Repository logo
Communities
Research Outputs
Projects
Researchers
Statistics
Feedback
  1. Home
  2. CRIS
  3. Publications
  4. Experimental and data-driven evaluation of transport-layer and application-layer security for MQTT-based IoT networks
Details

Experimental and data-driven evaluation of transport-layer and application-layer security for MQTT-based IoT networks

Journal
Pervasive and Mobile Computing
Publisher
Elsevier BV
Date Issued
2026-12
Author(s)
Del-Valle-Soto, Carolina  
Facultad de Ingeniería - CampGDL  
Alvarez-Garcia, Maria Fernanda
Valdivia, Leonardo  
Facultad de Ingeniería - CampGDL  
Del-Puerto-Flores, J. Alberto  
Facultad de Ingeniería - CampGDL  
Varela-Aldás, José
Visconti, Paolo
Type
Article
DOI
10.1016/j.pmcj.2026.102272
URL
https://scripta.up.edu.mx/handle/20.500.12552/13226
Abstract
The rapid expansion of Internet of Things (IoT) deployments has intensified the need for secure and efficient communication mechanisms tailored to resource-constrained devices. Message Queuing Telemetry Transport (MQTT) is widely adopted due to its lightweight design; however, it lacks native security support, requiring external protection mechanisms that may significantly affect system performance. This paper presents a comprehensive experimental and data-driven evaluation of two security paradigms for MQTT-based IoT networks implemented on ESP32 microcontrollers: transport-layer security using TLS and application-layer encryption based on elliptic curve cryptography (ECC) for key exchange combined with AES symmetric encryption. The analysis jointly evaluates memory utilization, end-to-end latency, energy consumption, and resistance to passive traffic interception under identical experimental conditions. In addition to conventional metric-based comparisons, multivariate statistical analysis and unsupervised learning techniques are employed as exploratory tools to characterize the system-level behavior induced by each security scheme. Results show that Transport Layer Security (TLS) offers stronger confidentiality guarantees at the cost of higher memory overhead, while the ECC–(Advanced Encryption Standard) AES approach significantly reduces memory footprint with moderate latency penalties and comparable energy consumption. Multivariate analysis further reveals that each security mechanism induces a distinct performance regime, providing a compact joint characterization of the security–performance trade-offs across the evaluated configurations. © 2026

Creación y actualización de perfiles en Scripta+

Hosting & Support by

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science

  • Accessibility settings
  • Privacy policy
  • End User Agreement
  • Send Feedback
Repository logo COAR Notify