Secure Association for the Internet of Things

Almog Benin, Sivan Toledo, Eran Tromer

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Existing standards (ZigBee and Bluetooth Low Energy) for networked low-power wireless devices do not support secure association (or pairing) of new devices into a network: their association process is vulnerable to man-in-the-middle attacks. This paper addresses three essential aspects in attaining secure association for such devices.First, we define a user-interface primitive, oblivious comparison, that allows users to approve authentic associations and abort compromised ones. This distills and generalizes several existing approve/abort mechanisms, and moreover we experimentally show that OC can be implemented using very little hardware: one LED and one switch.Second, we provide a new Message Recognition Protocol (MRP) that allows devices associated using oblivious comparison to exchange authenticated messages without the use of publickey cryptography (which exceeds the capabilities of many IoT devices). This protocol improves upon previously proposed MRPs in several respects.Third, we propose a robust definition of security for MRPs that is based on universal composability, and show that our MRP protocol satisfies this definition.

Original languageEnglish
Title of host publicationProceedings - 2015 International Workshop on Secure Internet of Things, SIoT 2015
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages25-34
Number of pages10
ISBN (Electronic)9781467377690
DOIs
StatePublished - 17 Feb 2016
Event4th International Workshop on Secure Internet of Things, SIoT 2015 - Vienna, Austria
Duration: 21 Sep 201525 Sep 2015

Publication series

NameProceedings - 2015 International Workshop on Secure Internet of Things, SIoT 2015

Conference

Conference4th International Workshop on Secure Internet of Things, SIoT 2015
Country/TerritoryAustria
CityVienna
Period21/09/1525/09/15

All Science Journal Classification (ASJC) codes

  • Computer Networks and Communications
  • Hardware and Architecture

Fingerprint

Dive into the research topics of 'Secure Association for the Internet of Things'. Together they form a unique fingerprint.

Cite this