{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T13:59:25Z","timestamp":1784296765905,"version":"3.55.0"},"reference-count":44,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2024,1,10]],"date-time":"2024-01-10T00:00:00Z","timestamp":1704844800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>In light of the existing security vulnerabilities within IoT publish\u2013subscribe systems, our study introduces an improved end-to-end encryption approach using conditional proxy re-encryption. This method not only overcomes limitations associated with the reliance on a trusted authority and the challenge of reliably revoking users in previous proxy re-encryption frameworks, but also strengthens data privacy against potential collusion between the broker and subscribers. Through our innovative encryption protocol, unauthorized re-encryption by brokers is effectively prevented, enhancing secure communication between publisher and subscriber. Implemented on HiveMQ, an open-source MQTT platform, our prototype system demonstrates significant enhancements. Comparison to the state-of-the-art end-to-end encryption work, encryption overhead of our scheme is comparable to it, and the decryption cost is approximately half of it. Moreover, our solution significantly improves overall security without compromising the asynchronous communication and decentralized authorization foundational to the publish\u2013subscribe model.<\/jats:p>","DOI":"10.3390\/s24020438","type":"journal-article","created":{"date-parts":[[2024,1,11]],"date-time":"2024-01-11T03:21:41Z","timestamp":1704943301000},"page":"438","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":13,"title":["End-to-End Encrypted Message Distribution System for the Internet of Things Based on Conditional Proxy Re-Encryption"],"prefix":"10.3390","volume":"24","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-0040-2504","authenticated-orcid":false,"given":"Shi","family":"Lin","sequence":"first","affiliation":[{"name":"School of Cryptographic Engineering, Engineering University of PAP, Xi\u2019an 710000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Li","family":"Cui","sequence":"additional","affiliation":[{"name":"School of Information and Communication, National University of Defense Technology, Wuhan 430000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Niu","family":"Ke","sequence":"additional","affiliation":[{"name":"School of Cryptographic Engineering, Engineering University of PAP, Xi\u2019an 710000, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,1,10]]},"reference":[{"key":"ref_1","unstructured":"Banks, A., Briggs, E., Borgendale, K., and Gupta, R. (2019). MQTT, Version 5.0, OASIS."},{"key":"ref_2","unstructured":"Godfrey, R., and Ingham, D.S.R. (2012). Advanced Message Queuing Protocol (AMQP), Version 1.0, OASIS."},{"key":"ref_3","unstructured":"Heninger, N., and Traynor, P. (2019, January 14\u201316). Discovering and Understanding the Security Hazards in the Interactions between IoT Devices, Mobile Apps, and Clouds on Smart Home Platforms. Proceedings of the 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA."},{"key":"ref_4","unstructured":"Choudhury, T., Ko, S.Y., Campbell, A., and Ganesan, D. (2017, January 19\u201323). Trust but Verify: Auditing the Secure Internet of Things. Proceedings of the 15th Annual International Conference on Mobile Systems, Applications, and Services, MobiSys\u201917, Niagara Falls, NY, USA."},{"key":"ref_5","unstructured":"Gupta, M., Abdelsalam, M., and Mittal, S. (2021, January 28). Transparent End-to-End Security for Publish\/Subscribe Communication in Cyber-Physical Systems. Proceedings of the SAT-CPS@CODASPY 2021, Proceedings of the 2021 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems, Virtual Event."},{"key":"ref_6","unstructured":"Maggi, F., Vosseler, R., and Quarta, D. (2018). The Fragility of Industrial IoT\u2019s Data Backbone: Security and Privacy Issues in MQTT and CoAP Protocols, Trend Micro Inc."},{"key":"ref_7","unstructured":"Huq, N., Vosseler, R., and Swimmer, M. (2017). Cyberattacks against Intelligent Transportation Systems."},{"key":"ref_8","unstructured":"EMQ (2021). EMQX Broker Docs, EMQ. v4.3."},{"key":"ref_9","unstructured":"HiveMQ (2021). HiveMQ Documentation, HiveMQ. v4.7."},{"key":"ref_10","unstructured":"Solace (2021). Solace Cloud, Solace."},{"key":"ref_11","unstructured":"Alibaba (2021). Alibaba Cloud Iot Platform, Alibaba."},{"key":"ref_12","unstructured":"Amazon (2021). Aws Iot Core, Amazon."