{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T05:06:41Z","timestamp":1787029601662,"version":"build-2736575974"},"reference-count":46,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2022,2,11]],"date-time":"2022-02-11T00:00:00Z","timestamp":1644537600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Internet-of-Things (IoT) and sensor technologies have enabled the collection of data in a distributed fashion for analysis and evidence-based decision making. However, security concerns regarding the source, confidentiality and integrity of the data arise. The most common method of protecting data transmission in sensor systems is Transport Layer Security (TLS) or its datagram counterpart (DTLS) today, but exist an alternative option based on Distributed Ledger Technology (DLT) that promise strong security, ease of use and potential for large scale integration of heterogeneous sensor systems. A DLT such as the IOTA Tangle offers great potential to improve sensor data exchange. This paper presents L2Sec, a cryptographic protocol which is able to secure data exchanged over the IOTA Tangle. This protocol is suitable for implementation on constrained devices, such as common IoT devices, leading to greater scalability. The first experimental results evidence the effectiveness of the approach and advocate for the integration of an hardware secure element to improve the overall security of the protocol. The L2Sec source code is released as open source repository on GitHub.<\/jats:p>","DOI":"10.3390\/s22041384","type":"journal-article","created":{"date-parts":[[2022,2,11]],"date-time":"2022-02-11T05:14:43Z","timestamp":1644556483000},"page":"1384","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":36,"title":["Enabling Secure Data Exchange through the IOTA Tangle for IoT Constrained Devices"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-2392-5463","authenticated-orcid":false,"given":"Alberto","family":"Carelli","sequence":"first","affiliation":[{"name":"Cybersecurity Lab, Connected Systems and Cybersecurity Area, LINKS Foundation, 10138 Turin, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrea","family":"Palmieri","sequence":"additional","affiliation":[{"name":"System Research and Applications, STMicroelectronics, 73100 Lecce, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Antonio","family":"Vilei","sequence":"additional","affiliation":[{"name":"System Research and Applications, STMicroelectronics, 73100 Lecce, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fabien","family":"Castanier","sequence":"additional","affiliation":[{"name":"System Research and Applications, STMicroelectronics, 20010 Cornaredo, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7431-6655","authenticated-orcid":false,"given":"Andrea","family":"Vesco","sequence":"additional","affiliation":[{"name":"Cybersecurity Lab, Connected Systems and Cybersecurity Area, LINKS Foundation, 10138 Turin, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,2,11]]},"reference":[{"key":"ref_1","unstructured":"GSMA (2021, November 26). IoT SAFE: Robust IoT Security at Scale. The Why, What and How of Securing IoT Applications and Data. Available online: https:\/\/www.gsma.com\/iot\/wp-content\/uploads\/2021\/06\/IoT-SAFE-Whitepaper-2021.pdf."},{"key":"ref_2","doi-asserted-by":"crossref","unstructured":"Ahmad, W., Rasool, A., Javed, A.R., Baker, T., and Jalil, Z. (2022). Cyber Security in IoT-Based Cloud Computing: A Comprehensive Survey. Electronics, 11.","DOI":"10.3390\/electronics11010016"},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"10250","DOI":"10.1109\/JIOT.2020.2997651","article-title":"An In-Depth Analysis of IoT Security Requirements, Challenges, and Their Countermeasures via Software-Defined Security","volume":"7","author":"Iqbal","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"121975","DOI":"10.1109\/ACCESS.2021.3109886","article-title":"A Review of Security Standards and Frameworks for IoT-Based Smart Environments","volume":"9","author":"Karie","year":"2021","journal-title":"IEEE Access"},{"key":"ref_5","unstructured":"Rescorla, E. (2021, November 26). The Transport Layer Security (TLS) Protocol Version 1.3. RFC 8446. Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc8446.html."