{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T15:16:12Z","timestamp":1785424572212,"version":"3.56.0"},"reference-count":59,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2017,6,28]],"date-time":"2017-06-28T00:00:00Z","timestamp":1498608000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>The Internet of Things (IoT) is a recent trend that extends the boundary of the Internet to include a wide variety of computing devices. Connecting many stand-alone IoT systems through the Internet introduces many challenges, with security being front-and-center since much of the collected information will be exposed to a wide and often unknown audience. Unfortunately, due to the intrinsic capability limits of low-end IoT devices, which account for a majority of the IoT end hosts, many traditional security methods cannot be applied to secure IoT systems, which open a door for attacks and exploits directed both against IoT services and the broader Internet. This paper addresses this issue by introducing a unified IoT framework based on the MobilityFirst future Internet architecture that explicitly focuses on supporting security for the IoT. Our design integrates local IoT systems into the global Internet without losing usability, interoperability and security protection. Specifically, we introduced an IoT middleware layer that connects heterogeneous hardware in local IoT systems to the global MobilityFirst network. We propose an IoT name resolution service (IoT-NRS) as a core component of the middleware layer, and develop a lightweight keying protocol that establishes trust between an IoT device and the IoT-NRS.<\/jats:p>","DOI":"10.3390\/fi9030027","type":"journal-article","created":{"date-parts":[[2017,6,28]],"date-time":"2017-06-28T10:25:56Z","timestamp":1498645556000},"page":"27","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":107,"title":["A Security Framework for the Internet of Things in the Future Internet Architecture"],"prefix":"10.3390","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5045-5482","authenticated-orcid":false,"given":"Xiruo","family":"Liu","sequence":"first","affiliation":[{"name":"Intel Labs, Hillsboro 97124, OR, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meiyuan","family":"Zhao","sequence":"additional","affiliation":[{"name":"Google, Mountain View 94043, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sugang","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Rutgers University, Piscataway 08854, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Feixiong","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Rutgers University, Piscataway 08854, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0635-9458","authenticated-orcid":false,"given":"Wade","family":"Trappe","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Rutgers University, Piscataway 08854, NJ, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2017,6,28]]},"reference":[{"key":"ref_1","first-page":"97","article-title":"That \u2018Internet of Things\u2019 Thing","volume":"22","author":"Ashton","year":"2009","journal-title":"RFID J."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"2787","DOI":"10.1016\/j.comnet.2010.05.010","article-title":"The Internet of Things: A Survey","volume":"54","author":"Atzori","year":"2010","journal-title":"Comput. Netw."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Giusto, D., Lera, A., Morabito, G., and Atzori, L. (2010). The Internet of Things, Springer.","DOI":"10.1007\/978-1-4419-1674-7"},{"key":"ref_4","unstructured":"Strategic Business Insights (Firm) (2008). Six Technologies with Potential Impacts on US Interests out to 2025, The National Intelligence Council. Technical Report."},{"key":"ref_5","unstructured":"Federal Trade Commission (2013). Internet of Things\u2014Privacy and Security in a Connected World, FTC."},{"key":"ref_6","unstructured":"(2013). Gartner Says the Internet of Things Installed Base Will Grow to 26 Billion Units By 2020, Gartner Inc."},{"key":"ref_7","unstructured":"(2017, June 19). MobilityFirst Future Internet Architecture. Available online: http:\/\/mobilityfirst.winlab.rutgers.edu\/."},{"key":"ref_8","unstructured":"(1970, January 01). eXpressive Internet Architecture. Available online: https:\/\/www.cs.cmu.edu\/~xia\/."