{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T18:34:46Z","timestamp":1784918086547,"version":"3.55.0"},"reference-count":28,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2025,6,30]],"date-time":"2025-06-30T00:00:00Z","timestamp":1751241600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Internet of Things (IoT) technology in healthcare has enabled innovative services that enhance patient monitoring, diagnostics and medical data management. However, securing sensitive health data while maintaining system efficiency of resource-constrained IoT devices remains a critical challenge. This work presents a comprehensive end-to-end IoT security framework for healthcare environments, addressing encryption at two key levels: lightweight encryption at the edge for resource-constrained devices and robust end-to-end encryption when transmitting data to the cloud via MQTT cloud brokers. The proposed system leverages multi-broker MQTT architecture to optimize resource utilization and enhance message reliability. At the edge, lightweight cryptographic techniques ensure low-latency encryption before transmitting data via a secure MQTT broker hosted within the hospital infrastructure. To safeguard data as it moves beyond the hospital to the cloud, stronger end-to-end encryption are applied to ensure end-to-end security, such as AES-256 and TLS 1.3, to ensure confidentiality and resilience over untrusted networks. A proof-of-concept Python 3.10 -based MQTT implementation is developed using open-source technologies. Security and performance evaluations demonstrate the feasibility of the multi-layer encryption approach, effectively balancing computational overhead with data protection. Security and performance evaluations demonstrate that our novel HECS4MQTT (Health Edge Cloud Security for MQTT) framework achieves a unique balance between efficiency and security. Unlike existing solutions that either impose high computational overhead at the edge or rely solely on transport-layer protection, HECS4MQTT introduces a layered encryption strategy that decouples edge and cloud security requirements. This design minimizes processing delays on constrained devices while maintaining strong cryptographic protection when data crosses trust boundaries. The framework also introduces a lightweight bridge component for re-encryption and integrity enforcement, thereby reducing broker compromise risk and supporting compliance with healthcare security regulations. Our HECS4MQTT framework offers a scalable, adaptable, and trust-separated security model, ensuring enhanced confidentiality, integrity, and availability of healthcare data while remaining suitable for deployment in real-world, latency-sensitive, and resource-limited medical environments.<\/jats:p>","DOI":"10.3390\/fi17070298","type":"journal-article","created":{"date-parts":[[2025,7,1]],"date-time":"2025-07-01T04:04:22Z","timestamp":1751342662000},"page":"298","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["HECS4MQTT: A Multi-Layer Security Framework for Lightweight and Robust Encryption in Healthcare IoT Communications"],"prefix":"10.3390","volume":"17","author":[{"given":"Saud","family":"Alharbi","sequence":"first","affiliation":[{"name":"Department of Computer Science, Brunel University, Uxbridge UB8 3PH, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wasan","family":"Awad","sequence":"additional","affiliation":[{"name":"College of Information Technology, Ahlia University, Manama 10878, Bahrain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"David","family":"Bell","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Brunel University, Uxbridge UB8 3PH, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,6,30]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"97197","DOI":"10.1109\/ACCESS.2022.3205351","article-title":"Security in the Internet of Things Application Layer: Requirements, Threats, and Solutions","volume":"10","author":"Abbasi","year":"2022","journal-title":"IEEE Access"},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"113292","DOI":"10.1109\/ACCESS.2021.3103725","article-title":"Recent Security Trends in Internet of Things: A Comprehensive Survey","volume":"9","author":"Harbi","year":"2021","journal-title":"IEEE Access"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"4132","DOI":"10.1109\/JIOT.2020.3026493","article-title":"Lightweight Cryptographic Protocols for IoT Constrained Devices: A Survey","volume":"8","author":"Khan","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"751","DOI":"10.18576\/amis\/190402","article-title":"Lightweight Security Scheme for Internet of Things Encryption","volume":"19","author":"Alharbi","year":"2025","journal-title":"Appl. Math. Inf. Sci."},{"key":"ref_5","unstructured":"OASIS Standard (2025, June 01). MQTT Version 5.0. OASIS. Available online: https:\/\/docs.oasis-open.org\/mqtt\/mqtt\/v5.0\/mqtt-v5.0.html."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Singh, M., Rajan, M.A., Shivraj, V.L., and Balamuralidhar, P. (2015, January 4\u20136). Secure MQTT for Internet of Things (IoT). Proceedings of the 5th International Conference on Communication Systems and Networks Technologies, Gwalior, India.","DOI":"10.1109\/CSNT.2015.16"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Pal, P., Lauer, G., Khoury, J., Hoff, N., and Loyall, J. (2012, January 3\u20137). P3S: A privacy preserving publish-subscribe middleware. Proceedings of the ACM\/IFIP\/USENIX International Conference on Distributed Systems Platforms and Open Distributed Processing, Montreal, QC, Canada.","DOI":"10.1007\/978-3-642-35170-9_24"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Wang, J., Zhang, J., Schooler, E.M., and Ion, M. (2014, January 10\u201314). Performance evaluation of attribute-based encryption: Toward data privacy in the IoT. Proceedings of the IEEE International Conference on Communications (ICC), Sydney, Australia.","DOI":"10.1109\/ICC.2014.6883405"},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Bisne, L., and Parmar, M. (2017, January 21\u201322). Composite secure MQTT for Internet of Things using ABE and dynamic S-box AES. Proceedings of the 2017 Innovations in Power and Advanced Computing Technologies (IPACT), Vellore, India.","DOI":"10.1109\/IPACT.2017.8245126"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Iqbal, M., Laksmono, A.M.A., Prihatno, A.T., Pratama, D., Jeong, B., and Kim, H. (2023, January 16\u201318). Enhancing IoT security: Integrating MQTT with ARIA Cipher 256 algorithm cryptography and mbedTLS. Proceedings of the 2023 International Conference on Platform Technology and Service (PlatCon), Busan, Republic of Korea.","DOI":"10.1109\/PlatCon60102.2023.10255171"},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"43019","DOI":"10.1109\/ACCESS.2023.3267718","article-title":"A Robust Security Scheme Based on Enhanced Symmetric Algorithm for MQTT in the Internet of Things","volume":"11","author":"Hintaw","year":"2023","journal-title":"IEEE Access"},{"key":"ref_12","first-page":"19","article-title":"Using cipher key to generate dynamic S-box in AES cipher system","volume":"6","author":"Hosseinkhani","year":"2012","journal-title":"Int. J. Comput. Sci. Secur."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"23","DOI":"10.15388\/Informatica.2009.235","article-title":"Key-dependent S-box generation in AES block cipher system","volume":"20","author":"Kazlauskas","year":"2009","journal-title":"Informatica"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"69","DOI":"10.5121\/ijcnc.2017.9206","article-title":"Security analysis of AES and enhancing its security by modifying S-box with an additional byte","volume":"9","author":"Rahman","year":"2017","journal-title":"Int. J. Comput. Netw. Commun."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"3384","DOI":"10.1109\/JIOT.2022.3221857","article-title":"SEEMQTT: Secure End-to-End MQTT-Based Communication for Mobile IoT Systems Using Secret Sharing and Trust Delegation","volume":"10","author":"Hamad","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"4717","DOI":"10.1109\/TDSC.2024.3358630","article-title":"MQTT-I: Achieving End-to-End Data Flow Integrity in MQTT","volume":"21","author":"Buccafurri","year":"2024","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"6828","DOI":"10.1109\/JIOT.2020.2988126","article-title":"iTLS: Lightweight Transport-Layer Security Protocol for IoT with Minimal Latency and Perfect Forward Secrecy","volume":"7","author":"Li","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Sadio, O., Ngom, I., and Lishou, C. (2019, January 22\u201325). Lightweight Security Scheme for MQTT\/MQTT-SN Protocol. Proceedings of the 2019 Sixth International Conference on Internet of Things: Systems, Management and Security (IOTSMS), Granada, Spain.","DOI":"10.1109\/IOTSMS48152.2019.8939177"},{"key":"ref_19","unstructured":"Wijayanto, A., Nugrahani, S.S., Wardani, D.W., Cahyono, H.D., and Setiadi, H. (September, January 31). Performance Comparison of AES, Grain V1, and RC4 Algorithms on the MQTT Protocol. Proceedings of the International Conference on Information Technology, Computer and Electrical Engineering, Semarang, Indonesia."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Al-Ani, A., Shen, W.K., Al-Ani, A.K., Laghari, S.A., and Elejla, O.E. (2023, January 24\u201327). Evaluating Security of MQTT Protocol in Internet of Things. Proceedings of the 2023 IEEE Canadian Conference on Electrical and Computer Engineering, Regina, SK, Canada.","DOI":"10.1109\/CCECE58730.2023.10288857"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Kurdi, H., and Thayananthan, V. (2022). A Multi-Tier MQTT Architecture with Multiple Brokers Based on Fog Computing for Securing Industrial IoT. Appl. Sci., 12.","DOI":"10.3390\/app12147173"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.jpdc.2019.01.004","article-title":"Publish\/Subscribe Based Multi-Tier Edge Computational Model in Internet of Things for Latency Reduction","volume":"127","author":"Veeramanikandan","year":"2019","journal-title":"J. Parallel Distrib. Comput."},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Pham, V.N., Nguyen, V.D., Nguyen, T.D.T., and Huh, E.N. (2020). Efficient Edge-Cloud Publish\/Subscribe Broker Overlay Networks to Support Latency-Sensitive Wide-Scale Iot Applications. Symmetry, 12.","DOI":"10.3390\/sym12010003"},{"key":"ref_24","unstructured":"(2025, June 01). AWS Key Management Service. Available online: https:\/\/docs.aws.amazon.com\/kms\/latest\/developerguide\/overview.html."},{"key":"ref_25","first-page":"21","article-title":"An Efficient Data Protection Scheme Based on Hierarchical ID-Based Encryption for MQTT","volume":"19","author":"Fan","year":"2023","journal-title":"ACM Trans. Sens. Netw. (TOSN)"},{"key":"ref_26","unstructured":"(2025, June 01). NIST STS Documentation, Available online: https:\/\/csrc.nist.gov\/publications\/detail\/sp\/800-22\/rev-1a\/final."},{"key":"ref_27","unstructured":"(2025, June 01). MITRE ATT & CK Framework. Available online: https:\/\/attack.mitre.org\/."},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1082","DOI":"10.1109\/JIOT.2017.2689682","article-title":"Experimental Characterization of Mobile IoT Application Latency","volume":"4","author":"Pereira","year":"2017","journal-title":"IEEE Internet Things J."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/7\/298\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T18:01:57Z","timestamp":1760032917000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/17\/7\/298"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,30]]},"references-count":28,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2025,7]]}},"alternative-id":["fi17070298"],"URL":"https:\/\/doi.org\/10.3390\/fi17070298","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,6,30]]}}}