SEDA: Scalable Embedded Device Attestation

被引:122
作者
Asokan, N. [1 ,2 ]
Brasser, Ferdinand [3 ]
Ibrahim, Ahmad [3 ]
Sadeghi, Ahmad-Reza [3 ]
Schunter, Matthias [4 ]
Tsudik, Gene [5 ]
Wachsmann, Christian [3 ]
机构
[1] Aalto Univ, Espoo, Finland
[2] Univ Helsinki, Helsinki, Finland
[3] Tech Univ Darmstadt, Darmstadt, Germany
[4] Intel Labs, Portland, OR USA
[5] Univ Calif Irvine, Irvine, CA USA
来源
CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2015年
关键词
remote attestation; device swarms; security;
D O I
10.1145/2810103.2813670
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, large numbers of smart interconnected devices provide safety and security critical services for energy grids, industrial control systems, gas and oil search robots, home/office automation, transportation, and critical infrastructure. These devices often operate in swarms - large, dynamic, and self-organizing networks. Software integrity verification of device swarms is necessary to ensure their correct and safe operation as well as to protect them against attacks. However, current device attestation schemes assume a single prover device and do not scale to swarms. We present SEDA, the first attestation scheme for device swarms. We introduce a formal security model for swarm attestation and show security of our approach in this model. We demonstrate two proof-of-concept implementations based on two recent (remote) attestation architectures for embedded systems, including an Intel research platform. We assess performance of SEDA based on these implementations and simulations of large swarms. SEDA can efficiently attest swarms with dynamic and static topologies common in automotive, avionic, industrial control and critical infrastructures settings.
引用
收藏
页码:964 / 975
页数:12
相关论文
共 56 条
  • [1] Ababneh N., 2008, IFIP INT C WIR OPT C
  • [2] [Anonymous], 2011, ACM C COMP COMM SEC
  • [3] [Anonymous], TECHNICAL REPORT
  • [4] [Anonymous], 2008, DISTRIBUTED COMPUTIN
  • [5] [Anonymous], 2005, KEY DISTRIBUTION MEC
  • [6] [Anonymous], 2014, USENIX SEC S
  • [7] [Anonymous], ACM C COMP COMM SEC
  • [8] Arbaugh W., 1997, IEEE S SEC PRIV
  • [9] Asokan N., TECHNICAL REPORT
  • [10] Brasser F., 2015, P 52 ANN DES AUT C