首页> 外文期刊>International Journal of Distributed Sensor Networks >How to Authenticate a Device? Formal Authentication Models for M2M Communications Defending against Ghost Compromising Attack
【24h】

How to Authenticate a Device? Formal Authentication Models for M2M Communications Defending against Ghost Compromising Attack

机译:如何验证设备?防御Ghost攻击的M2M通信的正式身份验证模型

获取原文
           

摘要

In Machine-to-Machine (M2M) communications, authentication of a device is of upmost importance for applications of Internet of Things. As traditional authentication schemes always assume the presence of a person, most authentication technologies cannot be applied in machine-centric M2M context. In this paper, we make the first attempt to formally model the authentication in M2M. We first model four attacking adversaries that can formulate all possible attacks in M2M, which are channel eavesdropping attack, credential compromise attack, function compromise attack, and ghost compromise attack. Next, we propose four models to tackle those corresponding adversaries, namely, credential-based model, machine-metrics-based model, reference-based model, and witness-based model. We also illustrate several concrete attacking methods and authentication approaches. We proof the authentication security for all proposed models and compare them for clarity. Our models present soundness and completeness in terms of authentication security, which can guide the design and analysis of concrete authentication protocols. Particularly, we construct a uniform authentication framework for M2M context and point out all possible authentication mechanisms in M2M.
机译:在机器对机器(M2M)的通信中,设备的身份验证对于物联网的应用至关重要。由于传统的身份验证方案始终假定有人在场,因此大多数身份验证技术无法应用于以机器为中心的M2M上下文。在本文中,我们首次尝试对M2M中的身份验证进行正式建模。我们首先对四个攻击对手进行建模,这些对手可以制定M2M中所有可能的攻击,包括通道窃听攻击,凭据泄露攻击,功能泄露攻击和幻影攻击。接下来,我们提出了四个模型来应对那些对应的对手,即基于凭证的模型,基于机器度量的模型,基于引用的模型和基于见证的模型。我们还将说明几种具体的攻击方法和身份验证方法。我们证明了所有提议模型的身份验证安全性,并进行了比较以明确。我们的模型在身份验证安全性方面表现出健全性和完整性,可以指导具体身份验证协议的设计和分析。特别是,我们为M2M上下文构造了一个统一的身份验证框架,并指出了M2M中所有可能的身份验证机制。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号