scieee AI-readable full text Open interactive document viewer

Optimising secure and sustainable smart home configurations

Muñoz Heredia, Daniel; Varela Vaca, Ángel Jesús; Borrego Núñez, Diana; Gómez López, María Teresa

Abstract

As the adoption of smart devices accelerates rapidly in smart homes worldwide, the variety of available devices on the market is also diversifying. This creates a challenge for users, who must choose devices that best meet their needs, and for system designers, who must ensure these devices integrate efficiently within a connected ecosystem. In response to this challenge, the solution presented in this work provides a metamodel that gathers the smart home features, including attributes related to security, usability, connectivity and sustainability. These features are used to create personalised configurations of smart homes that meet user requirements. This is achieved through the creation of multi-objective optimisation problems focused on improving: security, to ensure network and personal data protection; usability, to facilitate the easy management of the environment; connectivity, to maintain seamless interaction between both existing and future devices; and sustainability, which assesses the environmental impact and energy efficiency of the technological ecosystem. The implementation of the proposal is available and a set of experiments have been developed to evaluate the proposal’s applicability using real devices, being reproducible and replicable.

Full text

Contents lists available at ScienceDirect Internet of Things journal homepage: www.elsevier.com/locate/iot Research article Optimising secure and sustainable smart home configurations Daniel Muñoz-Heredia ∗, Ángel Jesús Varela-Vaca , Diana Borrego , María Teresa Gómez-López i3US and University of Seville, Dept. of Computer Languages and Systems, IDEA Research Group, Seville, Spain1 A R T I C L E I N F O Keywords: Smart homes Multi-objective problems Security Usability Connectivity Sustainability A B S T R A C T As the adoption of smart devices accelerates rapidly in smart homes worldwide, the variety of available devices on the market is also diversifying. This creates a challenge for users, who must choose devices that best meet their needs, and for system designers, who must ensure these devices integrate efficiently within a connected ecosystem. In response to this challenge, the solution presented in this work provides a metamodel that gathers the smart home features, including attributes related to security, usability, connectivity and sustainability. These features are used to create personalised configurations of smart homes that meet user requirements. This is achieved through the creation of multi-objective optimisation problems focused on improving: security, to ensure network and personal data protection; usability, to facilitate the easy management of the environment; connectivity, to maintain seamless interaction between both existing and future devices; and sustainability, which assesses the environmental impact and energy efficiency of the technological ecosystem. The implementation of the proposal is available and a set of experiments have been developed to evaluate the proposal’s applicability using real devices, being reproducible and replicable. 1. Introduction The rise of smart devices in homes has revolutionised our daily lives, making them more comfortable and productive. By 2030, nearly tens of millions of IoT devices are expected to be interconnected [1]. The inclusion and heterogeneity of new devices connected to each other and the outside world present unprecedented security risks [2]. This is further exacerbated by the abundance of emerging technologies, both in hardware and software features, that facilitate the development of new devices and the connectivity that binds them. As a result, home security depends not solely on physical security mechanisms, but also on tools and techniques that allow us to identify and resolve issues related to external cyber-risks, all from the comfort of our homes. A smart home can be defined as ‘‘the integration of different services within a home by using a common communication system. It assures an economical, secure and comfortable operation of the home and includes a high degree of intelligent functionality and flexibility’’ [3]. However, ensuring that a smart home configuration is interoperable, cost-effective, secure and convenient is not a trivial task [4,5]. Users’ choice and onboarding of devices is one of the main issues affecting the security and sustainability of smart homes. The plethora of models and brands available on the market overwhelms users, making device selection and configuration difficult to obtain secure and sustainable smart homes. Inexperienced users often struggle to identify the most suitable devices for their environment, leading to the acquisition of devices with inadequate security measures [4]. This situation is exacerbated by manufacturers’ lack of uniform security standards, resulting ∗Corresponding author. E-mail addresses: [email protected] (D. Muñoz-Heredia), [email protected] (Á.J. Varela-Vaca), [email protected] (D. Borrego), [email protected] (M.T. Gómez-López). 1IDEA Research Group: https://www.idea.us.es, i3US: https://i3us.us.es/ https://doi.org/10.1016/j.iot.2025.101637 Received 20 February 2025; Received in revised form 10 April 2025; Accepted 1 May 2025 Internet of Things 32 (2025) 101637 Available online 20 May 2025 2542-6605/© 2025 The Authors. Published by Elsevier B.V. This is an open access article under the CC BY-NC license ( http://creativecommons.org/licenses/by-nc/4.0/ ). D. Muñoz-Heredia et al. in many devices not receiving necessary firmware updates or security patches to protect against emerging threats, exposing users to constant cyber-attacks. Furthermore, closed ecosystems from certain manufacturers limit interoperability [5], forcing users to rely on a single provider and complicating the implementation of integrated and effective security solutions across different models of manufacturers. Cybercriminals can exploit these vulnerabilities to access personal information, remotely control devices, and compromise the physical security of the home. On the other hand, the choice of devices also impacts the sustainability of smart homes [5]. The production and use of energyinefficient devices can contribute to resource waste and increase the carbon footprint of a smart home. Therefore, it is crucial to consider the energy efficiency, and durability of the devices and their batteries when making purchasing decisions. Last but not least, when configuring a smart home [6], it is necessary to integrate all devices into a single platform to create rules and communication between them. Selecting equipment from different manufacturers can lead to integration issues, where some devices do not communicate effectively with each other, making it necessary to add new devices to act as communication intermediaries within the smart home. Although much research has been conducted on various aspects of smart homes, such as energy management, security issues and the sustainability of IoT devices, current approaches tend to focus on specific components or isolated objectives rather than holistic solutions. For example, several studies emphasise the optimisation of energy consumption and the integration of renewable energy sources in smart homes through demand response systems and distributed energy resources [7–9]. Others address security challenges by proposing cryptographic techniques and risk mitigation strategies to safeguard IoT networks [2,10]. Similarly, sustainability has been explored through frameworks to reduce e-waste and improve the longevity of devices [11,12]. Additionally, resilienceoriented metrics, such as those discussed in [13], are a promising direction to improve the robustness of smart home systems, especially in sensitive environments such as nursing homes or assisted living facilities. They could help evaluate the system’s ability to cope with disruptions or device failures. Furthermore, the perspective of a smart home as a two-tier system - composed of infrastructure (devices, network, environment) and substance (human actors) - as described in [14], could guide future adaptations of the optimisation model to better align with human-centric requirements. However, these approaches often lack a holistic perspective that simultaneously considers user preferences, device security, connectivity, energy efficiency and long-term sustainability in the selection and configuration of IoT devices for smart homes. Due to the heterogeneity between device models, manufacturer-provided solutions, and communication methods, it is necessary to define a domain model that gathers the features of those components in a smart home. This is crucial for later assistance in the decision-making in the configuration of sustainable, secure, connected and usable smart homes. Rather than introducing a new modelling paradigm, this work proposes a domain-specific model adapted to the smart home context, allowing integration of security-related metadata and sustainability criteria for device selection and optimisation. This paper seeks to fill this gap by proposing an integrated decision-making framework that aligns with these multiple objectives, addressing a critical need for smart home optimisation. The contributions of the paper are three-fold: (1) the definition of a domain-specific model as a formal representation of the smart home context, which builds on existing domain modelling principles and incorporates aspects of security, sustainability, connectivity and usability; (2) an optimisation-based approach to support the user’s decision-making for the smart home configuration process; and, (3) to develop a toolkit that enables to populate the domain model with real devices and reasoning capabilities to assist user’s decision-making configuration for the smart home. The rest of the paper is organised as follows. Section 2 presents the overall framework of the proposed solution, detailing the process flow from the user-defined requirements to the generation and visualisation of the optimised smart home configuration. Section 3 introduces the extended metamodel, based on CARMEN framework, which integrates key attributes for security, connectivity and sustainability, providing a comprehensive approach to representing IoT devices. Section 4 details the multiobjective optimisation strategy by describing how the optimisation problems are modelled using variables, constraints and the objective function. Section 5 presents the architecture of the proposed solution, structured into functional blocks. Section 6 describes the experiments conducted to validate the solution, analysing the solver performance across various scenarios and datasets. Section 7 discusses the threats to the study’s validity by considering both external and internal factors. Section 8 presents the related work in the literature related to the problem addressed. Finally, Section 9 presents conclusions and discusses potential future improvements. 