{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T23:18:12Z","timestamp":1781306292970,"version":"3.54.1"},"reference-count":52,"publisher":"MDPI AG","issue":"7","license":[{"start":{"date-parts":[[2020,3,28]],"date-time":"2020-03-28T00:00:00Z","timestamp":1585353600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Despite the advantages that the Internet of Things (IoT) will bring to our daily life, the increasing interconnectivity, as well as the amount and sensitivity of data, make IoT devices an attractive target for attackers. To address this issue, the recent Manufacturer Usage Description (MUD) standard has been proposed to describe network access control policies in the manufacturing phase to protect the device during its operation by restricting its communications. In this paper, we define an architecture and process to obtain and enforce the MUD restrictions during the bootstrapping of a device. Furthermore, we extend the MUD model with a flexible policy language to express additional aspects, such as data privacy, channel protection, and resource authorization. For the enforcement of such enriched behavioral profiles, we make use of Software Defined Networking (SDN) techniques, as well as an attribute-based access control approach by using authorization credentials and encryption techniques. These techniques are used to protect devices\u2019 data, which are shared through a blockchain platform. The resulting approach was implemented and evaluated in a real scenario, and is intended to reduce the attack surface of IoT deployments by restricting devices\u2019 communication before they join a certain network.<\/jats:p>","DOI":"10.3390\/s20071882","type":"journal-article","created":{"date-parts":[[2020,4,1]],"date-time":"2020-04-01T03:44:13Z","timestamp":1585712653000},"page":"1882","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":31,"title":["Security Architecture for Defining and Enforcing Security Profiles in DLT\/SDN-Based IoT Systems"],"prefix":"10.3390","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7997-5737","authenticated-orcid":false,"given":"Sara N.","family":"Matheu","sequence":"first","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5501-4608","authenticated-orcid":false,"given":"Alberto","family":"Robles Enciso","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0038-9012","authenticated-orcid":false,"given":"Alejandro","family":"Molina Zarca","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0803-1672","authenticated-orcid":false,"given":"Dan","family":"Garcia-Carrillo","sequence":"additional","affiliation":[{"name":"Odin Solutions, Department of Research and Innovation, Alcantarilla, 30820 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7697-116X","authenticated-orcid":false,"given":"Jos\u00e9 Luis","family":"Hern\u00e1ndez-Ramos","sequence":"additional","affiliation":[{"name":"European Commission, Joint Research Centre, 21027 Ispra, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7538-4788","authenticated-orcid":false,"given":"Jorge","family":"Bernal Bernabe","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5525-1259","authenticated-orcid":false,"given":"Antonio F.","family":"Skarmeta","sequence":"additional","affiliation":[{"name":"Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,3,28]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"80","DOI":"10.1109\/MC.2017.201","article-title":"DDoS in the IoT: Mirai and Other Botnets","volume":"50","author":"Kolias","year":"2017","journal-title":"Computer"},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Lear, E., Romascanu, D., and Droms, R. (2020, March 27). Manufacturer Usage Description Specification (RFC 8520), 2019. Available online: https:\/\/datatracker.ietf.org\/doc\/rfc8520\/.","DOI":"10.17487\/RFC8520"},{"key":"ref_3","unstructured":"Jeffrey, V., Rick, K., Phillip, L., and Sophia, A. (2020, March 27). NISTIR 8222: Internet of Things (IoT) Trust Concerns, 2018, Available online: https:\/\/csrc.nist.gov\/publications\/detail\/white-paper\/2018\/10\/17\/iot-trust-concerns\/draft."},{"key":"ref_4","unstructured":"Polk, T., Souppaya, M., and Barker, W.C. (2020, March 27). Mitigating IoT-Based Automated Distributed Threats, 2017, Available online: https:\/\/csrc.nist.gov\/publications\/detail\/white-paper\/2017\/10\/12\/mitigating-iot-based-automated-distributed-threats\/draft."