Submit your papersSubmit Now
For Enquiries: [email protected]
IIARD LogoIIARD

Certificate Authentication and Revocation System for IoT Devices using CoAP and CBOR Encoding in LoRaWAN

Duke, Tamunotonye Juliana, Sako, D.J.S., Bennett, E.O.

Abstract

Certificate revocation protocols are mechanisms used in a public key infrastructure to check if a digital certificate is still valid before its expiration date. Organizations deploy PKI across web servers, email platforms, virtual private networks, and, more recently, Internet of Things devices to authenticate endpoints and encrypt data in transit. Certificate revocation in Long Range Wide Area Network (LoRaWAN) is highly inefficient because traditional PKI mechanisms, like Certificate Revocation Lists or the Online Certificate Status Protocol , require data payloads and energy consumption that easily overwhelm resource-constrained IoT devices, introducing transaction sizes that are unsuitable for the 51-byte payload ceiling at LoRaWAN spreading factor 12 (SF12). This paper presents a system for a compact certificate revocation protocol for resource-constrained IoT devices operating on LoRaWAN networks. The proposed protocol combines Constrained Application Protocol and Concise Binary Object Representation encoding so that revocation request and response payloads remain within the LoRaWAN SF12 payload limit of 51 bytes. We implemented the proposed protocol in Python using standard cryptographic and constrained-network libraries, including OpenSSL, cryptography, aiocoap, and cbor2, together with a LoRaWAN simulation and energy-modelling environment. The protocol produced a 10-byte request and 19-byte response, giving a total payload of 29 bytes and remaining within the SF12 payload limit. Cache hit rates exceeded 97% across all tested scenarios under the shared peer-certificate workload. A web application interface was developed to expose the certificate-revocation workflow through configurable scenario inputs, communication testing, event logging, and report export controls.

Keywords

Keywords: LoRaWANInternet of ThingsConcise binary Object RepresentationConstrained Application ProtocolPublic Key Infrastructure

References

Astorga, J., Barcelo, M., Urbieta, A & Jacob, E. (2022). Revisiting the feasibility of public key cryptography in light of IIoT communications. Sensors, 22(7), 2561. Bormann, C., & Hoffman, P. (2020). Concise binary object representation (RFC 8949). Internet Engineering Task Force. https://doi.org/10.17487/RFC8949 Cooper, D., Santesson, S., Farrell, S., Boeyen, S., Housley, R., & Polk, W. (2008). Internet X.509 public key infrastructure certificate and certificate revocation list profile (RFC 5280). Internet Engineering Task Force. https://doi.org/10.17487/RFC5280 Ferreira, C. M., Sousa, N. M., & Correia, M. E. (2023). Certificate-based authentication for LoRaWAN: Design and performance evaluation. Ad Hoc Networks, 141, 103089. https://doi.org/10.1016/j.adhoc.2023.103089 Goppert, J., Walz, A.&Sikora, A. (2024). A survey on life-cycle-oriented certificate management in industrial networking environments,Journal of Sensor and Actuator Networks,13(2), 26. Hoglund, J., Furuhed, M., & Raza, S. (2023). Lightweight certificate revocation for low-power IoT with end-to-end security. Journal of Information Security and Applications, 73, 103424. https://doi.org/10.1016/j.jisa.2023.103424 Haxhibeqiri,J., De Poorter, E., Moerman, I. & Hoebeke, J. (2018). A survey of LoRaWAN for IoT: From technology to application, Sensors, 18(11), 3995. Kannwischer, M. J., Rijneveld, J., Schwabe, P., & Stoffelen, K. (2019). pqm4: Testing and Benchmarking NIST PQC on ARM Cortex-M4. Cryptology ePrint Archive, Paper 2019/844. https://eprint.iacr.org/2019/844 Khan, S., Lu, Y., Jiang, T., Madni, H. A., Khan, K. M., Rathnayake, M. V., Alzaidi, M. S., Aljuaid, H., Aziz, A., Yar, H., Ali, K., & Akbar, A. (2023). A survey on X.509 public- key infrastructure, certificate revocation, and their modern implementation on blockchain and ledger technologies. IEEE Communications Surveys & Tutorials, 25(4), 2306-2343. https://doi.org/10.1109/COMST.2023.3323640 Milani S. & Chatzigiannakis, I. (2021). Design, analysis, and experimental evaluation of a new secure rejoin mechanism for LoRaWAN using elliptic-curve cryptography, Journal of Sensor and Actuator Networks, 10(2), 36. Sanchez-Iborra, R., Sanchez-Gomez, J., Perez, S., Fernandez, P. J., Santa, J., Hernandez- Ramos, J. L., & Skarmeta, A. F. (2018). Enhancing LoRaWAN security through a lightweight and authenticated key management approach. Sensors, 18(6), 1833. https://doi.org/10.3390/s18061833 Sanchez-Iborra, R., Sanchez-Gomez, J., Ballesta-Vinas, J., Cano, M. D., & Skarmeta, A. F. (2023). Performance evaluation of LoRa technology with different spreading factors. Computer Communications, 192, 236-246. https://doi.org/10.1016/j.comcom.2023.015432 Shelby, Z., Hartke, K., & Bormann, C. (2014). The Constrained Application Protocol (RFC 7252). Internet Engineering Task Force. https://doi.org/10.17487/RFC7252 Sinha, S. (2024). State of IoT 2024: Number of connected IoT devices growing 13% to 18.8 billion globally, IoT Analytics. Stanco, G., Navarro, A., Frattini, F., Ventre, G. & Botta, A. (2024). A comprehensive survey on the security of low power wide area networks for the Internet of Things, ICT Express, 10 (3), 519-552.

More Articles from INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND MATHEMATICAL THEORY