2. ALBA-Assistant framework ALBA-Assistant has been defined as a framework to produce optimised secure and sustainable configurations for Smart Home according to user requirements. Fig. 1 shows the workflow followed by ALBA-Assistant. First of all, ALBA-Assistant enables users to define objectives and device requirements. Regarding devices, the user can define the requirements in terms of the number of devices, and the number of devices by type further existing devices can be included as a must for the configuration. Internally, ALBA-Assistant incorporates up-to-date information about vulnerabilities and weaknesses associated with the selected devices, enhancing the security assessment and decision-making process. Concerning objectives, the user can establish the levels of importance of security, connectivity, sustainability, and usability. For instance, maximise the level of connectivity and usability. ALBA-Assistant takes the information about devices and objectives and automatically generates a Constraint Optimisation Problem (COP). ALBA-Assistant incorporates the use of single (one objective) or multi-objective Constraint Optimisation Problems (COP) that, are based on user-defined preferences. ALBA-Assistant integrates a Constraint Programming Engine that executes the COP to obtain an optimal configuration according to a single or multiple objectives. Finally, the optimal configuration is reported to the user to make a final decision-making. The ALBA-Assistant approach integrates a metamodel to represent the devices, components and features of Smart Home. Internet of Things 32 (2025) 101637 2 D. Muñoz-Heredia et al. Fig. 1. Alba-assistant process overview. Fig. 2. ALBA-Assistant metamodel. 3. ALBA-Assistant metamodel The heterogeneity of devices that potentially can be involved in a smart home makes it difficult to address comprehensive solutions where the features of all devices can be represented and managed. Domain modelling has long been used to formally capture the structure and behaviour of complex systems, particularly in the fields of cognitive engineering and service systems [15,16]. For this reason, we propose a solution to automate the acquisition of relevant information from external repositories about these devices and the generation of possible configurations to assist the user in making decisions regarding security, usability, connectivity, and sustainability. ALBA-Assistant extends the CARMEN metamodel [17] and its complement, Onto-CARMEN [18], with specific attributes for supporting the classes Capability, Connectivity, and Vulnerability, not included in the original CARMEN metamodel. These attributes are necessary to define in greater detail the devices modelled in the smart home and to unify the information about sustainability and security, following ENISA [19] recommendations and IoT security guidelines from OWASP [20]. The resulting metamodel enables the modelling of multi-objective problems to find the best configurations according to user requirements and ensure alignment with best security practices. The proposed metamodel is shown in Fig. 2, where the classes and attributes previously included in CARMEN are depicted in blue, while the remaining content represents the advancements introduced in our proposal. Internet of Things 32 (2025) 101637 3 D. Muñoz-Heredia et al. Table 1 CVSS v3.x ratings. Severity Base score range None 0.0 Low 0.1–3.9 Medium 4.0–6.9 High 7.0–8.9 Critical 9.0–10.0 Essentially, a smart home comprises a set of interconnected intelligent devices, each belonging to a specific type, which determines its functionality (e.g., router, smartphone, smart TV, etc.). Therefore, a valid configuration would consist of a series of devices of different types that meet the user’s needs. Primarily, ALBA-Assistant addresses user needs in terms of security, usability, connectivity, and sustainability. To achieve this, it complements the information stored by the user for a specific device with information obtained from external sources. The following subsections detail the most important properties of the devices included in the metamodel to be able to configure a smart home as secure, sustainable, connected and usable. 3.1. Device security To understand security risks when selecting devices for a smart home, it is crucial to become familiar with key concepts, such as vulnerabilities documented in Common Vulnerabilities and Exposures (CVE) [21] and their impact assessed using the Common Vulnerability Scoring System (CVSS) [22]. Additionally, understanding the Common Weakness Enumeration (CWE) [23] is essential, as it provides a catalogue of software weaknesses that can lead to vulnerabilities. These standardised concepts (CVE, CVSS, and CWE) allow for identifying, quantifying, and understanding the nature of vulnerabilities, providing a solid basis for making informed decisions about the security of IoT devices in a smart home environment. To assess the impact of a vulnerability, we use the Common Vulnerability Scoring System (CVSS). This system measures severity on a scale from 0 to 10, where 0 represents the lowest severity and 10 the highest. For the purpose of our study, we specifically focus on CVSS version 3.x to evaluate vulnerability impact. This version categorises severity into distinct ranges, as detailed in Table 1. The CVSS base score is calculated using the following formula: 𝐶𝑉 𝑆𝑆 = 1 − [(1 − 𝐶𝑜𝑛𝑓𝑖𝑑𝑒𝑛𝑡𝑖𝑎𝑙𝑖𝑡𝑦)×(1−𝐼𝑛𝑡𝑒𝑔𝑟𝑖𝑡𝑦)×(1−𝐴𝑣𝑎𝑖𝑙𝑎𝑏𝑖𝑙𝑖𝑡𝑦)] (1) While CVE provides a reference framework for identifying and managing specific vulnerabilities, the Common Weakness Enumeration (CWE) focuses on the weaknesses that can lead to vulnerabilities. CWE is a community-developed list of software weaknesses that can contribute to vulnerabilities if not properly addressed. CWE serves as a complementary resource to CVE by offering a taxonomy of common weaknesses that affect the security of systems. It provides a systematic way to categorise and describe these weaknesses, helping developers and security professionals understand and address the root causes of vulnerabilities. The purpose of CWE is to enhance the security posture of systems by identifying and mitigating weaknesses before they can be exploited. By understanding the common weaknesses associated with vulnerabilities, organisations can take proactive measures to prevent these issues from arising in the first place. Within the ALBA-Assistant environment, the security of a device is determined by the potential vulnerabilities detected for it and modelled using the class Vulnerability, as well as by the weaknesses associated with them, identified by their CWE, as represented in the Weakness class. This class includes key attributes such as id, a CVE identifier for each vulnerability; description, which explains the vulnerability characteristics, and; baseScore, which provides a numerical value assessing the severity based on CVSS. Furthermore, baseSeverity offers a categorised assessment of the risk, while the vector details how the vulnerability can be exploited. The version attribute refers to the specific CVE version used for classification, such as CVE 2.0, 3.0, etc., which helps track standard changes over time. Finally, exploitability quantifies how easy it is for an attacker to exploit the vulnerability. Together, these elements provide a comprehensive framework for evaluating and mitigating vulnerabilities and improving the security of IoT devices in a smart home environment. Due to the rapid development of threats in the security field, it is important to have methods that guarantee that the vulnerability information is kept up to date. In the presented data model, each device has two time-based attributes: lastUpdate and updateFreq. The lastUpdate attribute records the date and time of the most recent update of device vulnerability data, which is essential to ensure that risk analysis and evaluation are based on a defined time point. Without regular review, the device’s risk profile may not accurately reflect current threats, leading to poor smart home configurations. Meanwhile, the updateFreq attribute sets how often a new vulnerability scan should be carried out, for example, measured in seconds. A regular interval encourages scheduled reviews, ensuring that any new vulnerability or change in the severity of an existing one is detected in time. Moreover, since it is an adjustable value, it can be modified according to the criticality of the device and the environment in which it operates, striking a balance between constant updating and system load. Overall, these attributes add a time element to the management of device security, enabling a proactive response to new threats and ensuring that risk assessments remain as accurate and current as possible. Additionally, the firmware attribute has been added to specify the firmware used by the device, along with its specific version. Internet of Things 32 (2025) 101637 4 D. Muñoz-Heredia et al. This detail not only supports effective version management, but also helps in the proactive identification of potential vulnerabilities existing in a firmware release. Moreover, the specific information about the version also serves as an indirect indicator of the device’s update cycle, revealing when it was last maintained. In a simplified manner, each device possesses an attribute named impact, which is the updated result of the weighted average of the CVSS scores of the vulnerabilities related to the device, giving greater weight as the severity of the vulnerabilities increases. This data will be used by the system to assist in decision-making and by the user to determine the overall security impact associated with a particular device. The data captured within the Vulnerability class is derived directly from the NIST external API based on the device model and brand, ensuring accuracy and relevance. By leveraging the functionality of this API, we can access a comprehensive database of known vulnerabilities and the associated weaknesses that may have contributed to them. Consequently, the insights gained from this analysis enable users to make informed decisions regarding device selection, prioritising those with fewer and less severe vulnerabilities while addressing any critical weaknesses, ultimately enhancing the overall security of smart home environments. 