Skip to content
Open access

SHERLOC: a privacy-preserving smart home system with secure message routing and privilege control

Jul 2026 · Cybersecurity · Vol 9 · 0 citations · 48 references
Computer Science

TL;DR

Experimental results from a full-scale prototype, comprising ESP32-based devices and Android apps, demonstrate that SHERLOC incurs millisecond-level latency and maintains compatibility with legacy MQTT brokers without altering protocol semantics, making it a robust and deployable solution for modern smart home environments.

Abstract

Smart home platforms predominantly adopt the broker-mediated publish/subscribe model (e.g., MQTT) for seamless device-app coordination. However, this architecture introduces a fundamental privacy-functionality conflict: the broker requires plaintext metadata (topic strings) for message routing, which inadvertently exposes fine-grained user behavioral patterns to semi-trusted service providers. Furthermore, existing systems lack rigorous cryptographic enforcement for app permissions, leaving the ecosystem vulnerable to over-privileged or malicious apps. While conventional Attribute-Based Encryption (ABE) provides fine-grained read-side access control, it cannot enforce writer-bound policies and remains computationally prohibitive for resource-constrained IoT nodes. In this paper, we propose SHERLOC, a practical and privacy-preserving framework that reconciles secure message routing with fine-grained privilege control. SHERLOC introduces two core primitives: (1) Secret Queue Telemetry Transport (SQTT), which leverages a novel trapdoor-based matching mechanism to support multi-level wildcard routing while ensuring topic indistinguishability and resistance against inside keyword-guessing attacks (IKGA); and (2) Outsourced Inner-Product Access Control Encryption (OS-IPACE), an attribute-hiding scheme that enforces dual no-read and no-write security for apps by offloading intensive pairing operations to a local hub without compromising data secrecy. We provide formal security proofs reducing SHERLOC’s privacy guarantees to the SXDH assumption. Experimental results from a full-scale prototype, comprising ESP32-based devices and Android apps, demonstrate that SHERLOC incurs millisecond-level latency and maintains compatibility with legacy MQTT brokers without altering protocol semantics, making it a robust and deployable solution for modern smart home environments.

Read PDF

Similar papers

Aug 2026

A flexible privacy-preserving framework for instant messaging in mobile social networks

A flexible privacy-preserving framework that combines the scalability of broadcast encryption with the fine-grained access control of Attribute-Based Encryption through a novel pseudo-layer encryption model, and achieves confidentiality, forward and backward secrecy, and collusion resistance.

Seyyed Mohammad Safi, Mahnaz Rafie, Sarina Sadat Mirmohammadi · 0 citations
Dec 2025

Achieving Flexible and Secure Authentication With Strong Privacy in Decentralized Networks

A flexible credential model that employs vector commitments with a padding strategy to unify credentials from heterogeneous issuers, enabling privacy-preserving authentication without enforcing a global static attribute set or verifier-defined policies is proposed.

Bin Xie, Rui Song, Xuyuan Cai et al. · 0 citations
Open access Jul 2026

An Efficient Privacy-Preserving Batch Authentication Scheme in Fog-Enabled VANETs

Performance evaluation examines the trade-off among authentication efficiency, communication overhead, and revocation performance, showing that EPAF is a practical solution for fog-enabled vehicular communication.

Cong Zhao, X. Ge, Yi-Kang Yang et al. · 0 citations
Conference Open access Jul 2026

MOSAIC-FL, a Micro-Service Based Privacy-Preserving Framework with Application to Genomics

The FL framework integrates an efficient gRPC communication layer and a Finite State Machine to ensure robust component synchronization and threat detection, while relying on a fault-tolerant secure aggregation protocol using a Threshold variant of the CKKS homomorphic cryptosystem.

P. Largillier, Karl Paygambar, Cédric Gouy-Pailler et al. · 0 citations

Doppio : Communication-Efficient and Secure Multi-Party Shuffle Differential Privacy

The augmented multi-party shuffle DP (AMP-SDP) model is proposed, which re-architects the data pipeline with a lightweight, versatile secret-shared intermediary layer that decentralizes trust while minimizing online communication costs and provides structural security hardening against both shuffler compromise and user-sid...

Wentao Dong, Yang Cao, Cong Wang et al. · 0 citations
2026

A Privacy-Preserving Scheme Based on Attribute and Homomorphic Encryption for Trustworthy Multi-Agent Data Management in Intelligence Edge Networking

With the deep integration of AI-native edge intelligence and 6G networks, distributed multi-agent systems composed of autonomous agents such as digital twins, autonomous vehicles, and the industrial Internet of Things are becoming the critical infrastructure for achieving “Synesthesia of Machines” of multi-source heter...

Fu Zhang, Xue-Yi Xia, Zhao-Feng Ma et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.