首页> 外文会议>European Symposium on Research in Computer Security >Privacy, Discovery, and Authentication for the Internet of Things
【24h】

Privacy, Discovery, and Authentication for the Internet of Things

机译:物联网的隐私,发现和身份验证

获取原文

摘要

Automatic service discovery is essential to realizing the full potential of the Internet of Things (IoT). While discovery protocols like Multicast DNS, Apple AirDrop, and Bluetooth Low Energy have gained widespread adoption across both IoT and mobile devices, most of these protocols do not offer any form of privacy control for the service, and often leak sensitive information such as service type, device hostname, device owner's identity, and more in the clear. To address the need for better privacy in both the IoT and the mobile landscape, we develop two protocols for private service discovery and private mutual authentication. Our protocols provide private and authentic service advertisements, zero round-trip (0-RTT) mutual authentication, and are provably secure in the Canetti-Krawczyk key-exchange model. In contrast to alternatives, our protocols are lightweight and require minimal modification to existing key-exchange protocols. We integrate our protocols into an existing open-source distributed applications framework, and provide benchmarks on multiple hardware platforms: Intel Edisons, Raspberry Pis, smartphones, laptops, and desktops. Finally, we discuss some privacy limitations of the Apple AirDrop protocol (a peer-to-peer file sharing mechanism) and show how to improve the privacy of Apple AirDrop using our private mutual authentication protocol.
机译:自动服务发现对于实现事物互联网(物联网)的全部潜力至关重要。虽然像多播DNS,Apple AirDrop和Bluetooth低能量等发现协议在IOT和移动设备上都有广泛的采用,但大多数这些协议都不为服务提供任何形式的隐私控制,并且通常泄漏敏感信息,如服务类型,设备主机名,设备所有者的身份,更清晰。为了满足IOT和移动景观中更好的隐私,我们开发了两个私人服务发现和私有相互身份验证的协议。我们的协议提供私人和正宗的服务广告,零往返(0-RTT)相互认证,并在Canetti-Krawczyk密钥交换模型中可被证明是可靠的。与替代方案相比,我们的协议是重量轻的,需要对现有密钥交换协议进行最小的修改。我们将协议集成到现有的开源分布式应用程序框架中,并在多个硬件平台上提供基准:Intel edisons,覆盆子PI,智能手机,笔记本电脑和台式机。最后,我们讨论了Apple AirDrop协议的一些隐私限制(对等文件共享机制),并展示如何使用我们的私有相互认证协议来改进Apple AirDrop的隐私。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号