3.2. Device sustainability Sustainability in smart devices is a fundamental aspect of designing environmentally responsible technological solutions, particularly in the context of connected homes. Today, it is essential to consider, not only the functionality and convenience these devices provide but also their environmental impact throughout their life cycle. To address this, our proposal models sustainability through two core components, the PowerSupply class and the capability attribute within the Device class. The capability attribute is used to assess a device’s computational capacity, which can vary from Class 0 (minimal computational power) to Unconstrained (maximum computational power), following the classification provided by ENISA [24]. Devices with higher computational capacity typically consume more energy, making them less sustainable. In contrast, devices with lower computational capacity are considered more sustainable due to their reduced energy consumption, contributing to a lower overall environmental impact. Complementing this, the Power-Supply class evaluates the sustainability of the device’s energy source based on key attributes. The source attribute identifies the type of power supply (e.g., plug, battery, or cell) offering insights into how the device is powered, which, in turn, affects both performance and environmental footprint. The rechargeable attribute indicates whether the power source can be recharged for repeated use. Rechargeable sources are typically more sustainable, as they reduce waste and the reliance on disposable alternatives. The renewable attribute indicates whether the energy source is obtained from renewable methods, such as solar or wind power. The use of renewable energy sources is increasingly important in reducing the carbon footprint of devices and promoting environmental sustainability. Finally, the disposable attribute assesses whether the power source can be safely discarded after use. This consideration ensures that the ecological implications of disposal are taken into account, as proper disposal methods can mitigate harmful environmental effects. Additionally, a sustainability attribute is included in the Device class, calculated based on the weighted sum of two components, adjusted to a defined scale (from 0 to 10). The first component is derived from the device’s computational capacity (capability), where numerical values are assigned to each of the available categories. The second component involves processing the various values of the attributes within the Power-Supply class for the device in question. To achieve this, it is necessary to convert each of the possible values presented in the categorical attributes that comprise this class into numerical values. The sustainability score combines two aspects: power supply attributes (75%) and computational capability (25%). This weighting reflects the assumption that the type of energy source has a more immediate impact on the environmental sustainability of IoT devices, particularly in terms of energy efficiency and waste generation. Although computational capability also contributes to energy consumption, its effect is more indirect. Given the lack of standardised sustainability metrics for IoT, this distribution was adopted to emphasise the dominant role of power usage in sustainability assessment. However, these percentages have been established, although can be adjusted according to user preferences. Alba-Assistant will use this metric to recommend devices that are both efficient and environmentally responsible, helping users prioritise sustainability alongside performance. Furthermore, users can directly use this value to assess the environmental impact of their devices and make informed choices that align with their sustainability goals. By integrating sustainability considerations into device selection, we can contribute to a more responsible and eco-friendly approach in smart home environments. 3.3. Device connectivity To determine a device’s connectivity capacity, it is sufficient to know the number of different types of connectivity technologies available for that specific device, such as Wi-Fi, Bluetooth, Zigbee, or cellular networks. Each of these technologies offers unique ranges, speeds, and energy consumption profiles, contributing to the device’s overall ability to connect to other systems, networks, or devices. Evaluating the availability of these connectivity options allows for an assessment of how versatile the device will be when interacting with its environment. In the ALBA-Assistant environment, the device’s connectivity capabilities are further modelled in the Connectivity class, which is linked to the Device class and consists of two key attributes, environment and wireless. The environment attribute specifies the Internet of Things 32 (2025) 101637 5 D. Muñoz-Heredia et al. type of connectivity technology employed by the device, allowing for a clear categorisation of its connectivity capabilities. The wireless attribute indicates whether the device operates with wireless connectivity methods or relies on traditional wired connections, providing insight into its flexibility in different settings. These connectivity attributes are crucial for understanding how well a device can communicate within its ecosystem. By assessing these factors, users can make informed choices about device selection, ensuring that their smart home technologies can seamlessly interact and enhance the overall functionality of the connected environment. Prioritising devices with diverse and efficient connectivity options enables greater adaptability and responsiveness in smart home setups. 3.4. Device usability Usability is a key factor in determining how easily a user can manage a device within a smart home environment. Devices that are compatible with a large number of applications are generally considered more user-friendly, as they offer greater flexibility and choice. A device that can be managed through multiple applications provides users with the freedom to select the app that best suits their preferences or existing ecosystem, enhancing the overall user experience. On the other hand, devices compatible with only a limited number of applications, or worse, just a single proprietary app, may feel more restrictive to users. These devices can force users to adopt unfamiliar interfaces or limit their ability to integrate the device with other smart home systems, forcing the necessity of installing several apps. This lack of flexibility can diminish overall usability, especially for users already managing a variety of smart home devices from different brands. In addition, devices that do not require any management application achieve the highest usability rating, as they can be controlled directly without additional software. These devices offer a streamlined user experience by eliminating the need for downloading, installing, and navigating external applications, making them ideal for users seeking simplicity in their smart home setups (e.g., routers). To effectively address these usability concerns, the Application class, which is linked to the Device class in the metamodel, serves as the fundamental pillar of usability assessment for devices. It contains a single key attribute, name, which represents the name of the compatible application that allows users to manage and configure the device. Our proposal, ALBA-Assistant, is built upon these classes to optimise the usability of devices in smart home environments, ensuring they are accessible and easy to manage through a wide range of applications. This approach not only enhances the user experience but also facilitates the seamless integration of various technologies within a connected ecosystem. 4. Alba-assistant multi-objective optimiser The elements included in the metamodel of Fig. 2 let us model the aspects of security, sustainability, connectivity and usability. These elements could create a smart home configuration according to user preferences. Since four different objectives can be taken into account, ALBA-Assistant uses multi-objective problems for modelling the optimal configuration, balancing the trade-off between various objectives to ascertain the best possible solution according to the user preferences. The steps followed in the proposal are: (1) creating and updating the dataset devices; (2) defining user requirements; (3) modelling multi-objective problems; and (4) finding the best configuration for solving the multi-objective optimisation problem. 4.1. Creation/updating of the device dataset ALBA-Assistant selects the most appropriate devices extracted from a dataset whose elements follow the explained metamodel in Fig. 2. Users can specify their own dataset of devices, or use a dataset provided in the proposal detailed in Section 6. Additionally, new devices can be added to an existing dataset repository. For each device, the user must specify the attributes included in the metamodel, that are model, category, capability, impact and sustainability. Furthermore, the applications that can be used for its management are represented by instantiating Application class, the various connectivity technologies it offers by including Connectivity instances, and the energy sources it can utilise using PowerSupply class. Based on this information, the values of impact and sustainability are automatically calculated and stored as attributes of the device. The information included as part of the devices can be used to optimise the configuration. 4.2. User device requirements: Devices and objective preferences The selection of devices will depend on the objectives the user attaches to the different targets, the requirements and the available devices that could be potentially included in the configuration. The user must indicate two aspects of a smart home configuration, (1) the number of desired devices of each type and (2) the level of importance he/she places on the 4 objectives. Related to the number of devices of each type, the user could indicate, for example, the creation of a smart home with 3 cameras, 2 motion sensors, and 1 thermostat. In addition, the user can also specify certain devices (brand and model) that he/she already owns and wants to be integrated into the home configuration. Regarding the 4 objectives involved in the multi-objective problem, for which the user must establish the level of importance he/she assigns to each one, we propose the assignment of importance represented by the weight (𝑤𝑖), taking as possible values: VERY HIGH, HIGH, MEDIUM, LOW or NONE. Each qualitative weight will be transformed into a quantitative value associated with Internet of Things 32 (2025) 101637 6 D. Muñoz-Heredia et al. each of the four objectives. This information is used to fine-tune the user’s preferences by optimising these factors in the proposed configuration. Min(𝑊security ⋅𝑆security −𝑊connectivity ⋅𝑆connectivity −𝑊sustainability ⋅𝑆sustainability +𝑊usability ⋅𝑆usability)(2) where 𝑊𝑖 represents the quantitative representation of the normalised weight. Each 𝑊𝑖 is associated with each objective to optimise according to user preferences (security, connectivity, sustainability and usability). This normalisation ensures that each factor contributes in a balanced way to the objective function. •𝑊𝑖=𝑤𝑖/T, where 𝑊𝑖 = 0.25 if 𝑇 = 0, which means that no preferences have been selected, giving the same importance to the four objectives, 25% to each one. •𝑤𝑖: can take the values {NONE → 0, LOW → 0.25, MEDIUM → 0.50, HIGH → 0.75, VERYHIGH → 1}. •T: total number of different objectives to optimise according to the user’s preferences, between 0 and 4. 