A Practical Attestation Protocol for Autonomous Embedded Systems

被引:15
作者
Kohnhaeuser, Florian [1 ]
Buscher, Niklas [1 ]
Katzenbeisser, Stefan [1 ]
机构
[1] Tech Univ Darmstadt, Secur Engn, Darmstadt, Germany
来源
2019 4TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P) | 2019年
关键词
remote attestation; collective attestation; embedded systems; mesh networks; autonomous systems;
D O I
10.1109/EuroSP.2019.00028
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the recent advent of the Internet of Things (IoT), embedded devices increasingly operate collaboratively in autonomous networks. A key technique to guard the secure and safe operation of connected embedded devices is remote attestation. It allows a third party, the verifier, to ensure the integrity of a remote device, the prover. Unfortunately, existing attestation protocols are impractical when applied in autonomous networks of embedded systems due to their limited scalability, performance, robustness, and security guarantees. In this work, we propose PASTA, a novel attestation protocol that is particularly suited for autonomous embedded systems. PASTA is the first that (i) enables many low-end prover devices to attest their integrity towards many potentially untrustworthy low-end verifier devices, (ii) is fully decentralized, thus, able to withstand network disruptions and arbitrary device outages, and (iii) is in addition to software attacks capable of detecting physical attacks in a much more robust way than any existing protocol. We implemented our protocol, conducted measurements, and simulated large networks. The results show that PASTA is practical on low-end embedded devices, scales to large networks with millions of devices, and improves robustness by multiple orders of magnitude compared with the best existing protocols.
引用
收藏
页码:263 / 278
页数:16
相关论文
共 46 条
[31]   SALAD: Secure and Lightweight Attestation of Highly Dynamic and Disruptive Networks [J].
Kohnhaeuser, Florian ;
Buescher, Niklas ;
Katzenbeisser, Stefan .
PROCEEDINGS OF THE 2018 ACM ASIA CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS'18), 2018, :329-342
[32]   SCAPI: A Scalable Attestation Protocol to Detect Software and Physical Attacks [J].
Kohnhaeuser, Florian ;
Buescher, Niklas ;
Gabmeyer, Sebastian ;
Katzenbeisser, Stefan .
PROCEEDINGS OF THE 10TH ACM CONFERENCE ON SECURITY AND PRIVACY IN WIRELESS AND MOBILE NETWORKS (WISEC 2017), 2017, :75-86
[33]  
KrebsOnSecurity, 2017, REAP CALM IOT SEC ST
[34]  
Li Y., 2011, ACM CCS
[35]  
Lu S., 2006, EUROCRYPT
[36]  
Maxwell G., 2018, EPRINT ARCH
[37]  
Micali S., 2001, ACM CCS
[38]  
Morris T., 2011, ENCY CRYPTOGRAPHY SE, P1332
[39]  
Przydatek B., 2003, ACM SENSYS
[40]  
Qiao B., 2006, IEEE WIC ACM C INT A