MQT-TZ: Secure MQTT Broker for Biomedical Signal Processing on the Edge

07/03/2020
by   Carlos Segarra, et al.
0

Physical health records belong to healthcare providers, but the information contained within belongs to each patient. In an increasing manner, more health-related data is being acquired by wearables and other IoT devices following the ever-increasing trend of the "Quantified Self". Even though data protection regulations (e.g., GDPR) encourage the usage of privacy-preserving processing techniques, most of the current IoT infrastructure was not originally conceived for such purposes. One of the most used communication protocols, MQTT, is a lightweight publish-subscribe protocol commonly used in the Edge and IoT applications. In MQTT, the broker must process data on clear text, hence exposing a large attack surface for a malicious agent to steal/tamper with this health-related data. In this paper, we introduce MQT-TZ, a secure MQTT broker leveraging Arm TrustZone, a popular Trusted Execution Environment (TEE). We define a mutual TLS-based handshake and a two-layer encryption for end-to-end security using the TEE as a trusted proxy. We provide quantitative evaluation of our open-source PoC on streaming ECGs in real time and highlight the trade-offs.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/24/2020

MQT-TZ: Hardening IoT Brokers Using ARM TrustZone

The publish-subscribe paradigm is an efficient communication scheme with...
research
04/27/2021

KEVLAR-TZ: A Secure Cache for ARM TrustZone

Edge devices are increasingly in charge of storing privacy-sensitive dat...
research
09/14/2019

iperfTZ: Understanding Network Bottlenecks for TrustZone-based Trusted Applications

The growing availability of hardware-based trusted execution environment...
research
03/31/2023

Combining Blockchain and IOT for Decentralized Healthcare Data Management

The emergence of the Internet of Things (IoT) has resulted in a signific...
research
07/29/2019

Secure Stream Processing for Medical Data

Medical data belongs to whom it produces it. In an increasing manner, th...
research
04/26/2018

Enabling Trusted App Development @ The Edge

We present the Databox application development environment or SDK as a m...
research
09/15/2020

Secure Internal Communication of a Trustzone-Enabled Heterogeneous Soc Lightweight Encryption

Security in TrustZone-enabled heterogeneous system-on-chip (SoC) is gain...

Please sign up or login with your details

Forgot password? Click here to reset