𝑆𝑖 represents the normalised score (ranging from 0 to 1) for each optimisation objective. These scores indicate how well each objective is met. To ensure consistency in the multi-objective optimisation function, all objectives are treated as minimisation objectives. For objectives such as connectivity and sustainability, which are naturally maximised (better outcomes are associated with higher scores), their signs are reversed. Thus, minimising the negative of these scores is equivalent to maximising their original values, which aligns them with the overall minimisation approach. For modelling the variables 𝑆security, 𝑆connectivity, 𝑆sustainability and 𝑆usability, we must include a set of constants and variables in the Optimisation Problem, and the constraints that relate them. The modelling of the Constraint Optimisation Problem (COP) is detailed in the following section. 4.3. Modelling the constraint optimisation problem To create a model that optimises the device configuration based on the selected criteria, it is necessary to define the constants, variables and constraints that make up the optimisation model. The constants represent available devices and their features according to the dataset and the user device requirements; the variables reflect the devices incorporated in the optimal configuration found; while the constraints ensure that the final configuration meets the preferences and constraints specified by the user. In a multiobjective optimisation problem, defining a series of constraints that guide the solver towards feasible solutions is crucial, while balancing the different objectives to be optimised. These fundamental elements for modelling the optimisation problem are detailed below. 4.3.1. Constants for representing device dataset and user device requirements Part of the COP is built with information extracted from external datasets that include the candidate devices that can participate in the optimal configuration of the smart home. Such information is modelled in the COP as matrices and arrays of constant values. Constant definitions. 𝐶𝑊 𝐸[𝑖][𝑗] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠},∀𝑗∈ {1..𝑛𝐶𝑊 𝐸} 𝐴𝑃 𝑃 [𝑖][𝑗] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠},∀𝑗∈ {1..𝑛𝐴𝑝𝑝} 𝐶𝐴𝑇 𝐸𝐺𝑂𝑅𝑌 [𝑖][𝑗] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠},∀𝑗∈ {1..𝑛𝐶𝑎𝑡𝑒𝑔𝑜𝑟𝑦} 𝐶𝑂𝑁𝑁_𝐶𝐴𝑃 [𝑖][𝑗] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠},∀𝑗∈ {1..𝑛𝐶𝑜𝑛𝑛𝑒𝑐𝑡𝑖𝑣𝑖𝑡𝑦} 𝐼𝑀𝑃 𝐴𝐶𝑇 [𝑖] ∈ R∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠} 𝑆𝑈𝑆𝑇 𝐴𝐼𝑁𝐴𝐵𝐼𝐿𝐼𝑇 𝑌 [𝑖] ∈ R∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠} 𝑈𝑆𝐸𝑅_𝑅𝐸𝑄𝑈𝐸𝑆𝑇 [𝑖] ∈ Z≥0∀𝑖∈ {1..𝑛𝐶𝑎𝑡𝑒𝑔𝑜𝑟𝑦} Legend: •𝐶𝑊 𝐸 is a Boolean matrix of constants where 𝐶𝑊 𝐸[𝑖][𝑗] is set to 1 if the device 𝑖 has associated the CWE 𝑗, and 0 otherwise. •𝐴𝑃 𝑃 is a Boolean matrix of constants where 𝐴𝑃 𝑃 [𝑖][𝑗] is set to 1 if the device 𝑖 is compatible with application 𝑗, and 0 otherwise. •𝐶𝐴𝑇 𝐸𝐺𝑂𝑅𝑌 is a Boolean matrix of constants where 𝐶𝐴𝑇 𝐸𝐺𝑂𝑅𝑌 [𝑖][𝑗] is set to 1 if device 𝑖 belongs to category 𝑗, and 0 otherwise. •𝐶𝑂𝑁𝑁_𝐶𝐴𝑃 is a Boolean matrix of constants where 𝐶𝑂𝑁𝑁_𝐶𝐴𝑃 [𝑖][𝑗] is set to 1 if the device 𝑖 has the capability to use communication technology 𝑗, and 0 otherwise. •𝐼𝑀𝑃 𝐴𝐶𝑇 is a float array of constants where 𝐼𝑀𝑃 𝐴𝐶𝑇 [𝑖] represents the value of impact for device 𝑖. •𝑆𝑈𝑆𝑇 𝐴𝐼𝑁𝐴𝐵𝐼𝐿𝐼𝑇 𝑌 is a float array of constants where 𝑆𝑈𝑆𝑇 𝐴𝐼𝑁𝐴𝐵𝐼𝐿𝐼𝑇 𝑌 [𝑖] is the value of sustainability for device 𝑖. •𝑈𝑆𝐸𝑅_𝑅𝐸𝑄𝑈𝐸𝑆𝑇 is an integer array of constants where 𝑈𝑆𝐸𝑅_𝑅𝐸𝑄𝑈𝐸𝑆𝑇 [𝑖] is the number of user device requirements belonging to the category 𝑖. Internet of Things 32 (2025) 101637 7 D. Muñoz-Heredia et al. 4.3.2. Variables of the optimisation problem The optimisation problem is based on the selection of a set of devices for optimising the mentioned optimisation function. The selection of the devices is modelled through a set of Boolean variables that indicates the inclusion (1) or exclusion (0) of a specific device in the solution. Main variable definition. 𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠} Legend: •𝑑𝑒𝑣𝑖𝑐𝑒𝑠 is an array of Boolean variables where 𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖] is set to 1 if the device i is included in the smart home, and 0 otherwise. In addition, additional variables (such as app or cwe) are needed to facilitate the calculation of certain aspects, such as the number of applications needed or the CWE present in the selected devices. These variables help to evaluate the optimisation factors. Auxiliary variable definitions. 𝑐𝑤𝑒[𝑖] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐶𝑊 𝐸} 𝑎𝑝𝑝[𝑖] ∈ {0,1} ∀𝑖∈ {1..𝑛𝐴𝑝𝑝} Legend: •𝑐𝑤𝑒 is an array of Boolean variables where 𝑐𝑤𝑒[𝑗] is set to 1 if there is a device 𝑖 included in the smart home where 𝐶𝑊 𝐸[𝑖][𝑗] is equal to 1. •𝑎𝑝𝑝 is an array of Boolean variables where 𝑎𝑝𝑝[𝑗] is set to 1 if the value of 𝐴𝑃 𝑃 [𝑖][𝑗] is equal to 1 and the corresponding application 𝑗 is required to control the device 𝑖, and device 𝑖 is included in the smart home. 4.3.3. Constraints for describing the user device requirements This type of constraint is essential for defining the boundaries of the search space for the solver, preventing configurations that are irrelevant to the user. This constraint ensures that, although the solution space may be vast, only those solutions that respect the requested quantity and types of devices are considered. In this optimisation problem, these constraints control the number and type of devices included in the solution. That is when the user specifies which types of devices he/she wishes to include and how many of each, these cardinality constraints ensure that the final solution meets those expectations. Constraints for limiting the number of devices. 𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠 ∑ 𝑖=1 𝐶𝐴𝑇 𝐸𝐺𝑂𝑅𝑌 [𝑖][𝑗]⋅𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖] = 𝑈𝑆𝐸𝑅_𝑅𝐸𝑄𝑈𝐸𝑆𝑇 [𝑗] ∀𝑗∈ {1..𝑛𝐶𝑎𝑡𝑒𝑔𝑜𝑟𝑦} (3) Explanation: 𝐶𝐴𝑇 𝐸𝐺𝑂𝑅𝑌 [𝑖][𝑗]⋅𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖] is 1 if device 𝑖 is included in the configuration (𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖] = 1) and belongs to category 𝑗 (i.e. if 𝐶𝐴𝑇 𝐸𝐺𝑂𝑅𝑌 [𝑖][𝑗] = 1). The sum of all devices selected in category 𝑗 must be equal to 𝑈𝑆𝐸𝑅_𝑅𝐸𝑄𝑈𝐸𝑆𝑇 [𝑗], which is the constant that represents the number of devices the user wants for category 𝑗. To illustrate the development of the multi-objective optimisation problem, this paper presents a running example that demonstrates step by step how the key elements of a COP are applied in the context of smart home configuration. This example provides a detailed overview of each stage of the process, from the initial problem definition to ascertain the optimal solution that satisfies the user requirements. In this first step, as shown in Fig. 3, the user requirements are specified to configure the smart home, including the number and types of devices to be integrated. During this process, device selection is modelled using a set of Boolean variables that represent the status of each device in the final configuration, indicating its inclusion (1) or exclusion (0). This approach formalises the decision-making process and ensures that the selections strictly adhere to the defined requirements. Another element of the model is the CATEGORY matrix, which links each device to its corresponding category. In this case, the user requirements include two devices from category CAT-4 and one device from category CAT-5. The matrix not only highlights this relationship between devices and categories, but also confirms that the solver selection (Devices 1, 3 and 4) satisfies the requirements in terms of both the number and type of devices needed. 4.3.4. Channelling constraints Channelling constraints are used to describe the implications derived from the inclusion of a device. That inclusion implies including the features of their attributes in the solution. This type of constraint is used to model security and usability. Related to security, the inclusion of a device can imply adding a CWE, then a weakness. However, the same CWE could also be included by another device. Internet of Things 32 (2025) 101637 8 D. Muñoz-Heredia et al. Fig. 3. User Requirements. Constraints for describing the CWEs involved in the solution. 𝑐𝑤𝑒[𝑗]≥ 𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠 ∑ 𝑖=1 (𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖]⋅𝐶𝑊 𝐸[𝑖][𝑗])∀𝑗∈ {1..𝑛𝐶𝑊 𝐸}(4) Explanation: This constraint forces the inclusion in the solution of each CWE associated with each of the devices selected for the configuration. That is, for each 𝑗 (i.e., for each CWE), if at least one of the selected devices is associated with CWE 𝑗, then 𝑐𝑤𝑒[𝑗] must be 1. Selection of required applications. 𝑛𝐴𝑝𝑝 ∑ 𝑗=1 (𝐴𝑃 𝑃 [𝑖][𝑗]⋅𝑎𝑝𝑝[𝑗])≥𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖] ∀𝑖∈ {1..𝑛𝐷𝑒𝑣𝑖𝑐𝑒𝑠}(5) Explanation: The constraint ensures that for each selected device (𝑑𝑒𝑣𝑖𝑐𝑒𝑠[𝑖]=1), at least one of the applications that can control it must be enabled. 4.3.5. Objective-based constraints Multi-objective optimisation problems involve multiple metrics or criteria that need to be optimised simultaneously, such as security, usability, connectivity or sustainability. These metrics are linked to numeric variables that represent different qualitative or quantitative aspects of the elements involved in the solution. From a theoretical standpoint, objective-based constraints create a correspondence between these metrics and the solver’s decisions. For instance, the selection of a device may be tied to a security or sustainability value, and the constraints ensure that the solver’s decisions regarding the selection of devices are reflected in the associated objectives. The key lies in modelling these metrics through cost functions that the solver can efficiently handle. These constraints also allow the solver to aggregate the individual contributions of each component to the overall objective, facilitating the optimisation of these goals. The four key factors and how they are realised in our case are detailed below. 