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"1661","DOI":"10.1109\/TCC.2020.3000336","article-title":"Complying With Data Handling Requirements in Cloud Storage Systems","volume":"10","author":"Henze","year":"2022","journal-title":"IEEE Trans. Cloud Comput."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Jia, Y., Xing, L., Mao, Y., Zhao, D., Wang, X., Zhao, S., and Zhang, Y. (2020, January 18\u201321). Burglars\u2019 IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT Clouds. Proceedings of the 2020 IEEE Symposium on Security and Privacy, SP 2020, San Francisco, CA, USA.","DOI":"10.1109\/SP40000.2020.00051"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1016\/j.future.2016.10.013","article-title":"PICADOR: End-to-end encrypted Publish-Subscribe information distribution with proxy re-encryption","volume":"71","author":"Borcea","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_16","first-page":"127","article-title":"Divertible Protocols and Atomic Proxy Cryptography","volume":"Volume 1403","author":"Nyberg","year":"1998","journal-title":"Proceedings of the Advances in Cryptology-EUROCRYPT\u201998, International Conference on the Theory and Application of Cryptographic Techniques"},{"key":"ref_17","first-page":"66","article-title":"Improved Security Notions for Proxy Re-Encryption to Enforce Access Control","volume":"Volume 11368","author":"Lange","year":"2017","journal-title":"Proceedings of the Progress in Cryptology-LATINCRYPT 2017-5th International Conference on Cryptology and Information Security in Latin America"},{"key":"ref_18","unstructured":"Li, W., Susilo, W., Tupakula, U.K., Safavi-Naini, R., and Varadharajan, V. (2009, January 10\u201312). Conditional proxy re-encryption secure against chosen-ciphertext attack. Proceedings of the 2009 ACM Symposium on Information, Computer and Communications Security, ASIACCS 2009, Sydney, Australia."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Qiu, J., Hwang, G., and Lee, H. (2014, January 3\u20135). Efficient Conditional Proxy Re-encryption with Chosen-Ciphertext Security. Proceedings of the Ninth Asia Joint Conference on Information Security, AsiaJCIS 2014, Wuhan, China. Computer Society.","DOI":"10.1109\/AsiaJCIS.2014.11"},{"key":"ref_20","unstructured":"Heninger, N., and Traynor, P. (2019, January 14\u201316). JEDI: Many-to-Many End-to-End Encryption and Key Delegation for IoT. Proceedings of the 28th USENIX Security Symposium, USENIX Security 2019, Santa Clara, CA, USA."},{"key":"ref_21","first-page":"300","article-title":"Identity-Based Encryption Gone Wild","volume":"Volume 4052","author":"Bugliesi","year":"2006","journal-title":"Proceedings of the Automata, Languages and Programming, 33rd International Colloquium, ICALP 2006"},{"key":"ref_22","unstructured":"Haddad, H.M., Wainwright, R.L., and Chbeir, R. (2018, January 9\u201313). Secure publish and subscribe systems with efficient revocation. Proceedings of the 33rd Annual ACM Symposium on Applied Computing, SAC 2018, Pau, France."},{"key":"ref_23","first-page":"332","article-title":"MQT-TZ: Secure MQTT Broker for Biomedical Signal Processing on the Edge","volume":"Volume 270","author":"Lovis","year":"2020","journal-title":"Proceedings of the Digital Personalized Health and Medicine-Proceedings of MIE 2020, Medical Informatics Europe"},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1109\/TC.2017.2647955","article-title":"Hardware-Based Trusted Computing Architectures for Isolation and Attestation","volume":"67","author":"Maene","year":"2018","journal-title":"IEEE Trans. Comput."},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1109\/Trustcom.2015.357","article-title":"Trusted Execution Environment: What It is, and What It is Not","volume":"Volume 1","author":"Sabt","year":"2015","journal-title":"Proceedings of the 2015 IEEE TrustCom\/BigDataSE\/ISPA"},{"key":"ref_26","first-page":"54","article-title":"Proxy Cryptosystems: Delegation of the Power to Decrypt Ciphertexts (Special Section on Cryptography and Information Security)","volume":"80","author":"Mambo","year":"1997","journal-title":"IEICE Trans. Fundam. Electron. Commun. Comput. Sci."