},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Rescorla, E., Tschofenig, H., and Modadugu, N. (2021, November 26). The Datagram Transport Layer Security (DTLS) Protocol Version 1.3. Available online: https:\/\/tools.ietf.org\/id\/draft-ietf-tls-dtls13-01.html.","DOI":"10.17487\/RFC9147"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Goworko, M., and Wytr\u0119bowicz, J. (2021). A Secure Communication System for Constrained IoT Devices\u2014Experiences and Recommendations. Sensors, 21.","DOI":"10.3390\/s21206906"},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Tsaur, W.J., Chang, J.C., and Chen, C.L. (2022). A Highly Secure IoT Firmware Update Mechanism Using Blockchain. Sensors, 22.","DOI":"10.3390\/s22020530"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"62728","DOI":"10.1109\/ACCESS.2018.2876766","article-title":"Distributed Ledger Technology for Smart Cities, the Sharing Economy, and Social Compliance","volume":"6","author":"Ferraro","year":"2018","journal-title":"IEEE Access"},{"key":"ref_10","unstructured":"IOTA Foundation (2021, November 26). IOTA Wiki. The Complete Reference for IOTA. Available online: https:\/\/wiki.iota.org."},{"key":"ref_11","unstructured":"IOTA Foundation (2021, November 26). mam.js. Available online: https:\/\/github.com\/iotaledger\/mam.js."},{"key":"ref_12","unstructured":"IOTA Foundation (2021, November 26). IOTA Streams. Available online: https:\/\/www.iota.org\/solutions\/streams."},{"key":"ref_13","unstructured":"STMicrolectronics (2021, November 26). B-L4S5I-IOT01A: STM32L4+ Discovery Kit IoT Node, Low-Power Wireless, BLE, NFC, WiFi. Available online: https:\/\/www.st.com\/en\/evaluation-tools\/b-l4s5i-iot01a.html."},{"key":"ref_14","unstructured":"STMicrolectronics (2021, November 26). STSAFE-A110. Available online: https:\/\/www.st.com\/en\/secure-mcus\/stsafe-a110.html."},{"key":"ref_15","unstructured":"IOTA Foundation (2021, November 26). HORNET Is a Powerful IOTA Fullnode Software. Available online: https:\/\/github.com\/iotaledger\/hornet."},{"key":"ref_16","unstructured":"Bormann, C., Ersue, M., and Ker\u00e4nen, A. (2021, November 26). Terminology for Constrained-Node Networks. RFC 7228. Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc7228.html."},{"key":"ref_17","unstructured":"(2021, November 26). IOTA: MAM Eloquently Explained. Available online: https:\/\/medium.com\/coinmonks\/iota-mam-eloquently-explained-d7505863b413."},{"key":"ref_18","unstructured":"IOTA Foundation (2021, November 26). STREAMS-A Cryptographic Framework for Building Secure Messaging Protocols. Available online: https:\/\/github.com\/iotaledger\/streams."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Rogaway, P. (2002, January 4\u20136). Authenticated-encryption with associated-data. Proceedings of the 9th ACM Conference on Computer and Communications Security, Kyoto, Japan.","DOI":"10.1145\/586110.586125"},{"key":"ref_20","unstructured":"IOTA Foundation (2021, November 26). IOTA Client Library in C. Available online: https:\/\/github.com\/iotaledger\/iota.c\/."},{"key":"ref_21","unstructured":"Frank, D. (2021, November 26). Libsodium-The Sodium Cryptography Library. Available online: https:\/\/download.libsodium.org\/doc\/."},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Bernstein, D.J., Duif, N., Lange, T., Schwabe, P., and Yang, B.Y. (2011). High-speed high-security signatures. International Workshop on Cryptographic Hardware and Embedded Systems, Springer.","DOI":"10.1007\/978-3-642-23951-9_9"},{"key":"ref_23","unstructured":"Josefsson, S., and Liusvaara, I. (2021, November 26). Edwards-Curve Digital Signature Algorithm (EdDSA). RFC 8032. Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc8032.html."},{"key":"ref_24","unstructured":"Saarinen, M.J.O., and Aumasson, J.P. (2021, November 26). The BLAKE2 Cryptographic Hash and Message Authentication Code (MAC). RFC 7693. Available online: https:\/\/www.rfc-editor.org\/rfc\/rfc7693.html."},{"key":"ref_25","unstructured":"Levy, S. (2021, November 26). Performance and Security of ECDSA. Comput. Sci., Available online: https:\/\/koclab.cs.ucsb.edu\/teaching\/ecc\/project\/2015Projects\/Levy.pdf."},{"key":"ref_26","unstructured":"Al-Zubaidie, M., Zhang, Z., and Zhang, J. (2019). Efficient and secure ECDSA algorithm and its applications: A survey. arXiv."},{"key":"ref_27","unstructured":"Bernstein, D.J. (2011). Extending the Salsa20 nonce. Workshop Record of Symmetric Key Encryption Workshop, Citeseer."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Luangoudom, S., Nguyen, T., Tran, D., and Nguyen, L.G. (2019, January 24\u201326). End to end message encryption using Poly1305 and XSalsa20 in Low power and Lossy Networks*. Proceedings of the 2019 11th International Conference on Knowledge and Systems Engineering (KSE), Da Nang, Vietnam.","DOI":"10.1109\/KSE.2019.8919479"},{"key":"ref_29","unstructured":"Rawat, A.S., and Deshmukh, M. (2019, January 27\u201328). Efficient Extended Diffie-Hellman Key Exchange Protocol. Proceedings of the 2019 International Conference on Computing, Power and Communication Technologies (GUCON), Greater Noida, India."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Canetti, R. (2001, January 14\u201317). Universally composable security: A new paradigm for cryptographic protocols. Proceedings of the 42nd IEEE Symposium on Foundations of Computer Science, Washington, DC, USA.","DOI":"10.1109\/SFCS.2001.959888"},{"key":"ref_31","unstructured":"Bellovin, S., and Merritt, M. (1992, January 4\u20136). Encrypted key exchange: Password-based protocols secure against dictionary attacks. Proceedings of the 1992 IEEE Computer Society Symposium on Research in Security and Privacy, Oakland, CA, USA."