μDTNSec: a security layer with lightweight certificates for Disruption-Tolerant Networks on microcontrollers

被引:0
作者
Schuermann, Dominik [1 ]
von Zengen, Georg [1 ]
Priedigkeit, Marvin [1 ]
Willenborg, Sebastian [1 ]
Wolf, Lars [1 ]
机构
[1] TU Braunschweig, Inst Operating Syst & Comp Networks, Braunschweig, Germany
关键词
Disruption-tolerant networking; DTN; Microcontroller; Security; PKI; ELLIPTIC CURVE CRYPTOGRAPHY; SENSOR; OPPORTUNITIES; CONTIKI; LIMITS;
D O I
10.1007/s12243-018-0655-2
中图分类号
TN [电子技术、通信技术];
学科分类号
0809 ;
摘要
In Delay/Disruption-Tolerant Networks, man-in-the-middle attacks are easy: due to the store-carry-forward principle, an attacker can simply place itself on the route between source and destination to eavesdrop or alter bundles. This weakness is aggravated in networks, where devices are energy-constrained but the attacker is not. To protect against these attacks, we design and implement mu DTNSec, a security layer for Delay/Disruption-Tolerant Networks on microcontrollers. Our design establishes a public key infrastructure with lightweight certificates as an extension to the Bundle Protocol. It has been fully implemented as an addition to mu DTN on Contiki OS and uses elliptic curve cryptography and hardware-backed symmetric encryption. In this enhanced version of mu DTNSec, public key identity bindings are validated by exchanging certificates using neighbor discovery. mu DTNSec provides a signature mode for authenticity and a sign-then-encrypt mode for added confidentiality. Our performance evaluation shows that the choice of the curve dominates the influence of the payload size. We also provide energy measurements for all operations to show the feasibility of our security layer on energy-constrained devices. Because a high quality source of randomness is required, we evaluated the random number generators by the AT86RF231 radio, its successor AT86RF233, and one based on the noise of the A/D converter. We found that only AT86RF233 provides the required quality.
引用
收藏
页码:589 / 600
页数:12
相关论文
共 22 条
  • [21] Security Analysis for Delay/Disruption Tolerant Satellite and Sensor Networks
    Bhutta, N.
    Ansa, G.
    Johnson, E.
    Ahmad, N.
    Alsiyabi, M.
    Cruickshank, H.
    [J]. 2009 INTERNATIONAL WORKSHOP ON SATELLITE AND SPACE COMMUNICATIONS, CONFERENCE PROCEEDINGS, 2009, : 385 - 389
  • [22] A Minimum Task-Based End-to-end Delivery Delay Routing Strategy With Updated Discrete Graph for Satellite Disruption-Tolerant Networks
    Yuan, Peng
    Yang, Zhihua
    Zhang, Qinyu
    Wang, Ye
    [J]. 2018 IEEE/CIC INTERNATIONAL CONFERENCE ON COMMUNICATIONS IN CHINA (ICCC), 2018, : 293 - 297