MeshGuard: MUD-Based Network Access Control for Large-Scale Thread-Powered IoT Networks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: George, Dominik Roy, van Hoof, Wouter, Mostafaei, Habib, Sciancalepore, Savio
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913173680947200
author George, Dominik Roy
van Hoof, Wouter
Mostafaei, Habib
Sciancalepore, Savio
author_facet George, Dominik Roy
van Hoof, Wouter
Mostafaei, Habib
Sciancalepore, Savio
contents The IETF standard Manufacturer Usage Description (MUD) enables manufacturers to equip IoT devices with certified URLs that provide traffic profiles for those devices, helping administrators enforce network access control. However, MUD assumes devices operate on full IP stacks and therefore does not account for constrained IoT devices running Thread--the dominant low-power mesh networking standard--which lacks complete TCP/IP functionality. While prior work proposes extensions to support MUD in Thread environments, these approaches are limited to simple topologies with a single border router and do not scale to realistic deployments with multiple, heterogeneous border routers. We introduce MeshGuard, a framework enabling MUD-based access control in complex Thread networks, with any number of border routers. MeshGuard extends the Mesh Link Establishment (MLE) protocol to deliver MUD information from constrained devices to border routers regardless of network topology. Moreover, MeshGuard leverages Software-Defined Networking (SDN) to synchronize access control lists across all routers. Experiments on our proof-of-concept with real devices (nRF5340, nRF52833, Raspberry-Pi 3) demonstrate enhanced security, minimal overhead, and linear scalability compared to state-of-the-art approaches.
format Preprint
id arxiv_https___arxiv_org_abs_2605_31326
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle MeshGuard: MUD-Based Network Access Control for Large-Scale Thread-Powered IoT Networks
George, Dominik Roy
van Hoof, Wouter
Mostafaei, Habib
Sciancalepore, Savio
Cryptography and Security
Networking and Internet Architecture
The IETF standard Manufacturer Usage Description (MUD) enables manufacturers to equip IoT devices with certified URLs that provide traffic profiles for those devices, helping administrators enforce network access control. However, MUD assumes devices operate on full IP stacks and therefore does not account for constrained IoT devices running Thread--the dominant low-power mesh networking standard--which lacks complete TCP/IP functionality. While prior work proposes extensions to support MUD in Thread environments, these approaches are limited to simple topologies with a single border router and do not scale to realistic deployments with multiple, heterogeneous border routers. We introduce MeshGuard, a framework enabling MUD-based access control in complex Thread networks, with any number of border routers. MeshGuard extends the Mesh Link Establishment (MLE) protocol to deliver MUD information from constrained devices to border routers regardless of network topology. Moreover, MeshGuard leverages Software-Defined Networking (SDN) to synchronize access control lists across all routers. Experiments on our proof-of-concept with real devices (nRF5340, nRF52833, Raspberry-Pi 3) demonstrate enhanced security, minimal overhead, and linear scalability compared to state-of-the-art approaches.
title MeshGuard: MUD-Based Network Access Control for Large-Scale Thread-Powered IoT Networks
topic Cryptography and Security
Networking and Internet Architecture
url https://arxiv.org/abs/2605.31326