首页> 外文会议>IEEE Systems and Information Engineering Design Symposium >Improving the security of wireless sensor networks in an IoT environmental monitoring system
【24h】

Improving the security of wireless sensor networks in an IoT environmental monitoring system

机译:提高IOT环境监测系统中无线传感器网络的安全性

获取原文

摘要

The Internet of Things (IoT) has become a popular subject in the technology industry and will soon reach the popularity level of smartphones. With the rapid technological advancements of sensors, Wireless Sensor Networks (WSNs) has become the main technology for IoT. We investigated the security of WSNs in an environmental monitoring system with the goal to improve the overall security. We implemented a Secure Temperature Monitoring System (STMS), which served as our investigational environment. Our results revealed a security flaw found in the bootstrap loader (BSL) password used to protect firmware found in the MSP430 MCU. We demonstrated how the BSL password could be brute forced in a matter of days. Furthermore, to our knowledge we illustrated the first sample of how an attacker can reverse engineer firmware and obtain WSN cryptographic keys. Our sample provides a step-by-step procedure on how to reverse engineer MSP430 firmware. We contributed a solution to improve the BSL password and better protect firmware found in the MSP430 chips. The Secure-BSL software we contributed allows the randomization of the BSL password. Our solution guarantees brute force times in a matter of decades. The impractical brute force time assures the security of firmware and prevents future reverse engineering tactics. In addition, our Secure-BSL software supports two-factor authentication, therefore adding another layer of security. The two-factor authentication feature allows developers to specify a user-defined passphrase to further protect the MSP430 MCU. Our research serves as proof that any security implemented in a WSN environment is broken if an attacker has access to firmware found in sensor devices.
机译:事物互联网(物联网)已成为技术行业的受欢迎的主题,并很快将达到智能手机的普及水平。随着传感器的快速技术进步,无线传感器网络(WSNS)已成为IOT的主要技术。我们调查了WSNS在环境监测系统中的安全,目标是提高整体安全性。我们实施了一个安全的温度监测系统(STMS),担任我们的调查环境。我们的结果揭示了在MSP430 MCU中保护的Bootstrap Loader(BSL)密码中发现的安全漏洞。我们展示了在几天内迫使BSL密码如何腐败。此外,对于我们的知识,我们说明了攻击者如何逆转工程固件的第一个样本,并获得WSN加密密钥。我们的示例提供了有关如何反向工程师MSP430固件的逐步过程。我们贡献了一个解决方案来改进BSL密码,更好地保护MSP430芯片中的固件。我们提供的安全BSL软件允许BSL密码随机化。我们的解决方案在几十年内保证了蛮力时间。不切实际的蛮力时间确保固件的安全性,并防止未来的逆向工程策略。此外,我们的安全BSL软件还支持双因素身份验证,从而增加了另一层安全性。双因素身份验证功能允许开发人员指定用户定义的密码,以进一步保护MSP430 MCU。我们的研究是证明如果攻击者可以访问传感器设备中发现的固件,则会损坏WSN环境中实现的任何安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号