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Hamza, A., Gharakheili, H.H., Benson, T.A., and Sivaraman, V. (2019, January 3\u20134). Detecting Volumetric Attacks on IoT Devices via SDN-Based Monitoring of MUD Activity. Symposium on SDN Research (SOSR). Proceedings of the 2019 ACM Symposium on SDN Research, San Jose, CA, USA.","DOI":"10.1145\/3314148.3314352"},{"key":"ref_6","unstructured":"Ranganathan, M. (2019, January 25\u201329). Soft MUD: Implementing Manufacturer Usage Descriptions on OpenFlow SDN Switches. Proceedings of the International Conference on Networks (ICN), Valencia, Spain."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1145\/1355734.1355746","article-title":"OpenFlow\u2013enabling innovation in campus networks","volume":"38","author":"McKeown","year":"2008","journal-title":"Acm Sigcomm Comput. Commun. Rev."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"149444","DOI":"10.1109\/ACCESS.2019.2947157","article-title":"Extending MUD profiles through an Automated IoT Security Testing Methodology","volume":"7","author":"Matheu","year":"2019","journal-title":"IEEE Access"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"8005","DOI":"10.1109\/JIOT.2019.2904123","article-title":"Security Management Architecture for NFV\/SDN-aware IoT Systems","volume":"6","author":"Zarca","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Matheu Garc\u00eda, S.N., Molina Zarca, A., Hern\u00e1ndez-Ramos, J.L., Bernab\u00e9, J.B., and G\u00f3mez, A.S. (2019). Enforcing Behavioral Profiles through Software-Defined Networks in the Industrial Internet of Things. Appl. Sci., 9.","DOI":"10.3390\/app9214576"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Garcia-Carrillo, D., Marin-Lopez, R., Kandasamy, A., and Pelov, A. (2017). A CoAP-Based Network Access Authentication Service for Low-Power Wide Area Networks: LO-CoAP-EAP. Sensors, 17.","DOI":"10.3390\/s17112646"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Bethencourt, J., Sahai, A., and Waters, B. (2007, January 20\u201323). Ciphertext Policy Attribute Based Encryption. Proceedings of the 2007 IEEE Symposium on Security and Privacy (SP \u201907), Berkeley, CA, USA.","DOI":"10.1109\/SP.2007.11"},{"key":"ref_13","unstructured":"Erdtman, S., Wahlstroem, E., Tschofenig, H., and Jones, M. (2020, March 27). CBOR Web Token (CWT), 2018. Available online: https:\/\/tools.ietf.org\/html\/rfc8392."},{"key":"ref_14","unstructured":"OASIS (2020, March 27). eXtensible Access Control Markup Language Version 3.0, 2013. Available online: http:\/\/docs.oasis-open.org\/xacml\/3.0\/xacml-3.0-core-spec-os-en.html."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Garcia-Carrillo, D., and Marin-Lopez, R. (2016). Lightweight CoAP-Based Bootstrapping Service for the Internet of Things. Sensors, 16.","DOI":"10.3390\/s16030358"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1109\/MC.2019.2917972","article-title":"Network Level Security for the Internet of Things: Opportunities and Challenges","volume":"52","author":"Sivanathan","year":"2019","journal-title":"Computer"},{"key":"ref_17","unstructured":"Ellesson, E., Strassner, J., Moore, B., and Westerinen, A. (2020, March 27). Policy Core Information Model \u2013 Version 1 Specification, 2001. Available online: https:\/\/tools.ietf.org\/html\/rfc3060."},{"key":"ref_18","unstructured":"Molloy, I., and Huang, H. (2018, January 18). Standardizing IoT Network Security Policy Enforcement. Proceedings of the Workshop on Decentralized IoT Security and Standards, San Diego, CA, USA."},{"key":"ref_19","unstructured":"Barrera, D., Molloy, I., and Huang, H. (2017). IDIoT - Securing the Internet of Things like it\u2019s 1994. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Jethanandani, M., Blair, D., Huang, L., and Agarwal, S. (2020, March 27). YANG Data Model for Network Access Control Lists (RFC8519), 2019. Available online: https:\/\/tools.ietf.org\/html\/rfc8519.","DOI":"10.17487\/RFC8519"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Bray, T. (2020, March 27). The JavaScript Object Notation (JSON) Data Interchange Format (RFC8259), 2017. Available online: https:\/\/tools.ietf.org\/html\/rfc8259.","DOI":"10.17487\/RFC8259"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Hamza, A., Gharakheili, H.H., and Sivaraman, V. (2018, January 20). Combining MUD Policies with SDN for IoT Intrusion Detection. Proceedings of the 2018 Workshop on IoT Security and Privacy, New York, NY, USA.","DOI":"10.1145\/3229565.3229571"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Al-Shaboti, M., Welch, I., Chen, A., and Mahmood, M.A. (2018, January 16\u201318). Towards Secure Smart Home IoT\u2014Manufacturer and User Network Access Control Framework. Proceedings of the IEEE 32nd International Conference on Advanced Information Networking and Applications (AINA), Krakow, Poland.","DOI":"10.1109\/AINA.2018.00131"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"690","DOI":"10.1109\/JSAC.2015.2393436","article-title":"Toward a Lightweight Authentication and Authorization Framework for Smart Objects","volume":"33","author":"Pawlowski","year":"2015","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"1452","DOI":"10.1016\/j.jcss.2014.12.021","article-title":"SAFIR - Secure access framework for IoT-enabled services on smart buildings","volume":"81","author":"Moreno","year":"2015","journal-title":"J. Comput. Syst. Sci."},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Hardt, D. (2020, March 27). The OAuth 2.0 Authorization Framework (RFC 6749), 2012. Available online: https:\/\/tools.ietf.org\/html\/rfc6749.","DOI":"10.17487\/rfc6749"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Bormann, C., and Hoffman, P. (2020, March 27). Concise Binary Object Representation (CBOR) (RFC7049), 2013. Available online: https:\/\/tools.ietf.org\/html\/rfc7049.","DOI":"10.17487\/rfc7049"},{"key":"ref_28","unstructured":"Carsten Bormann (2020, March 27). An Authorization Information Format (AIF) for ACE, 2019. Available online: https:\/\/tools.ietf.org\/html\/draft-bormann-core-ace-aif-01."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"230","DOI":"10.1109\/JIOT.2014.2387155","article-title":"DIAT\u2014A Scalable Distributed Architecture for IoT","volume":"2","author":"Sarkar","year":"2015","journal-title":"IEEE Internet Things J."},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"60","DOI":"10.1016\/j.cose.2015.06.002","article-title":"SecKit\u2014A Model-based Security Toolkit for the Internet of Things","volume":"54","author":"Neisse","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_31","unstructured":"OASIS (2020, March 27). Message Queue Telemetry Transport (MQTT) Version 5.0, 2019. Available online: https:\/\/docs.oasis-open.org\/mqtt\/mqtt\/v5.0\/mqtt-v5.0.html."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Phung, P.H., Truong, H., and Yasoju, D.T. (2017, January 25\u201330). P4SINC\u2014An Execution Policy Framework for IoT Services in the Edge. Proceedings of the 2017 IEEE International Congress on Internet of Things (ICIOT), Honolulu, HI, USA.","DOI":"10.1109\/IEEE.ICIOT.2017.23"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"32","DOI":"10.1109\/MIS.2004.31","article-title":"KAoS policy management for semantic Web services","volume":"19","author":"Uszok","year":"2004","journal-title":"IEEE Intell. Syst."},{"key":"ref_34","unstructured":"Kagal, L. (2002). Rei\u2014A Policy Language for the Me-Centric Project, HP Labs. Technical Report."},{"key":"ref_35","first-page":"33","article-title":"User-oriented Network Security Policy Specification","volume":"8","author":"Valenza","year":"2018","journal-title":"J. Internet Serv. Inf. Secur."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"2783658","DOI":"10.1155\/2018\/2783658","article-title":"BaDS\u2014Blockchain-Based Architecture for Data Sharing with ABS and CP-ABE in IoT","volume":"2018","author":"Zhang","year":"2018","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Conoscenti, M., Vetr\u00f2, A., and De Martin, J.C. (December, January 29). Blockchain for the Internet of Things: A systematic literature review. Proceedings of the 2016 IEEE\/ACS 13th International Conference of Computer Systems and Applications (AICCSA), Agadir, Morocco.","DOI":"10.1109\/AICCSA.2016.7945805"},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"164908","DOI":"10.1109\/ACCESS.2019.2950872","article-title":"Privacy-Preserving Solutions for Blockchain: Review and