TDT-Pipe: A Security-Aware Architecture for Trustworthy IoT Digital Twins
Digital Twins rely on continuous data exchanges between physical assets, Internet of Things devices, communication infrastructures, and software representations. In MQTT-based deployments, however, successful message delivery does not guarantee that a telemetry value is authentic, authorized, fresh, structurally valid, or appropriate for updating the active twin state. This paper presents TDT-Pipe, a security-aware telemetry-to-Digital-Twin pipeline that separates message transport from update admission. The architecture integrates secure publication, registry-based device control, edge validation, provenance generation, controlled state management, quarantine, auditing, and policy-based views. Telemetry messages are protected through payload digests and device-specific HMACs, while validation predicates classify them as verified, suspicious, or untrusted and map each class to apply, quarantine, or reject actions. The formal model links active values to the events that produced them and supports security properties covering authentication, integrity, freshness, replay protection, controlled state modification, audit traceability, and view confinement. A lightweight prototype is used to assess the feasibility of the approach. The evaluation indicates that the proposed validation, provenance, and controlled-admission mechanisms can be integrated into IoT Digital Twin pipelines while keeping the processing overhead limited.