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"769","DOI":"10.1109\/71.877936","article-title":"Key agreement in dynamic peer groups","volume":"11","author":"Steiner","year":"2000","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"ref_33","unstructured":"Ani, U.D., Watson, J.M., Nurse, J.R., Cook, A., and Maples, C. (2021, November 26). A Review of Critical Infrastructure Protection Approaches: Improving Security through Responsiveness to the Dynamic Modelling Landscape. Available online: https:\/\/arxiv.org\/pdf\/1904.01551."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"8021","DOI":"10.1109\/JIOT.2019.2903242","article-title":"Secure industrial Internet of Things critical infrastructure node design","volume":"6","author":"Mcginthy","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"5498","DOI":"10.1109\/JIOT.2020.3033435","article-title":"Efficient Security Algorithm for Power-Constrained IoT Devices","volume":"8","author":"Mamvong","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Bollo, M., Carelli, A., Di Carlo, S., and Prinetto, P. (October, January 29). Side-channel analysis of SEcube\u2122 platform. Proceedings of the 2017 IEEE East-West Design Test Symposium (EWDTS), Novi Sad, Serbia.","DOI":"10.1109\/EWDTS.2017.8110067"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Amiel, F., Feix, B., and Villegas, K. (2007). Power analysis for secret recovering and reverse engineering of public key algorithms. International Workshop on Selected Areas in Cryptography, Springer.","DOI":"10.1007\/978-3-540-77360-3_8"},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Amiel, F., Villegas, K., Feix, B., and Marcel, L. (2007, January 10). Passive and active combined attacks: Combining fault attacks and side channel analysis. Proceedings of the Workshop on Fault Diagnosis and Tolerance in Cryptography (FDTC 2007), Vienna, Austria.","DOI":"10.1109\/FDTC.2007.4318989"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Zhang, T., Jiang, H., Gui, X., and Chen, L. (2012, January 6\u20137). Design principles for trusted platform modules protected with power analysis. Proceedings of the 2012 Second International Conference on Intelligent System Design and Engineering Application, Sanya, China.","DOI":"10.1109\/ISdea.2012.571"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Tomlinson, A. (2017). Introduction to the TPM. Smart Cards, Tokens, Security and Applications, Springer.","DOI":"10.1007\/978-3-319-50500-8_7"},{"key":"ref_41","unstructured":"STMicroelectronics (2021, November 26). STSAFE-A110 Authentication, State-of-the-Art Security for Peripherals and IoT Devices; Rev. 1.0. Available online: https:\/\/www.st.com\/resource\/en\/datasheet\/stsafe-a110.pdf."},{"key":"ref_42","unstructured":"STMicroelectronics (2021, November 26). STSAFE-A110 Generic Sample Profile Description; Rev. 2.0. Available online: https:\/\/www.st.com\/resource\/en\/application_note\/an5435-stsafea110-generic-sample-profile-description-stmicroelectronics.pdf."},{"key":"ref_43","unstructured":"STMicrolectronics (2021, November 26). X-CUBE-SAFEA1. Available online: https:\/\/www.st.com\/content\/st_com_cx\/en\/products\/embedded-software\/mcu-mpu-embedded-software\/stm32-embedded-software\/stm32cube-expansion-packages\/x-cube-safea1.html."},{"key":"ref_44","unstructured":"STMicrolectronics (2021, December 01). X-CUBE-IOTA1. Available online: https:\/\/github.com\/STMicroelectronics\/x-cube-iota1."},{"key":"ref_45","unstructured":"STMicroelectronics (2021, November 26). Data Brief for Discovery Kit for IoT Node, Multi-Channel Communication with STM32L4+ Series; Rev. 1.0. Available online: https:\/\/www.st.com\/resource\/en\/data_brief\/b-l4s5i-iot01a.pdf."},{"key":"ref_46","unstructured":"STMicroelectronics (2021, November 26). User Manual for Discovery Kit for IoT Node, Multi-Channel Communication with STM32L4+ Series; Rev. 1.0. Available online: https:\/\/www.st.com\/resource\/en\/user_manual\/um2708-discovery-kit-for-iot-node-multichannel-communication-with-stm32l4-series-stmicroelectronics.pdf."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/4\/1384\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:17:20Z","timestamp":1760134640000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/22\/4\/1384"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,2,11]]},"references-count":46,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2022,2]]}},"alternative-id":["s22041384"],"URL":"https:\/\/doi.org\/10.3390\/s22041384","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,2,11]]}}}