The publish-subscribe paradigm has become the mainstream communication model for large-scale Internet of Things (IoT) systems. However, existing end-to-end encryption solutions based on Conditional Proxy Re-Encryption (CPRE) suffer from limitations in supporting dynamic and fine-grained access control policies. This paper proposes a dynamic policy-aware CPRE system that extends traditional CPRE with multi-dimensional condition support and policy hiding capabilities. Our system introduces a JSON-based policy language to define complex access control rules incorporating temporal, spatial, role-based, and device status conditions. We design a policy matching engine that enables fine-grained authorization while preserving policy privacy. The proposed scheme is implemented as an extension to the HiveMQ MQTT broker and evaluated comprehensively. Experimental results demonstrate that our system achieves enhanced security with acceptable performance overhead, providing only 5–15% increase in encryption time while supporting rich dynamic policies compared to the original CPRE scheme.
Building similarity graph...
Analyzing shared references across papers
Loading...
Shi Mei Lin
Niu Ke
Hu Jun Ru
Scientific Reports
Building similarity graph...
Analyzing shared references across papers
Loading...
Lin et al. (Thu,) studied this question.
www.synapsesocial.com/papers/69d0aefd659487ece0fa4e11 — DOI: https://doi.org/10.1038/s41598-026-46939-3