4.4. Optimising security Given that a final configuration comprises numerous devices of varying types, it is crucial to identify the security-related factors that require optimisation. The minimisation function includes 𝑆𝑠𝑒𝑐𝑢𝑟𝑖𝑡𝑦 for representing the score of security. Since Alba-Assistant Internet of Things 32 (2025) 101637 9 D. Muñoz-Heredia et al. Fig. 9. Execution times for security-based objective. 6.2. Experimental setting For Experiments 1 through 5, the number of devices for each category (e.g., router, repeater, smartphone) required in the final solution was specified randomly according to the total number of devices studied in each experiment. Additionally, the weight assigned to the objective to be optimised was set to the maximum value (VERY HIGH), while the weight for the other objectives was set to null (NONE). In the multi-objective experimentation, the weight value for each of the key criteria (security, usability, connectivity, and sustainability) was randomly selected from the possible values: NONE, LOW, MEDIUM, HIGH, and VERY HIGH. Additionally, each of these experiments has been conducted in different contexts, with the number of devices available in the tool varying from the complete dataset (425 devices) to a subset comprising only 125 devices. This approach facilitates the evaluation of the solver’s efficiency, both under current conditions and in projected scenarios, in terms of the time it takes to resolve the satisfiability problem. In Experiment 6, which corresponds to the second phase of the experimentation, no specific mandatory devices were included in the solution request at the start. The weights for the key optimisation criteria were assigned as follows: security: VERY HIGH, usability: LOW, connectivity: MEDIUM, and sustainability: HIGH. As the experimentation progressed, mandatory devices were gradually added until the final stage, where all devices included in the solution were specified by the user. The experiments were executed on a machine with an Intel(R) Core(TM) i7-10510U CPU (1.80 GHz up to 4.9 GHz, 8MB cache, 4 cores), an NVIDIA GTX 1080 graphics card, 16 GB 2666MHz DDR4-SDRAM RAM, and 500 GB NVMe PCIe SSD storage. The operating system was Ubuntu 22.04.1 LTS, and the programming environment was Python version 3.13.2. 6.3. Experiment 1: Minimising impact and CWE set Minimising the associated impact and the CWE set aims to obtain a solution that has the lowest possible sum of the impacts associated with the selected devices, minimising the number of distinct CWEs in the resulting set. Results of Experiment 1. Fig. 9 shows the results of Experiment 1, with data grouped according to the size of the dataset used by the tool as the search space for the solution. The dataset sizes range from the complete dataset (425 devices) to subsets containing 325, 225 and 125 devices. The vertical axis in the figure represents the time (in seconds) required by the solver to solve the COP problem, while the horizontal axis indicates the number of devices the user requests to include in the solution, and consequently, the number of devices the solver returns. This figure design will be used throughout Experiments 1 to 5. The general trend indicates that as the number of requested devices increases, the response time tends to increase. This is evident across all three datasets. Furthermore, it is evident that although each dataset differs by only 100 devices, the increase in the solver’s execution time is not linear. Instead, as the dataset grows larger, the time required to obtain a solution accelerates progressively, which may be attributed to the exponential growth in the number of possible configurations the solver must evaluate. To obtain a configuration of 20 devices that minimises overall impact and the diversity of CWEs, the average processing time was 0.484 s for a dataset of 425 devices, 0.335 s for 325 devices, 0.246 s for 225 devices, and 0.175 s for 125 devices. The security objective registers the highest resolution times among all optimisation goals (security, sustainability, usability and connectivity), with only the multi-objective optimisation showing longer resolution times. This is because security is the only objective that requires the optimisation of multiple individual factors (impact and CWEs). Consequently, the problem is formulated with an extensive set of variables, boolean variables for each CWE in the database and numerical variables that represent the impact of each device. Internet of Things 32 (2025) 101637 16 D. Muñoz-Heredia et al. Fig. 10. Execution times for sustainability-based objective. 6.4. Experiment 2: Maximising the sustainability The second key point focuses on the sustainability objective. The calculation of a device’s sustainability is based on the characteristics of the type of power source it uses to operate and its computational capabilities. Each computational capability is assigned a numerical value that decreases as its capabilities increase, with unconstrained devices rated at 2, class 2 devices at 5, class 1 devices at 7, and class 0 devices at 10, such that devices with lower computational capacity are considered more sustainable. On the other hand, the power source used by the device is evaluated in three equally weighted subcategories: whether the source is rechargeable, renewable, or disposable. If an attribute is deemed affirmative, it is assigned a value of 10; otherwise, it is assigned a value of 2. The final sustainability score of a device is a normalisation from 0 to 10, where 75% of the weight corresponds to the attributes related to the power source used, and 25% to the value associated with computational capability. Considering the sustainability values of the devices in the dataset, the application aims to identify the combination of devices that meets the user’s needs while maximising the sum of the sustainability values. Results of Experiment 2. The results of Experiment 2, shown in Fig. 10, are similar to those of Experiment 1, presented in Fig. 9. An upward trend in response times is again observed as the user requests a greater number of devices for the same dataset, and an accelerating upward trend is observed as the number of devices in the dataset increases. However, this problem is primarily composed of numerical variables that represent the sustainability value of each device, which results in reduced problem setup and resolution times compared to the previous experiment. On average, obtaining a configuration of 20 devices requires 0.0756 s when using a dataset of 425 devices, 0.0547 s with a dataset of 325 devices, 0.0457 s with a dataset of 225 devices, and 0.0368 s with a dataset of 125 devices. 6.5. Experiment 3: Maximising the number of connectivity technologies Each device is associated with a list of connectivity technologies, which allow the device to connect and communicate with other devices within the smart home. This optimisation identifies the combination of devices according to the user’s request that maximises the number of connectivity technologies present in the resulting smart home. Results of Experiment 3. For a set of devices that maximises the number of connectivity technologies available, the results shown in Fig. 11 present the same trends in execution times as those observed in previous experiments. With connectivity as the objective, the configuration times tend to be slightly higher than that observed when optimising impact or sustainability. This is because instead of creating a single numerical variable per device, the system generates a boolean variable for each connectivity technology that a device has, which greatly expands the number of combinations. In this case, obtaining a configuration of 20 devices requires an average of 0.202 s for a dataset of 425 devices, 0.158 s for a dataset of 325 devices, 0.113 s for a dataset of 225 devices, and 0.077 s for a dataset of 125 devices. Internet of Things 32 (2025) 101637 17 D. Muñoz-Heredia et al. Fig. 11. Execution times for connectivity-based objective. Fig. 12. Execution times for usability-based objective. 6.6. Experiment 4: Minimising the number of necessary applications On certain occasions, a device may require the installation of an application for its configuration or management. Therefore, each device is associated with a list of compatible applications that allow the aforementioned functions. Since the user seeks to control the maximum number of devices with the minimum number of distinct applications, the optimisation presented in this example aims to identify the set of devices that meets the user’s needs while minimising the number of distinct applications required. Results of Experiment 4. During the experimentation related to minimising the number of applications required for the proper functioning of the resulting configuration, it can be observed in Fig. 12. For this objective, execution times are highly dependent on both the number of unique applications found in the database and the implication constraints that associate each device with its possible valid applications. The results for selecting 20 devices are detailed as follows: the average response time is 0.157 s for a dataset with 425 devices, 0.130 s for a dataset with 325 devices, 0.105 s for a dataset with 225 devices and 0.0670 s for a dataset with 125 devices. 