Secure Association for the Internet of Things.

IACR Cryptology ePrint Archive(2015)

引用 8|浏览91
暂无评分
摘要
Existing standards (ZigBee and Bluetooth Low Energy) for networked low-power wireless devices do not support secure association (or pairing) of new devices into a network: their association process is vulnerable to man-in-the-middle attacks. This paper addresses three essential aspects in attaining secure association for such devices.First, we define a user-interface primitive, oblivious comparison, that allows users to approve authentic associations and abort compromised ones. This distills and generalizes several existing approve/abort mechanisms, and moreover we experimentally show that OC can be implemented using very little hardware: one LED and one switch.Second, we provide a new Message Recognition Protocol (MRP) that allows devices associated using oblivious comparison to exchange authenticated messages without the use of publickey cryptography (which exceeds the capabilities of many IoT devices). This protocol improves upon previously proposed MRPs in several respects.Third, we propose a robust definition of security for MRPs that is based on universal composability, and show that our MRP protocol satisfies this definition.
更多
查看译文
关键词
secure association,Internet of Things,ZigBee,Bluetooth low energy,networked low-power wireless device,association process,man-in-the-middle attack,user-interface primitive,oblivious comparison,authentic association,LED,message recognition protocol,authenticated message,public key cryptography,IoT device,MRP protocol
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要