Formal security analysis of LoRaWAN

被引:69
作者
Eldefrawy, Mohamed [1 ]
Butun, Ismail [1 ]
Pereira, Nuno [2 ]
Gidlund, Mikael [1 ]
机构
[1] Mid Sweden Univ, Informat Syst & Technol, Sundsvall, Sweden
[2] Polytech Porto IPP, Sch Engn DEI ISEP, Porto, Portugal
关键词
LoRaWAN; IoT; Scyther verification;
D O I
10.1016/j.comnet.2018.11.017
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Recent Low Power Wide Area Networks (LPWAN) protocols are receiving increased attention from industry and academia to offer accessibility for Internet of Things (IoT) connected remote sensors and actuators. In this work, we present a formal study of LoRaWAN security, an increasingly popular technology, which defines the structure and operation of LPWAN networks based on the LoRa physical layer. There are previously known security vulnerabilities in LoRaWAN that lead to the proposal of several improvements, some already incorporated into the latest protocol specification. Our analysis of LoRaWAN security uses Scyther, a formal security analysis tool and focuses on the key exchange portion of versions 1.0 (released in 2015) and 1.1 (the latest, released in 2017). For version 1.0, which is still the most widely deployed version of LoRaWAN, we show that our formal model allowed to uncover weaknesses that can be related to previously reported vulnerabilities. Our model did not find weaknesses in the latest version of the protocol (v1.1), and we discuss what this means in practice for the security of LoRaWAN as well as important aspects of our model and tools employed that should be considered. The Scyther model developed provides realistic models for LoRaWAN v1.0 and v1.1 that can be used and extended to formally analyze, inspect, and explore the security features of the protocols. This, in turn, can clarify the methodology for achieving secrecy, integrity, and authentication for designers and developers interested in these LPWAN standards. We believe that our model and discussion of the protocols security properties are beneficial for both researchers and practitioners. To the best of our knowledge, this is the first work that presents a formal security analysis of LoRaWAN. (C) 2018 Elsevier B.V. All rights reserved.
引用
收藏
页码:328 / 339
页数:12
相关论文
共 50 条
  • [31] LoRaWAN Security: An Evolvable Survey on Vulnerabilities, Attacks and their Systematic Mitigation
    Hessel, Frank
    Almon, Lars
    Hollick, Matthias
    ACM TRANSACTIONS ON SENSOR NETWORKS, 2022, 18 (04)
  • [32] Analysis of Latency and MAC-Layer Performance for Class A LoRaWAN
    Sorensen, Rene Brandborg
    Kim, Dong Min
    Nielsen, Jimmy Jessen
    Popovski, Petar
    IEEE WIRELESS COMMUNICATIONS LETTERS, 2017, 6 (05) : 566 - 569
  • [33] Privacy monitoring of LoRaWAN devices through traffic stream analysis
    Terenzi, Francesco
    Spadaccino, Pietro
    Cuomo, Francesca
    2022 IEEE 23RD INTERNATIONAL SYMPOSIUM ON A WORLD OF WIRELESS, MOBILE AND MULTIMEDIA NETWORKS (WOWMOM 2022), 2022, : 425 - 433
  • [34] Analysis of the Influence of Terrain on LoRaWAN-based IoT Deployments
    Torres-Sanz, Vicente
    A Sanguesa, Julio
    Serna, Felix
    J Martinez, Francisco
    Garrido, Piedad
    Calafate, Carlos T.
    PROCEEDINGS OF THE INT'L ACM CONFERENCE ON MODELING, ANALYSIS AND SIMULATION OF WIRELESS AND MOBILE SYSTEMS, MSWIM 2023, 2023, : 217 - 224
  • [35] Enhancing LoRaWAN Security: An Advanced AES-Based Cryptographic Approach
    Abboud, Samira
    Abdoun, Nabil
    IEEE ACCESS, 2024, 12 : 2589 - 2606
  • [36] Novel Enhanced LoRaWAN Framework for Smart Home Remote Control Security
    Naoui, Sarra
    Elhdhili, Mohamed Elhoucine
    Azouz Saidane, Leila
    WIRELESS PERSONAL COMMUNICATIONS, 2020, 110 (04) : 2109 - 2130
  • [37] Novel Enhanced LoRaWAN Framework for Smart Home Remote Control Security
    Sarra Naoui
    Mohamed Elhoucine Elhdhili
    Leila Azouz Saidane
    Wireless Personal Communications, 2020, 110 : 2109 - 2130
  • [38] Enhancing LoRaWAN Security through a Lightweight and Authenticated Key Management Approach
    Sanchez-Iborra, Ramon
    Sanchez-Gomez, Jesus
    Perez, Salvador
    Fernandez, Pedro J.
    Santa, Jose
    Hernandez-Ramos, Jose L.
    Skarmeta, Antonio F.
    SENSORS, 2018, 18 (06)
  • [39] Implementation and Analysis of LoRaWAN Network in Landfill
    Silvino Belo da Silva, Joao Paulo
    Silveri Freire, Raimundo Carlos
    de Souza, Cleonilson Protasio
    Granja Aguiar, Icaro Modesto
    2024 8TH INTERNATIONAL SYMPOSIUM ON INSTRUMENTATION SYSTEMS, CIRCUITS AND TRANSDUCERS, INSCIT 2024, 2024,
  • [40] LoRa-PUF: A Two-Step Security Solution for LoRaWAN
    Aliyu, Mohammed Bello
    Hafeez, Maryam
    Johnson, Anju
    2023 IEEE 97TH VEHICULAR TECHNOLOGY CONFERENCE, VTC2023-SPRING, 2023,