Related Experiment Video
Updated: Dec 25, 2025

Integration of 5G Experimentation Infrastructures into a Multi-Site NFV Ecosystem
Published on: February 3, 2021
Security Architecture for Defining and Enforcing Security Profiles in DLT/SDN-Based IoT Systems.
Sara N Matheu1, Alberto Robles Enciso1, Alejandro Molina Zarca1
1Department of Information and Communications Engineering, University of Murcia, 30100 Murcia, Spain.
This study enhances Internet of Things (IoT) security by using Manufacturer Usage Description (MUD) to restrict device communication. The new method improves data privacy and network protection during device bootstrapping.
Area of Science:
- Computer Science
- Cybersecurity
- Network Engineering
Background:
- Internet of Things (IoT) devices face increasing cyber threats due to extensive data and connectivity.
- The Manufacturer Usage Description (MUD) standard offers a solution by defining network access control policies during manufacturing.
- Existing MUD implementations require enhancement to cover broader security aspects.
Purpose of the Study:
- To propose an architecture and process for obtaining and enforcing MUD restrictions during device bootstrapping.
- To extend the MUD model with a flexible policy language for data privacy, channel protection, and resource authorization.
- To leverage Software Defined Networking (SDN) and attribute-based access control for robust IoT security.
Main Methods:
- Defined an architecture and process for MUD policy enforcement during device bootstrapping.
- Extended the MUD model with a flexible policy language for enhanced security attributes.
- Utilized Software Defined Networking (SDN) and attribute-based access control (ABAC) with encryption.
- Integrated a blockchain platform for secure data sharing among devices.
Main Results:
- Successfully implemented and evaluated an architecture for MUD-based IoT security in a real-world scenario.
- Demonstrated the reduction of the attack surface in IoT deployments by restricting device communications.
- Showcased improved data privacy, channel protection, and resource authorization through the extended MUD model.
Conclusions:
- The proposed approach effectively enhances IoT security by enforcing MUD restrictions early in the device lifecycle.
- The integration of SDN, ABAC, and blockchain provides a comprehensive solution for securing sensitive IoT data.
- This method significantly reduces the vulnerability of IoT networks to cyberattacks by proactively managing device communication.
Related Concept Videos
Zones of Protection
Protective zones are defined by closed dashed lines, containing one or more components. A key characteristic of these zones is the strategic placement of...
Distribution Reliability and Automation
Global Regulatory Systems
Ethical Standards I
The Code of Ethics provisions outline the nurse's duty to the patient, the healthcare team, the profession, and society. The Code's fundamental principles include advocacy,...
Legal Guidelines for Documentation
Role-Based Identity