首页> 外文期刊>ACM Transaction on Information and System Security >Distributed Authentication of Program Integrity Verification in Wireless Sensor Networks
【24h】

Distributed Authentication of Program Integrity Verification in Wireless Sensor Networks

机译:无线传感器网络中程序完整性验证的分布式身份验证

获取原文
获取原文并翻译 | 示例

摘要

Security in wireless sensor networks has become important as they are being developed and deployed for an increasing number of applications. The severe resource constraints in each sensor make it very challenging to secure sensor networks. Moreover, sensors are usually deployed in hostile and unattended environments and hence are susceptible to various attacks, including node capture, physical tampering, and manipulation of the sensor program. Park and Shin [2005] proposed a soft tamper-proofing scheme that verifies the integrity of the program in each sensor device, called the program integrity verification (PIV), in which sensors authenticate PIV servers (PIVSs) using centralized and trusted third-party entities, such as authentication servers (ASs). This article presents a distributed authentication protocol of PIVSs (DAPP) without requiring the commonly used ASs. DAPP uses the Blundo scheme [Blundo et al. 1992] for sensors and PIVSs to establish pairwise keys and for PIVSs to authenticate one another. We also present a protocol for PIVSs to cooperatively detect and revoke malicious PIVSs in the network. We implement and evaluate both DAPP and PIV on Mica2 Motes and laptops, showing that DAPP reduces the sensors' communication traffic in the network by more than 90% and the energy consumption on each sensor by up to 85%, as compared to the case of using a centralized AS for authenticating PIVSs. We also analyze the security of DAPP under various attack models, demonstrating its capability in dealing with diverse types of attacks.
机译:随着无线传感器网络正在为越来越多的应用开发和部署,其安全性已变得至关重要。每个传感器中严格的资源限制使得保护传感器网络非常具有挑战性。此外,传感器通常部署在恶劣且无人值守的环境中,因此容易受到各种攻击,包括节点捕获,物理篡改和传感器程序的操纵。 Park and Shin [2005]提出了一种软防篡改方案,该方案可验证每个传感器设备中程序的完整性,称为程序完整性验证(PIV),在该方案中,传感器使用集中且受信任的第三方对PIV服务器(PIVS)进行身份验证。实体,例如身份验证服务器(AS)。本文介绍了不需要常用的AS的PIVS的分布式身份验证协议(DAPP)。 DAPP使用Blundo方案[Blundo等。 [1992年],以便传感器和PIVS建立成对密钥,并使PIVS相互认证。我们还提出了PIVS的协议,以协同检测和撤销网络中的恶意PIVS。我们在Mica2 Motes和笔记本电脑上实现并评估了DAPP和PIV,与之相比,DAPP可以将传感器在网络中的通信流量减少90%以上,每个传感器的能耗最多减少85%。使用集中式AS认证PIVS。我们还分析了DAPP在各种攻击模型下的安全性,展示了DAPP处理各种类型攻击的能力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号