Challenges","volume":"7","author":"Canovas","year":"2019","journal-title":"IEEE Access"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Rescorla, E., and Modadugu, N. (2020, March 27). Datagram Transport Layer Security Version 1.2, 2012. Available online: https:\/\/tools.ietf.org\/html\/rfc6347.","DOI":"10.17487\/rfc6347"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"11738","DOI":"10.1109\/ACCESS.2018.2801383","article-title":"A Lightweight and Flexible Encryption Scheme to Protect Sensitive Data in Smart Building Scenarios","volume":"6","author":"Rotondi","year":"2018","journal-title":"IEEE Access"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Garcia-Morchon, O., Kumar, S.S., and Sethi, M. (2020, March 27). Internet of Things Security: State of the Art and Challenges (RFC 8576), 2019. Available online: https:\/\/tools.ietf.org\/html\/rfc8576.","DOI":"10.17487\/RFC8576"},{"key":"ref_42","unstructured":"Vollbrecht, J.R., Aboba, B., Blunk, L.J., Levkowetz, H., and Carlson, J. (2020, March 27). Extensible Authentication Protocol (RFC 3748), 2004. Available online: https:\/\/tools.ietf.org\/html\/rfc3748."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Vollbrecht, J., Holdrege, M., Laat, C., Calhoun, P., Gommans, L., Farrell, S., Bruijn, B.D., Gross, G., and Spence, D. (2020, March 27). AAA Authorization Framework (RFC 2904), 2000. Available online: https:\/\/tools.ietf.org\/html\/rfc2904.","DOI":"10.17487\/rfc2904"},{"key":"ref_44","unstructured":"Ohba, Y., Patil, B., Forsberg, D., Tschofenig, H., and Yegin, A.E. (2020, March 27). Protocol for Carrying Authentication for Network Access (RFC 5191), 2008. Available online: https:\/\/tools.ietf.org\/html\/rfc5191."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Aboba, B., and Calhoun, P.R. (2020, March 27). RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP), 2003. Available online: https:\/\/tools.ietf.org\/html\/rfc3579.","DOI":"10.17487\/rfc3579"},{"key":"ref_46","doi-asserted-by":"crossref","unstructured":"Bersani, F., and Tschofenig, H. (2020, March 27). The EAP-PSK Protocol: A Pre-Shared Key Extensible Authentication Protocol Method (RFC 4764), 2007. Available online: https:\/\/tools.ietf.org\/html\/rfc4764.","DOI":"10.17487\/rfc4764"},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"Enns, R., Bjorklund, M., and Schoenwaelder, J. (2020, March 27). Network Configuration Protocol (RFC 6241), 2011. Available online: https:\/\/tools.ietf.org\/html\/rfc6241.","DOI":"10.17487\/rfc6241"},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"345","DOI":"10.1080\/00207160.2014.915316","article-title":"DCapBAC - embedding authorization logic into smart things through ECC optimizations","volume":"93","author":"Jara","year":"2016","journal-title":"Int. J. Comput. Math."},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Masinter, L., Berners-Lee, T., and Fielding, R.T. (2020, March 27). Uniform Resource Identifier (URI): Generic Syntax, 2005. Available online: https:\/\/tools.ietf.org\/html\/rfc3986.","DOI":"10.17487\/rfc3986"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Schaad, J. (2020, March 27). CBOR Object Signing and Encryption (COSE) (RFC8152), 2017. Available online: https:\/\/tools.ietf.org\/html\/rfc8152.","DOI":"10.17487\/RFC8152"},{"key":"ref_51","unstructured":"Hyperledger (2020, March 27). Hyperledger Blockchain Performance Metrics, 2018. Available online: https:\/\/cn.hyperledger.org\/resources\/publications\/blockchain-performance-metrics."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Jiang, L., Chang, X., Liu, Y., Mi\u0161i\u0107, J., and Mi\u0161i\u0107, V.B. (2020). Performance analysis of Hyperledger Fabric platform: A hierarchical model approach. Peer -Peer Netw. Appl., 1\u201312.","DOI":"10.1007\/s12083-019-00850-z"}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/7\/1882\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T09:12:59Z","timestamp":1760173979000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/20\/7\/1882"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,28]]},"references-count":52,"journal-issue":{"issue":"7","published-online":{"date-parts":[[2020,4]]}},"alternative-id":["s20071882"],"URL":"https:\/\/doi.org\/10.3390\/s20071882","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,28]]}}}