},{"key":"ref_9","unstructured":"(2017, June 19). Named Data Networking. Available online: http:\/\/named-data.net\/."},{"key":"ref_10","unstructured":"(2017, June 19). Nebula Future Internet Architecture Project. Available online: http:\/\/nebula-fia.org."},{"key":"ref_11","unstructured":"CoRE Working Group DF-1 Protocol and Command Set Reference Manual; IETF Standards; Fremont, CA, USA, 1996."},{"key":"ref_12","unstructured":"(2017, June 19). MelsecNet. Available online: https:\/\/eu3a.mitsubishielectric.com\/fa\/en\/."},{"key":"ref_13","unstructured":"(2017, June 19). Distributed System (SDS). Available online: http:\/\/holjeron.com\/products\/sds-products\/."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Newman, M. (2013). BACnet: the Global Standard for Building Automation and Control Networks, Momentum Press.","DOI":"10.5643\/9781606502907"},{"key":"ref_15","unstructured":"European Telecommunications Standards Institute (ETSI) (2014). Low Throughput Networks (LTN): Functional Architecture, European Telecommunications Standards Institute (ETSI). ETSI GS LTN 002 v1.1.1."},{"key":"ref_16","unstructured":"(2017, June 19). Global Sensor Networks. Available online: https:\/\/github.com\/LSIR\/gsn\/wiki."},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Aberer, K., Hauswirth, M., and Salehi, A. (2007, January 7\u201311). Infrastructure for Data Processing in Large-scale Interconnected Sensor Networks. Proceedings of the IEEE International Conference on Mobile Data Management, Mannheim, Germany.","DOI":"10.1109\/MDM.2007.36"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Shelby, Z. (2012). RFC6690: Constrained RESTful Environments (CoRE) Link Format, IETF Standards; CoRE Working Group.","DOI":"10.17487\/rfc6690"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Shelby, Z., Hartke, K., Bormann, C., and Frank, B. (2014). RFC7252: The Constrained Application Protocol (CoAP), CoRE Working Group. IETF Standards.","DOI":"10.17487\/rfc7252"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Lee, C.T., Yang, C.H., Chang, C.M., Kao, C.Y., Tseng, H.M., Hsu, H., and Chou, P.H. (2014, January 6\u20138). A Smart Energy System with Distributed Access Control. Proceedings of the IEEE International Conference on Internet of Things, Cambridge, MA, USA.","DOI":"10.1109\/iThings.2014.17"},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"1224","DOI":"10.1109\/JSEN.2014.2361406","article-title":"IoT-OAS: An OAuth-Based Authorization Service Architecture for Secure Services in IoT Scenarios","volume":"15","author":"Cirani","year":"2015","journal-title":"IEEE Sens. J."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Blazquez, A., Tsiatsis, V., and Vandikas, K. (2015, January 11\u201314). Performance Evaluation of OpenID Connect for an IoT Information Marketplace. Proceedings of the 81st IEEE Vehicular Technology Conference (VTC Spring), Glasgow, UK.","DOI":"10.1109\/VTCSpring.2015.7146004"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Seitz, L., Selander, G., and Gehrmann, C. (2013, January 4\u20137). Authorization Framework for the Internet-of-Things. Proceedings of the 14th IEEE International Symposium on a World of Wireless, Mobile and Multimedia Networks (WoWMoM), Madrid, Spain.","DOI":"10.1109\/WoWMoM.2013.6583465"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Fotiou, N., Kotsonis, T., Marias, G.F., and Polyzos, G.C. (2016, January 27). Access Control for the Internet of Things. Proceedings of the International Workshop on Secure Internet of Things (SIoT 2016), Crete, Greece.","DOI":"10.1109\/SIoT.2016.010"},{"key":"ref_25","unstructured":"Gerdes, S., Bergmann, O., and Bormann, C. (2015). Delegated CoAP Authentication and Authorization Framework (DCAF), IETF Internet Draft."},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"1228","DOI":"10.1109\/COMST.2015.2498304","article-title":"The Virtual Object as a Major Element of the Internet of Things: A Survey","volume":"18","author":"Nitti","year":"2016","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"ref_27","unstructured":"(2017, June 20). oneM2M. Available online: https:\/\/www.onem2m.org\/."