首页> 外文会议>European Symposium on Research in Computer Security >Boot Attestation: Secure Remote Reporting with Off-The-Shelf IoT Sensors
【24h】

Boot Attestation: Secure Remote Reporting with Off-The-Shelf IoT Sensors

机译:启动证明:使用搁板的IOT传感器安全远程报告

获取原文

摘要

A major challenge in computer security is about establishing the trustworthiness of remote platforms. Remote attestation is the most common approach to this challenge. It allows a remote platform to measure and report its system state in a secure way to a third party. Unfortunately, existing attestation solutions either provide low security, as they rely on unrealistic assumptions, or are not applicable to commodity low-cost and resource-constrained devices, as they require custom secure hardware extensions that are difficult to adopt across IoT vendors. In this work, we propose a novel remote attestation scheme, named Boot Attestation, that is particularly optimized for low-cost and resource-constrained embedded devices. In Boot Attestation, software integrity measurements are immediately committed to during boot, thus relaxing the traditional requirement for secure storage and reporting. Our scheme is very light on cryptographic requirements and storage, allowing efficient implementations, even on the most low-end IoT platforms available today. We also describe extensions for more flexible management of ownership and third party (public-key) attestation that may be desired in fully Internet-enabled devices. Our scheme is supported by many existing off-the-shelf devices. To this end, we review the hardware protection capabilities for a number of popular device types and present implementation results for two such commercially available platforms.
机译:计算机安全中的一项重大挑战是建立遥控平台的可信度。远程证明是这一挑战最常见的方法。它允许远程平台以安全的方式测量并报告其系统状态。遗憾的是,现有的证明解决方案要么提供低安全性,因为它们依赖于不切实际的假设,或者不适用于商品低成本和资源受限的设备,因为它们需要难以穿越物联网供应商难以采用的定制安全硬件扩展。在这项工作中,我们提出了一种新的远程证明方案,名为Boot Attation,特别针对低成本和资源受限的嵌入式设备特别优化。在启动证明中,软件完整性测量立即在启动期间致电,从而放松传统的安全存储和报告要求。我们的计划非常轻,获取加密需求和存储,允许高效的实现,即使是当今最低限度的IOT平台也是如此。我们还描述了为更灵活的所有权管理和第三方(公共关键)证明的扩展,可能在全面的可互联网的设备中所需的。我们的计划得到了许多现有的现成设备的支持。为此,我们审查了许多流行的设备类型的硬件保护能力,并为两个这样的商业上可用平台提供了实现结果。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号