Scrutinizing Implementations of Smart Home Integrations

被引:8
|
作者
Mahadewa, Kulani [3 ]
Wang, Kailong [3 ]
Bai, Guangdong [5 ]
Shi, Ling [4 ]
Liu, Yan [6 ]
Dong, Jin Song [1 ,2 ]
Liang, Zhenkai [3 ]
机构
[1] Natl Univ Singapore, Sch Comp, Singapore, Singapore
[2] Griffith Univ, Nathan, Qld 4111, Australia
[3] Natl Univ Singapore, Dept Comp Sci, Singapore, Singapore
[4] Natl Univ Singapore, Singapore, Singapore
[5] Univ Queensland, Brisbane, Qld, Australia
[6] Ant Financial, Hangzhou 310000, Peoples R China
基金
新加坡国家研究基金会;
关键词
Network security; Smart homes; Zigbee; Protocols; Authentication; !text type='Java']Java[!/text; Wireless fidelity; Internet of Things; IoT security; smart home; specification extraction; program analysis; SECURITY;
D O I
10.1109/TSE.2019.2960690
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
A key feature of the booming smart home is the integration of a wide assortment of technologies, including various standards, proprietary communication protocols and heterogeneous platforms. Due to customization, unsatisfied assumptions and incompatibility in the integration, critical security vulnerabilities are likely to be introduced by the integration. Hence, this work addresses the security problems in smart home systems from an integration perspective, as a complement to numerous studies that focus on the analysis of individual techniques. We propose HomeScan, an approach that examines the security of the implementations of smart home systems. It extracts the abstract specification of application-layer protocols and internal behaviors of entities, so that it is able to conduct an end-to-end security analysis against various attack models. Applying HomeScan on three extensively-used smart home systems, we have found twelve non-trivial security issues, which may lead to unauthorized remote control and credential leakage.
引用
收藏
页码:2667 / 2683
页数:17
相关论文
共 50 条
  • [1] Robust and Lightweight Remote User Authentication Mechanism for Next-Generation IoT-Based Smart Home
    Ashraf, Zeeshan
    Sohail, Adnan
    Hameed, Abdul
    Farhan, Muhammad
    Alotaibi, Faiz Abdullah
    Alnfiai, Mrim M.
    IEEE ACCESS, 2023, 11 : 137899 - 137910
  • [2] G2F: A Secure User Authentication for Rapid Smart Home IoT Management
    Luo, Hongwei
    Wang, Chao
    Luo, Hao
    Zhang, Fan
    Lin, Feng
    Xu, Guoai
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (13): : 10884 - 10895
  • [3] Signal Emulation Attack and Defense for Smart Home IoT
    Zhang, Xiaonan
    Yu, Sihan
    Zhou, Hansong
    Huang, Pei
    Guo, Linke
    Li, Ming
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (03) : 2040 - 2057
  • [4] Key-Free Authentication Protocol Against Subverted Indoor Smart Devices for Smart Home
    Huang, Zhigang
    Zhang, Lei
    Meng, Xinyu
    Choo, Kim-Kwang Raymond
    IEEE INTERNET OF THINGS JOURNAL, 2020, 7 (02) : 1039 - 1047
  • [5] Ranking Security of IoT-Based Smart Home Consumer Devices
    Allifah, Naba M.
    Zualkernan, Imran A.
    IEEE ACCESS, 2022, 10 : 18352 - 18369
  • [6] Sovereign: Self-Contained Smart Home With Data-Centric Network and Security
    Zhang, Zhiyi
    Yu, Tianyuan
    Ma, Xinyu
    Guan, Yu
    Moll, Philipp
    Zhang, Lixia
    IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (15) : 13808 - 13822
  • [7] A Secure and Anonymous User Authentication Scheme for IoT-Enabled Smart Home Environments Using PUF
    Cho, Yeongjae
    Oh, Jihyeon
    Kwon, Deokkyu
    Son, Seunghwan
    Lee, Joonyoung
    Park, Youngho
    IEEE ACCESS, 2022, 10 : 101330 - 101346
  • [8] A Robust Two-Factor User Authentication Scheme-Based ECC for Smart Home in IoT
    Zou, Shihong
    Cao, Qiang
    Wang, Chenyu
    Huang, Zifu
    Xu, Guoai
    IEEE SYSTEMS JOURNAL, 2022, 16 (03): : 4938 - 4949
  • [9] Lightweight Encryption for Smart Home
    Al Salami, Sanaah
    Baek, Joonsang
    Salah, Khaled
    Damiani, Ernesto
    PROCEEDINGS OF 2016 11TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY, (ARES 2016), 2016, : 382 - 388
  • [10] An Overview of Wireless IoT Protocol Security in the Smart Home Domain
    Marksteiner, Stefan
    Jimenez, Victor Juan Exposito
    Vallant, Heribert
    Zeiner, Herwig
    2017 JOINT 13TH CTTE AND 10TH CMI CONFERENCE ON INTERNET OF THINGS - BUSINESS MODELS, USERS, AND NETWORKS, 2017,