},{"key":"ref_28","unstructured":"Li, J., Zhang, Y., Nagaraja, K., and Raychaudhuri, D. (2012, January 1\u20134). Supporting Efficient Machine-to-machine Communications in the Future Mobile Internet. Proceedings of the IEEE Wireless Communications and Networking Conference Workshops (WCNCW), Paris, France."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Li, S., Zhang, Y., Raychaudhuri, D., and Ravindran, R. (2014, January 18\u201319). A Comparative Study of MobilityFirst and NDN based ICN-IoT Architectures. Proceedings of the 10th IEEE International Conference on Heterogeneous Networking for Quality, Reliability, Security and Robustness (QShine), Rhodes Island, Greece.","DOI":"10.1109\/QSHINE.2014.6928680"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"14","DOI":"10.1109\/MSP.2015.7","article-title":"Low-Energy Security: Limits and Opportunities in the Internet of Things","volume":"13","author":"Trappe","year":"2015","journal-title":"IEEE Secur. Priv."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Zhang, F., Nagaraja, K., Zhang, Y., and Raychaudhuri, D. (2012, January 21\u201322). Content Delivery in the MobilityFirst future Internet Architecture. Proceedings of the 35th IEEE Sarnoff Symposium (SARNOFF), Newark, NJ, USA.","DOI":"10.1109\/SARNOF.2012.6222763"},{"key":"ref_32","unstructured":"Su, K., Bronzino, F., Ramakrishnan, K., and Raychaudhuri, D. (October, January 30). MFTP: A Clean-Slate Transport Protocol for the Information Centric MobilityFirst Network. Proceedings of the 2nd ACM International Conference on Information-Centric Networking, San Francisco, CA, USA."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Li, S., Zhang, Y., Raychaudhuri, D., Ravindran, R., Zheng, Q., Dong, L., and Wang, G. (2015, January 6\u201310). IoT Middleware Architecture over Information-Centric Network. Proceedings of the 2015 IEEE Globecom Workshops, San Diego, CA, USA.","DOI":"10.1109\/GLOCOMW.2015.7414119"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Moskowitz, R., and Nikander, P. (2006). Host Identity Protocol (HIP) Architecture, The Internet Society. IETF Internet Standard, RFC 4423.","DOI":"10.17487\/rfc4423"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Andersen, D.G., Balakrishnan, H., Feamster, N., Koponen, T., Moon, D., and Shenker, S. (2008, January 17\u201322). Accountable Internet Protocol (AIP). Proceedings of the ACM SIGCOMM Conference on Data Communication, Seattle, WA, USA.","DOI":"10.1145\/1402958.1402997"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"1344","DOI":"10.1109\/JSAC.2010.101012","article-title":"MILSA: A New Evolutionary Architecture for Scalability, Mobility, and Multihoming in the Future Internet","volume":"28","author":"Pan","year":"2010","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_37","unstructured":"Liu, X., Trappe, W., and Zhang, Y. (August, January 30). Secure Name Resolution for Identifier-to-Locator Mappings in the Global Internet. Proceedings of the 22nd IEEE International Conference on Computer Communications and Networks (ICCCN), Nassau, Bahamas."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Liu, X., Trappe, W., and Lindqvist, J. (2014, January 7\u201311). A Policy-driven Approach to Access Control in Future Internet Name Resolution Services. Proceedings of the 9th ACM workshop on Mobility in the Evolving Internet Architecture, Maui, HI, USA.","DOI":"10.1145\/2645892.2645897"},{"key":"ref_39","unstructured":"GlobalPlatform (2011). The Trusted Execution Environment: Delivering Enhanced Security at a Lower Cost to the Mobile Market, GlobalPlatform Inc."},{"key":"ref_40","unstructured":"GlobalPlatform (2011). TEE Systems Architecture v1.0, GlobalPlatform Inc."},{"key":"ref_41","unstructured":"Steiner, J.G., Neuman, B.C., and Schiller, J.I. (1988, January 12). Kerberos: An Authentication Service for Open Network Systems. Proceedings of the USENIX Winter, Dallas, TX, USA."},{"key":"ref_42","unstructured":"Kaliski, B., Arnold, T.S., Schlafly, R., Markowitz, M., Yin, Y.L., Arazi, B., Blake, I., Chen, L., Finkelstein, L., and Fumy, W. (2000). IEEE Standard Specifications for Public-Key Cryptography, IEEE Computer Society."