首页> 外文会议>IEEE International Conference on Collaboration and Internet Computing >Securing Mobile Data Collectors by Integrating Software Attestation and Encrypted Data Repositories
【24h】

Securing Mobile Data Collectors by Integrating Software Attestation and Encrypted Data Repositories

机译:通过集成软件认证和加密数据存储库来保护移动数据收集器的安全

获取原文

摘要

Drones are increasingly being used as mobile data collectors for various monitoring services. However, since they may move around in unattended hostile areas with valuable data, they can be the targets of malicious physical/cyber attacks. These attacks may aim at stealing privacy-sensitive data, including secret keys, and eavesdropping on communications between the drones and the ground station. To detect tampered drones, a code attestation technique is required. However, since attestation itself does not guarantee that the data in the drones' memory are not leaked, data collected by the drones must be protected and secret keys for secure communications must not be leaked. In this paper, we present a solution integrating techniques for software-based attestation, data encryption and secret key protection. We propose an attestation technique that fills up free memory spaces with data repositories. Data repositories consist of pseudo-random numbers that are also used to encrypt collected data. We also propose a group attestation scheme to efficiently verify the software integrity of multiple drones. Finally, to prevent secret keys from being leaked, we utilize a technique that converts short secret keys into large look-up tables. This technique prevents attackers from abusing free space in the data memory by filling up the space with the look-up tables. To evaluate the integrated solution, we implemented it on AR.Drone and Raspberry Pi.
机译:无人机越来越多地用作各种监视服务的移动数据收集器。但是,由于它们可能会在无人值守的敌对区域中随身携带有价值的数据,因此它们可能成为恶意物理/网络攻击的目标。这些攻击可能旨在窃取包括密钥在内的对隐私敏感的数据,并窃听无人机与地面站之间的通信。为了检测被篡改的无人机,需要一种代码证明技术。但是,由于证明本身不能保证无人机内存中的数据不会泄漏,因此必须保护无人机收集的数据,并且不得泄漏用于安全通信的秘密密钥。在本文中,我们提出了一种集成技术的解决方案,用于基于软件的证明,数据加密和密钥保护。我们提出了一种证明技术,该技术可以用数据存储库填充可用的内存空间。数据存储库由伪随机数组成,伪随机数也用于加密收集的数据。我们还提出了一种小组证明计划,以有效地验证多架无人机的软件完整性。最后,为了防止秘密密钥被泄露,我们利用一种将短秘密密钥转换为大型查询表的技术。该技术通过使用查找表填充空间来防止攻击者滥用数据存储器中的可用空间。为了评估集成解决方案,我们在AR.Drone和Raspberry Pi上实现了该解决方案。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号