...
首页> 外文期刊>Computer networks >Towards more practical software-based attestation
【24h】

Towards more practical software-based attestation

机译:寻求更实用的基于软件的认证

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

Software-based attestation promises to enable the integrity verification of untrusted devices without requiring any particular hardware. However, existing proposals rely on strong assumptions that hinder their deployment and might even weaken their security. One of such assumptions is that using the maximum known network round-trip time to define the attestation timeout allows all honest devices to reply in time. While this is normally true in controlled environments, it is generally false in real deployments and especially so in a scenario like the Internet of Things where numerous devices communicate over an intrinsically unreliable wireless medium. Moreover, a larger timeout demands more computations, consuming extra time and energy and restraining the untrusted device from performing its main tasks. In this paper, we review this fundamental and yet overlooked assumption and propose a novel stochastic approach that significantly improves the overall attestation performance. Our experimental evaluation with loT devices communicating over real-world uncontrolled Wi-Fi networks demonstrates the practicality and superior performance of our approach that in comparison with the current state of the art solution reduces the total attestation time and energy consumption around seven times for honest devices and two times for malicious ones, while improving the detection rate of honest devices (8% higher TPR) without compromising security (0% FPR). (C) 2018 Elsevier B.V. All rights reserved.
机译:基于软件的证明有望在不需要任何特定硬件的情况下对不受信任的设备进行完整性验证。但是,现有建议依赖于强大的假设,这些假设会阻碍其部署,甚至可能削弱其安全性。这样的假设之一是,使用最大已知网络往返时间来定义证明超时,将允许所有诚实设备及时回复。尽管这在受控环境中通常是正确的,但在实际部署中通常是错误的,尤其是在诸如物联网之类的场景中,其中许多设备通过本质上不可靠的无线介质进行通信。此外,较大的超时需要更多的计算,从而消耗更多的时间和精力,并限制了不受信任的设备执行其主要任务。在本文中,我们回顾了这个基本但仍被忽略的假设,并提出了一种新颖的随机方法,该方法可以显着提高整体证明性能。我们对通过真实世界不受控制的Wi-Fi网络通信的loT设备进行的实验评估证明,与传统的解决方案相比,该方法的实用性和卓越性能使诚实设备的总认证时间和能耗降低了大约7倍两倍于恶意设备,同时提高了诚实设备的检​​测率(TPR高8%),而又不损害安全性(FPR为0%)。 (C)2018 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号