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Canetti, R., and Krawczyk, H. (2002). Security Analysis of IKE\u2019s Signature-based Key-Exchange Protocol. Advances in Cryptology\u2014CRYPTO 2002, Springer.","DOI":"10.1007\/3-540-45708-9_10"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Krawczyk, H. (2003). SIGMA: The \u2018SIGn-and-MAc\u2019 Approach to Authenticated Diffie-Hellman and its Use in the IKE Protocols. Advances in Cryptology-CRYPTO 2003, Springer.","DOI":"10.1007\/978-3-540-45146-4_24"},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Choo, K.K.R., Boyd, C., Hitchcock, Y., and Maitland, G. (2004). On Session Identifiers in Provably Secure Protocols. Security in Communication Networks, Springer.","DOI":"10.1007\/978-3-540-30598-9_25"},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"993","DOI":"10.1145\/359657.359659","article-title":"Using encryption for authentication in large networks of computers","volume":"21","author":"Needham","year":"1978","journal-title":"ACM Commun."},{"key":"ref_47","doi-asserted-by":"crossref","first-page":"533","DOI":"10.1145\/358722.358740","article-title":"Timestamps in Key Distribution Protocols","volume":"24","author":"Denning","year":"1981","journal-title":"ACM Commun."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"294","DOI":"10.1145\/359460.359473","article-title":"Secure Communications over Insecure Channels","volume":"21","author":"Merkle","year":"1978","journal-title":"ACM Commun."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"644","DOI":"10.1109\/TIT.1976.1055638","article-title":"New directions in cryptography","volume":"22","author":"Diffie","year":"1976","journal-title":"IEEE Trans. Inf. Theory"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Adrian, D., Bhargavan, K., Durumeric, Z., Gaudry, P., Green, M., Halderman, J.A., Heninger, N., Springall, D., Thom\u00e9, E., and Valenta, L. (2015, January 12\u201316). Imperfect forward secrecy: How Diffie-Hellman fails in practice. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA.","DOI":"10.1145\/2810103.2813707"},{"key":"ref_51","doi-asserted-by":"crossref","first-page":"107","DOI":"10.1007\/BF00124891","article-title":"Authentication and Authenticated Key Exchanges","volume":"2","author":"Diffie","year":"1992","journal-title":"Des. Codes Cryptogr."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Karn, P., and Simpson, W. (1999). Photuris: Session-Key Management Protocol, IETF Network Working Group.","DOI":"10.17487\/rfc2522"},{"key":"ref_53","doi-asserted-by":"crossref","unstructured":"Harkins, D., and Carrel, D. (1998). The Internet Key Exchange (IKE), IETF Network Working Group. Technical Report, RFC 2409.","DOI":"10.17487\/rfc2409"},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Kaufman, C. (2005). Internet Key Exchange (IKEv2) Protocol, IETF Network Working Group.","DOI":"10.17487\/rfc4306"},{"key":"ref_55","unstructured":"(2017, June 19). wolfSSL. Available online: https:\/\/www.wolfssl.com\/wolfSSL\/Home.html."},{"key":"ref_56","unstructured":"(2017, June 19). ARM. Available online: https:\/\/tls.mbed.org\/."},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Dworkin, M. (2007). Recommendation for Block Cipher Modes of Operation: Galois\/Counter Mode (GCM) and GMAC, NIST Special Publication 800-38D.","DOI":"10.6028\/NIST.SP.800-38d"},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Kivinen, T. (2003). More Modular Exponential (MODP) Diffie-Hellman Groups for Internet Key Exchange (IKE), IETF Network Working Group. RFC3526.","DOI":"10.17487\/rfc3526"},{"key":"ref_59","doi-asserted-by":"crossref","unstructured":"Rescorla, E., and Modadugu, N. (2012). Datagram Transport Layer Security Version 1.2, IETF Network Working Group. RFC6347.","DOI":"10.17487\/rfc6347"}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/9\/3\/27\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T18:40:39Z","timestamp":1760208039000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/9\/3\/27"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,6,28]]},"references-count":59,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2017,9]]}},"alternative-id":["fi9030027"],"URL":"https:\/\/doi.org\/10.3390\/fi9030027","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2017,6,28]]}}}