Perancangan Dan Implementasi Mekanisme Autentikasi Pesan MQTT Berbasis HMAC-SHA256 Pada Arsitektur Industrial Control System Berbiaya Rendah

dc.contributor.advisorArif, Hamdani
dc.contributor.authorWidagdo, Muhamad Hanif
dc.date.accessioned2026-08-27T05:07:15Z
dc.date.issued2026-08-10
dc.description.abstractThe convergence of Information Technology (IT) and Operational Technology (OT) through the Industrial Internet of Things (IIoT) has transformed manufacturing by enabling real-time monitoring and remote machine control. However, cost considerations in medium-scale industries often lead to the use of low cost Industrial Control Systems (ICS) that utilize resource-constrained devices, such as the Arduino Uno R3, as edge nodes. This architecture introduces severe security vulnerabilities, particularly due to the transmission of unencrypted MQTT messages over port 1883, making the system highly susceptible to Man-in-the Middle (MitM) and command forgery attacks. Traditional transport layer security mitigations like Mutual TLS (mTLS) are infeasible due to the heavy computational overhead and the Arduino's limited SRAM (2 KB), which risks triggering heap exhaustion. This study proposes an application layer security mechanism using the HMAC-SHA256 algorithm to guarantee payload authenticity and integrity on the Web–Broker–Bridge path, coupled with a bitwise XOR Checksum on the Serial UART path to detect physical transmission errors. The proposed design is implemented using a .NET Framework 4.8 Bridge and an Arduino Uno R3 firmware, and evaluated within an isolated physical testbed. The experimental results demonstrate that the proposed mechanism successfully achieves a 100% block rate against spoofing attacks and a 100% detection rate against tampering on state files. Furthermore, the security overhead remains highly acceptable; the HMAC-SHA256 computation, offloaded to the Gateway layer, incurs an average processing latency of only 0.236 ms with a median of 0.070 ms (well below the 200 ms operational threshold), while the integrity validation layer on the edge device adds only 170 bytes of Flash ROM and a transient 20-byte SRAM stack usage, imposing no persistent memory burden on the Arduino Uno microcontroller, ensuring that the physical control of the machinery remains stable and real-time.
dc.identifier.citationIEEE
dc.identifier.kodeprodiKODEPRODI57302#Rekayasa Keamanan Siber
dc.identifier.nidnNIDN0001129002
dc.identifier.nimNIM4332201055
dc.identifier.urihttps://repository.polibatam.ac.id//handle/PL29/6224
dc.language.isoother
dc.publisherPoliteknik Negeri Batam
dc.subjectArduino Uno R3
dc.subjectHMAC-SHA256
dc.subjectIndustrial Control System
dc.subjectMQTT
dc.subjectXOR Checksum
dc.titlePerancangan Dan Implementasi Mekanisme Autentikasi Pesan MQTT Berbasis HMAC-SHA256 Pada Arsitektur Industrial Control System Berbiaya Rendah
dc.title.alternativeDesign and Implementation of HMAC-SHA256 Based MQTT Message Authentication Mechanism in Low-Cost Industrial Control System Architecture
dc.typeArticle

Files

Original bundle

Now showing 1 - 3 of 3
Loading...
Thumbnail Image
Name:
4332201055_Article.pdf
Size:
596.47 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Borang_Publikasi.pdf
Size:
441.45 KB
Format:
Adobe Portable Document Format
Loading...
Thumbnail Image
Name:
Lembar_Pengesahan.pdf
Size:
403.55 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: