Publications
Projects
login
About
login:
password:
Forgot your password?
Securing the MQTT Publish-Subscribe Protocol
Securing the MQTT Publish-Subscribe Protocol
Publication type:
mastersthesis
Zusammenfassung:
Publish/Subscribe ist ein messaging Paradigma, welches dynamische many-to-many Kommunikation in lose gekoppelten und verteilten Umgebungen ermöglicht. Das MQ Telemetry Transport Protocol (MQTT) ist ein topic-based publish/subscribe Protokoll. Informationsproduzenten publizieren Nachrichten zu einem Thema (Topic) an einen Message-Broker, und Informationskonsumenten schreiben sich auf einem Message-Broker ein, um die Nachrichten zu den sie interessierenden Topics zu erhalten. Dabei ist der Message-Broker für die Speicherung und Weiterleitung der Nachrichten verantwortlich. IBM hat eine publish/subscribe Infrastruktur entwickelt, welche MQTT als Messaging-Protokoll verwendet. Das Herz der Infrastruktur bildet ein Message-Broker von geringer Grösse. Das Design der implementierten Lösung ermöglicht ein dynamisches Konfigurieren der verwendeten Protokollstapel mittels einfügbaren Modulen. Die Module garantieren gewisse Kommunikationseigenschaften wie zum Beispiel Zuverlässigkeit oder segmentation and reassembly. Dieses publish/subscribe System wird vor allem in Umgebungen eingesetzt, welche von einer zentralen Instanz betrieben und administriert werden. Dabei kann ein solches System hunderte oder gar tausende Teilnehmer umfassen. Da das verwendete MQTT Protokoll keinerlei Sicherheitseigenschaften anbietet, hat sich das Bedürfnis nach gesicherter Kommunikation entwickelt. Damit könnten die Teilnehmer auch in nicht vertrauenswürdigen Netzwerken eingesetzt werden.
Authors:
Andreas Wirth
Abstract:
Publish/Subscribe is a messaging paradigm that supports dynamic many-to-many communication in a loosely coupled distributed environment. MQTT is a topic-based publish/subscribe protocol. Information producers publish topic related events to a message broker, and information consumers subscribe to some of these topics. The message broker is responsable to store the events and forward them to the information consumers. IBM implemented a publish/subscribe infrastructure consisting of a small footprint message broker and messaging clients, using the MQTT protocol. The flexible design of this implementation allows to dynamically configure protocol stacks consisting of modules that offer different services, such as reliability or segmentation and reassembly. The MQTT protocol has been designed without security in mind, but the need of a secured communication between the messaging clients and the message broker evolved. In this thesis, the design and prototypical implementation of encryption and access control modules is introduced, which are pluggable into the protocol stacks.
Title:
Securing the MQTT Publish-Subscribe Protocol
Year:
2006
school:
University of Zurich
group:
csg
actions