This is an early access version, the complete PDF, HTML, and XML versions will be available soon.
Open AccessArticle
Secure Local Communication Between Browser Clients and Resource-Constrained Embedded IoT Devices
by
Christian Schwinne
Christian Schwinne *
and
Jan Pelzl
Jan Pelzl
Department Hamm 1, Hamm-Lippstadt University of Applied Sciences, 59063 Hamm, Germany
*
Author to whom correspondence should be addressed.
J. Cybersecur. Priv. 2026, 6(1), 9; https://doi.org/10.3390/jcp6010009 (registering DOI)
Submission received: 20 October 2025
/
Revised: 6 December 2025
/
Accepted: 25 December 2025
/
Published: 1 January 2026
Abstract
This contribution outlines a completely new, fully local approach for secure web-based device control on the basis of browser inter-window messaging. Modern smart home IoT (Internet of Things) devices are commonly controlled with proprietary mobile applications via remote servers, which can have significant adverse implications for the end user. Given that many IoT devices in use today are limited in both available memory and processing speed, standard approaches such as HTTPS-based transport security are not always feasible and a need for more suitable alternatives for such constrained devices arises. The proposed local method for lightweight and secure web-based device control using inter-window messaging leverages existing standard web technologies to enable a maximum degree of privacy, choice, and sustainability within the smart home ecosystem. The implemented proof-of-concept shows that it is feasible to meet essential security objectives in a local web IoT control context while utilizing less than a kilobyte of additional memory compared to an unsecured solution, thereby promoting sustainability through hardening of the control protocols used by existing devices with too few resources for implementing standard web cryptography. In this way, the present work contributes to achieving the vision of a fully open and secure local smart home.
Share and Cite
MDPI and ACS Style
Schwinne, C.; Pelzl, J.
Secure Local Communication Between Browser Clients and Resource-Constrained Embedded IoT Devices. J. Cybersecur. Priv. 2026, 6, 9.
https://doi.org/10.3390/jcp6010009
AMA Style
Schwinne C, Pelzl J.
Secure Local Communication Between Browser Clients and Resource-Constrained Embedded IoT Devices. Journal of Cybersecurity and Privacy. 2026; 6(1):9.
https://doi.org/10.3390/jcp6010009
Chicago/Turabian Style
Schwinne, Christian, and Jan Pelzl.
2026. "Secure Local Communication Between Browser Clients and Resource-Constrained Embedded IoT Devices" Journal of Cybersecurity and Privacy 6, no. 1: 9.
https://doi.org/10.3390/jcp6010009
APA Style
Schwinne, C., & Pelzl, J.
(2026). Secure Local Communication Between Browser Clients and Resource-Constrained Embedded IoT Devices. Journal of Cybersecurity and Privacy, 6(1), 9.
https://doi.org/10.3390/jcp6010009
Article Metrics
Article metric data becomes available approximately 24 hours after publication online.