstructured":"Rahman, A., and Dijk, E. (2014). Group Communication for the Constrained Application Protocol (CoAP), IETF. RFC 7390.","DOI":"10.17487\/rfc7390"},{"key":"ref_2","unstructured":"Sporny, M., Guy, A., and Sabadello, M. (2022, April 25). Decentralized Identifiers (DIDs) v1.0. W3C Proposed Recommendation, W3C. Available online: https:\/\/www.w3.org\/TR\/did-core\/."},{"key":"ref_3","unstructured":"Sporny, M., Noble, G., Longley, D., Burnett, D.C., Zundel, B., and Hartog, K.D. (2022, April 25). Verifiable Credentials Data Model 1.0. W3C Recommendation, W3C, Available online: https:\/\/www.w3.org\/TR\/verifiable-claims-data-model\/."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Shelby, Z., Hartke, K., and Bormann, C. (2014). The Constrained Application Protocol (CoAP), IETF. RFC 7252.","DOI":"10.17487\/rfc7252"},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Ansey, R., Kempf, J., Berzin, O., Xi, C., and Sheikh, I. (2019, January 9\u201313). Gnomon: Decentralized Identifiers for Securing 5G IoT Device Registration and Software Update. Proceedings of the 2019 IEEE Globecom Workshops (GC Wkshps), Waikoloa, HI, USA.","DOI":"10.1109\/GCWkshps45667.2019.9024702"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Figueroa-Lorenzo, S., A\u00f1orga Benito, J., and Arrizabalaga, S. (2021). Modbus Access Control System Based on SSI over Hyperledger Fabric Blockchain. Sensors, 21.","DOI":"10.3390\/s21165438"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Terzi, S., Savvaidis, C., Votis, K., Tzovaras, D., and Stamelos, I. (2020, January 2\u20136). Securing Emission Data of Smart Vehicles with Blockchain and Self-Sovereign Identities. Proceedings of the 2020 IEEE International Conference on Blockchain (Blockchain), Rhodes, Greece.","DOI":"10.1109\/Blockchain50366.2020.00067"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Fan, X., Chai, Q., Xu, L., and Guo, D. (2020, January 6). DIAM-IoT: A Decentralized Identity and Access Management Framework for Internet of Things. Proceedings of the 2nd ACM International Symposium on Blockchain and Secure Critical Infrastructure, Taipei, Taiwan.","DOI":"10.1145\/3384943.3409436"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"159965","DOI":"10.1109\/ACCESS.2021.3131012","article-title":"Enabling Identity for the IoT-as-a-Service Business Model","volume":"9","author":"Regueiro","year":"2021","journal-title":"IEEE Access"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Fotiou, N., Thomas, Y., Siris, V.A., Xylomenos, G., and Polyzos, G.C. (2021, January 7\u201310). Securing Named Data Networking routing using Decentralized Identifiers. Proceedings of the 2021 IEEE 22nd International Conference on High Performance Switching and Routing (HPSR), Paris, France.","DOI":"10.1109\/HPSR52026.2021.9481850"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Fotiou, N., Siris, V., and Polyzos, G. (2021, January 21). Enabling self-verifiable mutable content items in IPFS using Decentralized Identifiers. Proceedings of the DI2F: Decentralising the Internet with IPFS and Filecoin, IFIP Networking, Espoo, Finland.","DOI":"10.23919\/IFIPNetworking52078.2021.9472820"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Josefsson, S. (2006). The Base16, Base32, and Base64 Data Encodings, IETF. RFC 4648.","DOI":"10.17487\/rfc4648"},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"77","DOI":"10.1007\/s13389-012-0027-1","article-title":"High-speed high-security signatures","volume":"2","author":"Bernstein","year":"2012","journal-title":"J. Cryptogr. Eng."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Bormann, C., and Hoffman, P. (2020). Concise Binary Object Representation (CBOR), IETF. RFC 8949.","DOI":"10.17487\/RFC8949"},{"key":"ref_15","unstructured":"W3C Credentials Community Group (2021). DDID Specification Registries, W3C Credentials Community Group. Working Group Note."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Jones, M., Bradley, J., and Sakimura, N. (2015). JSON Web Signature (JWS), IETF. RFC 7515.","DOI":"10.17487\/RFC7515"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Schaad, J. (2017). CBOR Object Signing and Encryption (COSE), IETF. RFC 8152.","DOI":"10.17487\/RFC8152"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Hoffman, P., and Schlyter, J. (2012). The DNS-Based Authentication of Named Entities (DANE) Transport Layer Security (TLS) Protocol: TLSA, IETF. RFC 6698.","DOI":"10.17487\/rfc6698"},{"key":"ref_19","unstructured":"Sporny, M., and Longley, D. (2021). Revocation List 2020, W3C Credentials Community Group. Draft Community Group Report."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"521","DOI":"10.1109\/TDSC.2018.2825449","article-title":"Memory-efficient implementation of elliptic curve cryptography for the Internet-of-Things","volume":"16","author":"Liu","year":"2018","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_21","unstructured":"af Heurlin, L. (2015). Authorization Certificate based Access Control in Embedded Environments. [Master\u2019s Thesis, Aalto University]."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/6\/173\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T23:23:13Z","timestamp":1760138593000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/6\/173"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,6,1]]},"references-count":21,"journal-issue":{"issue":"6","published-online":{"date-parts":[[2022,6]]}},"alternative-id":["fi14060173"],"URL":"https:\/\/doi.org\/10.3390\/fi14060173","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,6,1]]}}}