},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Weng, J., Yang, Y., Tang, Q., Deng, R.H., and Bao, F. (2009, January 18\u201320). Efficient Conditional Proxy Re-encryption with Chosen-Ciphertext Security. Proceedings of the Information Security Conference, Pafos, Cyprus.","DOI":"10.1007\/978-3-642-04474-8_13"},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Shao, J., Wei, G., Ling, Y., and Xie, M. (2011, January 5\u20139). Identity-Based Conditional Proxy Re-Encryption. Proceedings of the 2011 IEEE International Conference on Communications (ICC), Kyoto, Japan.","DOI":"10.1109\/icc.2011.5962419"},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Liang, K., Liu, Z., Tan, X., Wong, D.S., and Tang, C. (2012, January 28\u201330). A CCA-Secure Identity-Based Conditional Proxy Re-Encryption without Random Oracles. Proceedings of the International Conference on Information Security and Cryptology, Seoul, Republic of Korea.","DOI":"10.1007\/978-3-642-37682-5_17"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.tcs.2016.08.023","article-title":"On the security of two identity-based conditional proxy re-encryption schemes","volume":"652","author":"He","year":"2016","journal-title":"Theor. Comput. Sci."},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1016\/j.tcs.2012.08.017","article-title":"Chosen-ciphertext secure anonymous conditional proxy re-encryption with keyword search","volume":"462","author":"Fang","year":"2012","journal-title":"Theor. Comput. Sci."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"83","DOI":"10.1016\/j.tcs.2012.11.026","article-title":"Proxy-invisible CCA-secure type-based proxy re-encryption without random oracles","volume":"491","author":"Seo","year":"2013","journal-title":"Theor. Comput. Sci."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Son, J., Kim, D., Hussain, R., and Oh, H. (May, January 27). Conditional proxy re-encryption for secure big data group sharing in cloud environment. Proceedings of the 2014 IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), Toronto, ON, Canada.","DOI":"10.1109\/INFCOMW.2014.6849289"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"2778","DOI":"10.1093\/comjnl\/bxv050","article-title":"Efficient and Fully CCA Secure Conditional Proxy Re-Encryption from Hierarchical Identity-Based Encryption","volume":"58","author":"Liang","year":"2015","journal-title":"Comput. J."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.csi.2016.12.005","article-title":"Identity-based conditional proxy re-encryption with fine grain policy","volume":"52","author":"Ge","year":"2017","journal-title":"Comput. Stand. Interfaces"},{"key":"ref_36","first-page":"2","article-title":"Flexible, Efficient, and Secure Access Delegation in Cloud Computing","volume":"10","author":"Xiong","year":"2019","journal-title":"ACM Trans. Manag. Inf. Syst. (TMIS)"},{"key":"ref_37","first-page":"1","article-title":"A Provably Secure Conditional Proxy Re-Encryption Scheme without Pairing","volume":"11","author":"Paul","year":"2019","journal-title":"J. Internet Serv. Inf. Secur."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Katz, J., and Lindell, Y. (2014). Introduction to Modern Cryptography, Computer Science, Mathematics. [2nd ed.]. Available online: https:\/\/api.semanticscholar.org\/CorpusID:9506320.","DOI":"10.1201\/b17668"},{"key":"ref_39","first-page":"459","article-title":"Efficient Communication-Storage Tradeoffs for Multicast Encryption","volume":"Volume 1592","author":"Stern","year":"1999","journal-title":"Proceedings of the Advances in Cryptology-EUROCRYPT\u201999, International Conference on the Theory and Application of Cryptographic Techniques"},{"key":"ref_40","unstructured":"Caro, A.D., and Iovino, V. (July, January 28). jPBC: Java pairing based cryptography. Proceedings of the 16th IEEE Symposium on Computers and Communications, ISCC 2011, Kerkyra, Corfu, Greece."},{"key":"ref_41","unstructured":"e Foundation (2021). Eclipse Paho Java Client, e Foundation."},{"key":"ref_42","unstructured":"HiveMQ (2021). Hivemq-Community-Edition, HiveMQ."},{"key":"ref_43","unstructured":"HiveMQSDK (2021). HiveMQ Extension SDK 4.7.1 API, HiveMQSDK."},{"key":"ref_44","unstructured":"Dirk, F. (2023, November 28). AES; Datenschutz und Datensicherheit, Advanced Encryption Standard (AES). Available online: https:\/\/api.semanticscholar.org\/CorpusID:31476420."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/2\/438\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T13:44:04Z","timestamp":1760103844000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/24\/2\/438"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,1,10]]},"references-count":44,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2024,1]]}},"alternative-id":["s24020438"],"URL":"https:\/\/doi.org\/10.3390\/s24020438","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,1,10]]}}}