6.7. Experiment 5: Minimising the multi-objective function Building upon the concepts demonstrated in previous examples, the current example illustrates the results of optimising a combination of objectives in a multi-objective optimisation solver. In this case, specific weights are assigned to each objective Internet of Things 32 (2025) 101637 18 D. Muñoz-Heredia et al. Fig. 13. Execution times for the entirety of objectives. (SECURITY, SUSTAINABILITY, CONNECTIVITY, and USABILITY). These weights range from NONE (0) to VERY-HIGH (1), indicating the relative importance of each objective in the optimisation process. In this approach, rather than focusing on a single optimisation criterion, multiple objectives are considered simultaneously. Each objective is assigned a weight that reflects its relative importance or priority. This allows for a more nuanced evaluation of the outcomes, as the optimisation process balances and integrates the different objectives according to their assigned weights. The results presented in this example highlight how varying the weights for each objective affects the overall optimisation outcome. This enables the user to achieve a smart home configuration that best aligns with their specific needs and preferences, providing a tailored solution that balances multiple goals effectively. Results of Experiment 5. In Fig. 13, the results of the multi-objective optimisation can be observed. Since the calculations applied within the optimisation problem depend on the involved objectives, the highest response times for the same dataset and number of requested devices correspond to measurements where all objectives (SECURITY, SUSTAINABILITY, CONNECTIVITY, and USABILITY) have been considered. Conversely, the lowest response times for each situation correspond to problems where only a single objective has been optimised, which explains the large whiskers present in each box. Since in the most complex case, all the logic corresponding to the optimisation of all objectives is applied, the overall response times increase compared to those observed in previous experiments, where only a single objective was optimised. The average response time for 20 requested devices is 0.643 s for a dataset with 425 devices, 0.481 s for a dataset with 325 devices, 0.326 s for a dataset with 225 devices and 0.224 s for a dataset with 125 devices. In the scenario where the user requests the maximum number of devices possible for each dataset, the following data is obtained: the average response time for requesting 125 devices from a dataset of the same size is 0.315 s, for requesting 225 devices from its corresponding dataset is 0.515 s, for requesting 325 devices from a dataset of 325 devices is 0.734 s and for requesting 425 devices from the largest dataset is 1.068 s. Once again, it is evident that the average response times tend to increase at an accelerated rate as the number of available devices in the dataset grows and increases more gradually as the user requests more devices for the same dataset size. 6.8. Experiment 6: Solutions for partial configurations The experiment focusses on identifying how the imposition of specific devices by the user affects the values of the objectives of the final solution provided by the system in a multi-objective optimisation problem. The experiment begins with the user requesting 15 devices from the system without specifying any devices that must be included in the solution. As the experiment progresses, the user requests new solutions from the system while increasing the number of devices that must appear in the final solution, with these devices explicitly specified by the user. This situation places the multi-objective optimisation problem in a partial configuration where the system must forcibly include the devices specified by the client and determine which additional devices from the dataset will form a better overall configuration, which will then be returned to the user. Results of Experiment 6. For this experiment, the prioritisation of the objectives to be optimised is as follows: the primary objective is SECURITY, assigned a weight of VERY-HIGH, followed by SUSTAINABILITY with a weight of HIGH. Next is CONNECTIVITY, with a MEDIUM weight, and lastly, USABILITY, which has the lowest weight, LOW. Internet of Things 32 (2025) 101637 19 D. Muñoz-Heredia et al. As illustrated in Table 2, for a type of device, if the user does not determine any specific mandatory device, the system can find a final configuration with an average impact value of 0 and an empty CWE set. This means the solver achieves a perfect score for the SECURITY objective by minimising both the average impact value and the size of the CWE set to the greatest extent possible. Following the prioritisation of objectives, the variable related to the SUSTAINABILITY objective reaches a mean value of 5.35. This is followed by the CONNECTIVITY objective, with a final configuration incorporating 9 different connectivity technologies. Finally, for the USABILITY objective, only one application is required to manage the devices in the final configuration. As the user imposes mandatory devices that must appear in the solution, the values determining the satisfaction of the objectives tend to deteriorate. This results in an increase in the average impact value and the size of the CWE set for the SECURITY objective, a decrease in the sustainability value for the SUSTAINABILITY objective, a lower number of available connectivity technologies in the final configuration for the CONNECTIVITY objective, and a greater number of applications required to manage the devices for the USABILITY objective. This demonstrates that the most optimised configurations concerning the user’s objectives are those with the fewest devices mandated by the user. This decline in the overall optimisation capacity of the system reaches its peak when the user specifies all the devices that must be included in the final configuration. In this case, the system does not operate to identify which devices should be added to the partial configuration to optimise the values related to the objectives, as it is a complete configuration imposed by the user. When the user specifies all 15 devices in the configuration, the following results are observed: an average impact value of 3.561 (+3.561), a CWE set consisting of 20 (+20) elements, a sustainability value of 4.95 (−0.40), a total of 7 (−2) different connectivity technologies, and 3 (+2) applications required for managing the environment. Although the inclusion of mandatory devices inevitably constrains the optimisation process and leads to less favourable results, this behaviour opens the door to interesting mitigation strategies. Future versions of ALBA-Assistant could include compensatory selection mechanisms that prioritise devices with particularly high scores in the most affected criteria. For example, if the user imposes a device with known security vulnerabilities, the system could favour additional devices with high-security scores, thereby minimising the overall risk. This would help maintain the quality of the solution even under strict user constraints. 6.9. Conclusions of the experimentation The results obtained from the performed experiments demonstrate the capacity of ALBA-Assistant to find configurations comprising multiple devices that meet user requirements, whether by optimising a single objective or a combination of objectives, with the additional capability to specify the relative importance of each objective. Moreover, the tool is proficient in generating comprehensive configurations from partial configurations explicitly defined by the user, highlighting its adaptability to pre-defined conditions. In particular, the presented solution demonstrates a high level of capability in generating configurations that include approximately 20 devices. This is attributed to the consistently observed response times, which are under 2 s across all datasets considered. This value has been deliberately chosen because it approximates the average number of devices typically found in a smart home, as reported by Deloitte (2023), which cites an average of 21 devices per smart home [27]. This alignment with real-world data reinforces the relevance and practical applicability of ALBA-Assistant in common usage scenarios. Additionally, it has been demonstrated that ALBA-Assistant possesses the capacity to dynamically adapt to variations in user preferences and objectives. Despite changes in optimisation criteria, the system’s performance remains stable, showing no significant degradation in response times. This level of adaptability is further complemented by the tool’s ability to generate new, optimised configurations as users incorporate additional devices into their smart homes. This underscores ALBA-Assistant’s robustness and flexibility in managing the increasing complexity and variability of smart home environments, providing solutions that not only meet current requirements but also adjust to future developments in the user’s environment. 7. Threats to validity Assessment of threats to validity is critical to ensure the quality of a study. According to Wohlin et al. [28], two main aspects of validity have been taken into account: •External validity. The data from the experiments are realistic, as the primary unit of information used by the application is devices, and these have been created by adapting the data provided by official manufacturers to the fields of the data model used by the application. If the user decides to add a new device, he/she must consult and transform the official manufacturer data into a format accepted by the application. Additionally, it is important to highlight the use of reputable APIs to obtain the additional information necessary for fully creating the device within the application, such as the NIST API, which provides potential vulnerability data for a device. Since such APIs are not under our control, they may present inconsistencies. Therefore, shortly, we intend to use multiple sources for the same purpose to prevent such issues. To ensure that the experiments are reproducible and valid, all API requests and responses generated during the experimentation phase, including those seeking both partial and complete configurations, are available in the various repositories linked to this project. Internet of Things 32 (2025) 101637 20 D. Muñoz-Heredia et al. Table 2 Variation in the results due to the imposition of devices.. No. of devices imposed Average impact No. of different CWE Apps required Available connectivity technologies Average sustainability 0 0.0 0 Amazon Alexa Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 5.35 1 0.605 10 Amazon Alexa Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Ethernet, 4G 5.35 2 1.106 16 Amazon Alexa Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 5.35 3 1.106 16 Amazon Alexa Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 5.35 4 1.713 16 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 5 1.713 16 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 6 2.120 17 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 7 2.120 17 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 8 2.520 17 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 9 2.520 17 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 10 2.520 17 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 11 2.950 18 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 12 2.950 18 Amazon Alexa, Wyze Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Z-Wave, Ethernet, 4G 4.95 13 2.950 18 Amazon Alexa, Wyze, Mi Home Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Ethernet, 4G 4.95 14 2.950 18 Amazon Alexa, Wyze, Mi Home Wi-Fi, 3G, Dedicated Wiring, ZigBee, 5G, Bluetooth, Ethernet, 4G 4.95 15 3.561 20 Amazon Alexa, Wyze, Mi Home Wi-Fi, 3G, ZigBee, 5G, Bluetooth, Ethernet, 4G 4.95 •Internal validity. Given that COP (Constraint Optimisation Problems) are highly sensitive to problem complexity, the application allows the level of difficulty to be adjusted, either by simplifying or complicating the problem to be solved. This is achieved by reducing or increasing the number of devices stored in the dataset, or by optimising individual objectives instead of addressing all objectives simultaneously. Users must bear in mind that an ideal solution would consider all devices available on the market. However, this would significantly increase the complexity of the problem, making it more challenging to find an optimal solution. By limiting the number of devices or optimising only certain objectives, the calculation becomes simpler, but the precision of the final solution is also diminished. As such, users must be aware that their solution is limited by the available devices within the application. Furthermore, users must keep devices already present in the application up-to-date, as factors such as compatible applications may change over time. If real-time updates are not performed, the validity of the proposed solutions could be compromised. Internet of Things 32 (2025) 101637 21 D. Muñoz-Heredia et al. 8. Related work Research on optimising safe and sustainable configurations in smart homes encompasses a variety of approaches and areas of study. In this section, relevant work is presented and divided into two main subsections: Configuration Optimisation and Sustainability in Smart Homes. The first one focuses on studies that address the selection and management of IoT devices considering security, sustainability, and energy efficiency aspects, in order to optimally configure smart homes. The second subsection reviews research that analyses the sustainability of IoT devices, including their energy efficiency, energy sources, recycling, and extended lifetime, thus ensuring reduced environmental impact and long-term integration in smart homes. 