首页> 外文会议>IEEE Systems and Information Engineering Design Symposium >Improving the security of wireless sensor networks in an IoT environmental monitoring system
【24h】

Improving the security of wireless sensor networks in an IoT environmental monitoring system

机译:在物联网环境监控系统中提高无线传感器网络的安全性

获取原文

摘要

The Internet of Things (IoT) has become a popular subject in the technology industry and will soon reach the popularity level of smartphones. With the rapid technological advancements of sensors, Wireless Sensor Networks (WSNs) has become the main technology for IoT. We investigated the security of WSNs in an environmental monitoring system with the goal to improve the overall security. We implemented a Secure Temperature Monitoring System (STMS), which served as our investigational environment. Our results revealed a security flaw found in the bootstrap loader (BSL) password used to protect firmware found in the MSP430 MCU. We demonstrated how the BSL password could be brute forced in a matter of days. Furthermore, to our knowledge we illustrated the first sample of how an attacker can reverse engineer firmware and obtain WSN cryptographic keys. Our sample provides a step-by-step procedure on how to reverse engineer MSP430 firmware. We contributed a solution to improve the BSL password and better protect firmware found in the MSP430 chips. The Secure-BSL software we contributed allows the randomization of the BSL password. Our solution guarantees brute force times in a matter of decades. The impractical brute force time assures the security of firmware and prevents future reverse engineering tactics. In addition, our Secure-BSL software supports two-factor authentication, therefore adding another layer of security. The two-factor authentication feature allows developers to specify a user-defined passphrase to further protect the MSP430 MCU. Our research serves as proof that any security implemented in a WSN environment is broken if an attacker has access to firmware found in sensor devices.
机译:物联网(IoT)已成为技术行业的热门话题,并将很快达到智能手机的普及水平。随着传感器技术的飞速发展,无线传感器网络(WSN)已成为物联网的主要技术。我们在环境监视系统中调查了WSN的安全性,目的是提高整体安全性。我们实施了安全的温度监控系统(STMS),将其用作我们的研究环境。我们的结果表明,用于保护MSP430 MCU中的固件的引导加载程序(BSL)密码中发现了一个安全漏洞。我们演示了如何在几天之内强行使用BSL密码。此外,据我们所知,我们举例说明了攻击者如何逆向工程固件并获得WSN加密密钥的第一个示例。我们的样本提供了有关如何反向工程MSP430固件的分步过程。我们提供了一种解决方案,以改善BSL密码并更好地保护MSP430芯片中的固件。我们提供的Secure-BSL软件允许BSL密码随机化。我们的解决方案可确保数十年的暴力破解时间。不切实际的暴力破解时间确保了固件的安全性,并阻止了未来的逆向工程策略。此外,我们的Secure-BSL软件支持两因素身份验证,因此增加了另一层安全性。两因素身份验证功能使开发人员可以指定用户定义的密码,以进一步保护MSP430 MCU。我们的研究可以证明,如果攻击者可以访问传感器设备中的固件,则WSN环境中实现的任何安全性都将被破坏。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号