8.1. Configuration optimisation Contribution [10] introduces the concept of Sustainable and Secure Internet of Things (SS-IoT), which highlights the need to integrate lightweight cryptographic techniques to ensure the security and sustainability of IoT devices in urban environments. This work is relevant to our study as it also advocates the implementation of IoT devices that are not only secure but also ecologically responsible. In addition, [2] presents a comprehensive review of vulnerabilities, risks, and countermeasures in smart homes. They focus on the security challenges that arise from the increasing number of connected devices in smart homes and the need to address these challenges through robust device selection and management. This study emphasises the importance of managing security risks, aligning with the goals of our work in optimising configurations that enhance both security and user safety. Aligned with the focus of this paper on prioritising security and sustainability in the selection of smart home devices, the contribution in [29] evaluates different modelling approaches to optimise the intelligence of smart homes, including how to manage and assess these systems to meet user expectations. Although their work centres more on system modelling, it reinforces the need for effective device management strategies. Furthermore, [30] provides a comprehensive review of green IoT, discussing the importance of energy efficiency and sustainability in IoT device management. Its conclusions highlight the need to select devices that minimise energy consumption and promote sustainable practices, which is essential for optimising smart home configurations. Aligned with the focus of this paper on prioritising security and sustainability in the selection of smart home devices, the paper [31] on the Internet of Things for sustainability explores perspectives on privacy, cybersecurity, and future trends, providing a framework for understanding how IoT devices can be selected and managed in ways that are secure and sustainable. These studies highlight the importance of careful device selection based on safety, sustainability, and energy efficiency criteria, aligning with the objective of this work to develop a framework for optimised decision-making in smart home configuration. 8.2. Sustainability in smart homes The sustainability of IoT devices is crucial for their long-term integration in smart homes. The contribution in [12] examines the challenges of longevity and solutions for IoT devices, proposing a vendor agility approach to improve the lifespan and security of devices. Their research directly addresses the issues of planned obsolescence and the need to maintain the security and functionality of IoT devices over time. This is particularly relevant to our study, which also seeks solutions that extend the lifetime and improve the sustainability of devices. [32] provides a review of recent solutions and challenges in energy efficiency and security in IoT networks. This work provides a comprehensive overview of current strategies to improve the energy efficiency of IoT devices, which is essential for the sustainability of smart homes. The relevance of this study lies in its focus on selecting devices that optimise both security and energy efficiency. Moreover, [33] provides a thorough review of the evolution of technology in smart homes, focusing on self-powered and sustainable sensors. This article is particularly useful for our analysis of how to achieve long-term sustainability in smart homes by integrating energy-harvesting systems, which contribute to both energy efficiency and extended device lifetime. The contribution in [34] proposes a federated reinforcement learning approach to manage the energy consumption of smart homes. By using distributed energy resources and optimising appliance usage, their model contributes to energy efficiency in multihome environments, which is essential for sustainable smart home systems. This approach aligns with the goals of our research by highlighting the importance of energy management in achieving sustainability. Additionally, [35] discusses the role of multi-objective optimisation in energy management for smart homes. Their approach is especially relevant to our study, as it provides insights into reducing operational costs and emissions through better energy management strategies in smart homes. In terms of understanding how to implement security solutions that do not compromise sustainability, the work in [36] discusses sustainable security for the Internet of Things, providing a framework for selecting devices that are both secure and sustainable. Moreover, [7] discusses the impact of distributed energy resources (DER) in smart homes, suggesting that integrating DERs not only helps optimise the energy management of smart homes but also transforms passive consumers into active participants in energy markets. This work provides a unique perspective on how smart homes can contribute to community-based energy management, making it a valuable contribution to the sustainability discussion. [9] explores the potential and challenges of smart homes, focusing on integrating renewable energy sources and proper energy management schemes to reduce overall grid demand. The paper also discusses how smart homes can contribute to modern power grids, making them an essential study for understanding the sustainability of IoT devices in energy management. Internet of Things 32 (2025) 101637 22 D. Muñoz-Heredia et al. Contribution in [8] presents a hybrid algorithm for energy management in IoT-enabled smart homes under price-based demand response programs. Their model demonstrates how energy costs can be minimised while maintaining comfort and operational efficiency, which aligns with our goal of achieving sustainable configurations in smart homes. Additionally, [11] discusses an innovative approach to waste management and energy efficiency in smart homes using IoT technologies. Their research proposes a sustainable pattern for managing waste and optimising energy consumption, which is crucial for achieving sustainability goals in the context of smart homes. These papers underscore the critical need to balance security, energy management, and sustainability in the selection of IoT devices for smart homes, providing both theoretical frameworks and practical approaches that support our research approach. 8.3. Related foundations from adjacent domains Beyond the specific literature on smart home optimisation and sustainability, several adjacent research domains provide relevant insights that inform the foundations of our work. First, the problem of selecting appropriate hardware and software components has been studied in enterprise and organisational contexts [37–39]. Although these approaches do not focus on domestic environments, they share the challenge of selecting compatible and efficient components across multiple criteria, a concept that also underpins our decision-making framework. Second, multi-criteria optimisation has a long tradition in operational research and engineering, providing a strong methodological foundation for our approach. These principles have guided the formulation of our constraint-based model and its extension to multiple factors. Third, our domain model is inspired by systems engineering practices, where domain-specific metamodels are commonly used to abstract and formalise knowledge about complex systems. Our adaptation to the smart home domain builds on this foundation and aligns with previous efforts in modelling service-oriented systems [16]. Finally, while privacy is not a core focus of our current framework, it is an essential dimension of IoT systems, particularly in mobile and healthcare applications. [40] highlights the importance of integrating security, privacy and resilience, which we identify as valuable future directions, particularly in contexts involving sensitive user data and federated environments. Unfortunately, the mentioned proposal does not include other features related to sustainability. 9. Conclusions and future work ALBA-Assistant is presented as a solution that enables users with no knowledge of IoT devices to create a smart home configuration according to his/her requirements, thanks to a controlled multi-objective optimisation solver using constraint optimisation problems. The proposal extends an existing metamodel to include properties related to security, sustainability, connectivity and usability. The applicability of the proposal is demonstrated through a set of experiments. In addition to the returned devices, the solution provides a range of general values related to the optimised objectives, allowing the user to compare and adjust the obtained solutions. The solution is powered with real devices that can be combined in the optimal solution. This requires considerable effort to regularly fill in and review the information, ensuring that all devices are accurate and reflect the most recent options on the market. Furthermore, it is important to emphasise how the use of constraint optimisation problems (COP) lets us model complex problems that are solved in a feasible time. These problems tend to be complex due to the large number of variables and constraints that must be considered simultaneously. Efficiently solving a COP requires robust algorithms and often involves a trade-off between processing time and result accuracy. Moreover, as the scale of devices and constraints increases, COPs become progressively more challenging, as evidenced by the experiments conducted, which negatively affect both the computational performance and the quality of the solutions obtained. As future work, we propose to adapt our solution to federated environments where IoT interactions and subsequent analysis need to be performed to preserve privacy aspects. In addition, we consider the integration of engineering resilience as a promising direction to improve the robustness of smart home systems, such as nursing homes or assisted living facilities. CRediT authorship contribution statement Daniel Muñoz-Heredia: Writing – review & editing, Writing – original draft, Software, Investigation, Data curation. Ángel Jesús Varela-Vaca: Writing – review & editing, Validation, Project administration, Investigation, Formal analysis, Conceptualization. Diana Borrego: Validation, Supervision, Resources, Investigation, Conceptualization. María Teresa Gómez-López: Writing – review & editing, Validation, Project administration, Methodology, Formal analysis, Conceptualization. Material Following open science’s good practices, our software artifacts are available in the latest version publicly in Zenodo repository https://doi.org/10.5281/zenodo.13753241. Internet of Things 32 (2025) 101637 23 D. Muñoz-Heredia et al. Declaration of competing interest The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper. Acknowledgements This research was supported by the grants KOSMOS-US PID2024-155363OB-C42, AETHER-US PID2020-112540RB-C44 and ALBA-US TED2021-130355B-C32 funded by MICIU/AEI/10.13039/501100011033 and by the ‘‘European Union NextGenerationEU/PRTR’’. Data availability No data was used for the research described in the article. References [1] M. Serror, S. Hack, M. Henze, M. Schuba, K. Wehrle, Challenges and opportunities in securing the industrial internet of things, IEEE Trans. Ind. Inform. 17 (5) (2021) 2985–2996, http://dx.doi.org/10.1109/TII.2020.3023507. [2] B. Hammi, S. Zeadally, R. Khatoun, J. Nebhen, Survey on smart homes: Vulnerabilities, risks, and countermeasures, Comput. Secur. 117 (2022) 102677. [3] R. Lutolf, Smart home concept and the integration of energy meters into a home based system, in: Seventh International Conference on Metering Apparatus and Tariffs for Electricity Supply 1992, IET, 1992, pp. 277–278. [4] C. Wang, L. Cassidy, W. He, T.J. Pierson, D. Kotz, Challenges and opportunities in onboarding smart-home devices, in: Proceedings of the 25th International Workshop on Mobile Computing Systems and Applications, HOTMOBILE ’24, Association for Computing Machinery, New York, NY, USA, 2024, pp. 60–65, http://dx.doi.org/10.1145/3638550.3641137, URL https://doi.org/10.1145/3638550.3641137. [5] D. Campos, L. Martins, J. Mota, D. Tavares, J. Pereira, M. Oliveira, D. Boaventura, D. Correa, E. Ferreira, G. Pinto, N. Seixas, A. Maia, M. Romário, E. Passos, F. Durao, G.B. Figueiredo, M. Peixoto, T. Januario, C. Prazeres, I. Machado, E. Almeida, Designing, implementing, and testing AI-oriented smart home applications: Challenges and best practices, in: A. Ampatzoglou, J. Pérez, B. Buhnova, V. Lenarduzzi, C.C. Venters, U. Zdun, K. Drira, L. Rebelo, D. Di Pompeo, M. Tucci, E.Y. Nakagawa, E. Navarro (Eds.), Software Architecture. ECSA 2024 Tracks and Workshops, Springer Nature Switzerland, Cham, 2024, pp. 83–99. [6] N.N.W. Tay, J. Botzheim, N. Kubota, Weighted constraint satisfaction for smart home automation and optimization, Adv. Artif. Intell. 2016 (1) (2016) 2959508, https://doi.org/10.1155/2016/2959508, arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1155/2016/2959508, URL https://onlinelibrary.wiley. com/doi/abs/10.1155/2016/2959508. [7] A. Saif, S.K. Khadem, M.F. Conlon, B. Norton, Impact of distributed energy resources in smart homes and community-based electricity market, IEEE Trans. Ind. Appl. 59 (1) (2023) 59–69, http://dx.doi.org/10.1109/TIA.2022.3202756. [8] G. Hafeez, Z. Wadud, I.U. Khan, I. Khan, Z. Shafiq, M. Usman, M.U.A. Khan, Efficient energy management of IoT-enabled smart homes under price-based demand response program in smart grid, Sensors 20 (11) (2020). [9] R. El-Azab, Smart homes: potentials and challenges, Clean Energy 5 (2) (2021) 302–315, http://dx.doi.org/10.1093/ce/zkab010. [10] M. Badawy, Sustainable secure internet of things (SS-IoT), in: 2023 1st International Conference on Advanced Innovations in Smart Cities, ICAISC, 2023, pp. 1–6, http://dx.doi.org/10.1109/ICAISC56366.2023.10085280. [11] M. Ehsanifar, F. Dekamini, C. Spulbar, R. Birau, M. Khazaei, I.C. Bărbăcioru, A sustainable pattern of waste management and energy efficiency in smart homes using the internet of things (IoT), Sustainability 15 (6) (2023). [12] C.J. Bradley, Sustainable Security: Exploring Longevity Challenges and Solutions for IoT (Ph.D. thesis), Carleton University, 2023, URL https://repository. library.carleton.ca/files/np193b263. (Accessed 16 July 2024). [13] W. Zhang, C. van Luttervelt, Toward a resilient manufacturing system, CIRP Ann 60 (1) (2011) 469–472, http://dx.doi.org/10.1016/j.cirp.2011.03.041. [14] W. Zhang, J. Wang, Y. Lin, Integrated design and operation management for enterprise systems, Enterp. Inf. Syst. 13 (2019) 424–429, http://dx.doi.org/ 10.1080/17517575.2019.1597169. [15] Y. Lin, C. Zhang, Towards a novel interface design framework: Function-behavior-state paradigm, Int. J. Hum.-Comput. Stud. 61 (2004) 259–297, http://dx.doi.org/10.1016/j.ijhcs.2003.11.008. [16] J. Wang, H. Wang, J. Ding, K. Furuta, T. Kanno, W. Ip, W. Zhang, On domain modelling of the service system with its application to enterprise information systems, Enterp. Inf. Syst. 10 (2013) 1–16, http://dx.doi.org/10.1080/17517575.2013.810784. [17] Á.J. Varela-Vaca, D.G. Rosado, L.E. Sánchez, M.T. Gómez-López, R.M. Gasca, E. Fernández-Medina, CARMEN: A framework for the verification and diagnosis of the specification of security requirements in cyber-physical systems, Comput. Ind. 132 (2021) 103524, http://dx.doi.org/10.1016/j.compind.2021.103524. [18] C. Blanco, D.G. Rosado, Á.J. Varela-Vaca, M.T. Gómez-López, E. Fernández-Medina, Onto-CARMEN: Ontology-driven approach for cyber–physical system security requirements meta-modelling and reasoning, Internet Things 24 (2023) http://dx.doi.org/10.1016/j.iot.2023.100989. [19] European Network and Information Security Agency, European Network and Information Security Agency, 2012, http://www.enisa.europa.eu/activities/riskmanagement/current-risk/business-process-integration. [20] OWASP Internet of Things Project, 2024, Available from OWASP. URL https://wiki.owasp.org/index.php/OWASP_Internet_of_Things_Project#tab=Main. (Accessed 20 December 2024). [21] MITRE, Common Vulnerabilities and Exposures, 2024, URL http://cve.mitre.org/. (Accessed 24 December 2024). [22] Common Vulnerability Scoring System SIG, 2024, Available from FIRST. URL https://www.first.org/cvss/. (Accessed 23 December 2024). [23] Common Weakness Enumeration, 2024, URL http://cwe.mitre.org/index.html. (Accessed 18 December 2024). [24] C. Lévy-Bencheton, E. Darra, G. Tétu, G. Dufay, M. Alatta, Security and Resilience of Smart Home Environments, ENISA, 2015, URL https://www.enisa. europa.eu/publications/security-resilience-good-practices. [25] Google Team, Google OR-Tools: Open Source Optimization Tools, 2025, URL https://developers.google.com/optimization. (Accessed 13 February 2025). [26] E.C.P. Neto, S. Dadkhah, R. Ferreira, A. Zohourian, R. Lu, A.A. Ghorbani, CICIoT2023: A real-time dataset and benchmark for large-scale attacks in IoT environments, J. Sensors (2023). [27] J. Arbanas, P. H.Silverglate, S. Hupfer, J. Loucks, P. Raman, M. Steinhart, Consumers embrace connected devices and virtual experiences for the long term, 2023, URL https://www2.deloitte.com/us/en/insights/industry/telecommunications/connectivity-mobile-trends-survey/2023/connectivitymobile-trends-survey-full-report.html. Internet of Things 32 (2025) 101637 24 D. Muñoz-Heredia et al. [28] C. Wohlin, P. Runeson, M. Höst, M.C. Ohlsson, B. Regnell, Experimentation in Software Engineering, Springer, 2012, http://dx.doi.org/10.1007/978-3642-29044-2. [29] D. Wu, W. Feng, T. Li, Z. Yang, Evaluating the intelligence capability of smart homes: A conceptual modeling approach, Data Knowl. Eng. 148 (2023) 102218. [30] M. Alsharif, A. Jahid, A. Kelechi, R. Kannadasan, Green IoT: A review and future research directions, Symmetry 15 (3) (2023) 757, http://dx.doi.org/10. 3390/sym15030757. [31] A. Salam, in: A. Salam (Ed.), Internet of Things for Sustainable Community Development, Springer, Cham, 2020, pp. 1–32, http://dx.doi.org/10.1007/9783-030-35291-2_10. [32] M. Mahamat, G. Jaber, A. Bouabdallah, Achieving efficient energy-aware security in IoT networks: a survey of recent solutions and research challenges, Wirel. Netw. 29 (2023) 787–808, http://dx.doi.org/10.1007/s11276-022-03170-y. [33] B. Dong, Q. Shi, Y. Yang, F. Wen, Z. Zhang, C. Lee, Technology evolution from self-powered sensors to AIoT enabled smart homes, Nano Energy 79 (2021) 105414. [34] S. Lee, D.-H. Choi, Federated reinforcement learning for energy management of multiple smart homes with distributed energy resources, IEEE Trans. Ind. Inform. 18 (1) (2022) 488–497, http://dx.doi.org/10.1109/TII.2020.3035451. [35] S.A. Mansouri, A. Ahmarinejad, E. Nematbakhsh, M.S. Javadi, A.R. Jordehi, J.P. Catalão, Energy management in microgrids including smart homes: A multi-objective approach, Sustain. Cities Soc. 69 (2021) 102852. [36] M. De Donno, et al., Sustainable security for internet of things, in: 2019 International Conference on Smart Applications, Communications and Networking (SmartNets), 2019, pp. 1–4, http://dx.doi.org/10.1109/SmartNets48225.2019.9069776. [37] I. Fantozzi, J. Olhager, C. Johnsson, M. Schiraldi, Guiding organizations in the digital era: Tools and metrics for success, Int. J. Eng. Bus. Manag. 17 (2025) http://dx.doi.org/10.1177/18479790241312804. [38] A. Kumar, R. Dewan, W.S. Al-Dayyeni, B. Bhushan, J. Giri, S.M. Islam, A. Elaraby, Wireless body area network: Architecture and security mechanism for healthcare using internet of things, Int. J. Eng. Bus. Manag. 17 (2025) http://dx.doi.org/10.1177/18479790251315317, URL https://doi.org/10.1177/ 18479790251315317. [39] X. Liu, W. Zhang, R. Radhakrishnan, Y. Tu, Manufacturing perspective of enterprise application integration: The state of the art review, Int. J. Prod. Res. 46 (2008) 4567–4596, http://dx.doi.org/10.1080/00207540701263325. [40] W. Lin, M. Xu, J. He, W. Zhang, Privacy, security and resilience in mobile healthcare applications, Enterp. Inf. Syst. 17 (2021) 1–15, http://dx.doi.org/ 10.1080/17517575.2021.1939896. Internet of Things 32 (2025) 101637 25