State-of-the-Art Software-Based Remote Attestation: Opportunities and Open Issues for Internet of Things

被引:33
作者
Ankergard, Sigurd Frej Joel Jorgensen [1 ]
Dushku, Edlira [1 ]
Dragoni, Nicola [1 ]
机构
[1] Tech Univ Denmark DTU, DTU Comp, DK-2800 Lyngby, Denmark
关键词
remote attestation; software-based attestation; timing-based attestation; software integrity verification; legacy Internet of Things; INTEGRITY; SCHEME;
D O I
10.3390/s21051598
中图分类号
O65 [分析化学];
学科分类号
070302 ; 081704 ;
摘要
The Internet of Things (IoT) ecosystem comprises billions of heterogeneous Internet-connected devices which are revolutionizing many domains, such as healthcare, transportation, smart cities, to mention only a few. Along with the unprecedented new opportunities, the IoT revolution is creating an enormous attack surface for potential sophisticated cyber attacks. In this context, Remote Attestation (RA) has gained wide interest as an important security technique to remotely detect adversarial presence and assure the legitimate state of an IoT device. While many RA approaches proposed in the literature make different assumptions regarding the architecture of IoT devices and adversary capabilities, most typical RA schemes rely on minimal Root of Trust by leveraging hardware that guarantees code and memory isolation. However, the presence of a specialized hardware is not always a realistic assumption, for instance, in the context of legacy IoT devices and resource-constrained IoT devices. In this paper, we survey and analyze existing software-based RA schemes (i.e., RA schemes not relying on specialized hardware components) through the lens of IoT. In particular, we provide a comprehensive overview of their design characteristics and security capabilities, analyzing their advantages and disadvantages. Finally, we discuss the opportunities that these RA schemes bring in attesting legacy and resource-constrained IoT devices, along with open research issues.
引用
收藏
页码:1 / 23
页数:23
相关论文
共 51 条
  • [1] INVITED Things, Trouble, Trust: On Building Trust in IoT Systems
    Abera, Tigist
    Asokan, N.
    Davi, Lucas
    Koushanfar, Farinaz
    Paverd, Andrew
    Sadeghi, Ahmad-Reza
    Tsudik, Gene
    [J]. 2016 ACM/EDAC/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2016,
  • [2] Ahn S, 2007, LECT NOTES COMPUT SC, V4706, P296
  • [3] Collective Remote Attestation at the Internet of Things Scale: State-of-the-Art and Future Challenges
    Ambrosin, Moreno
    Conti, Mauro
    Lazzeretti, Riccardo
    Rabbani, Md Masoom
    Ranise, Silvio
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2020, 22 (04): : 2447 - 2461
  • [4] SANA: Secure and Scalable Aggregate Network Attestation
    Ambrosin, Moreno
    Conti, Mauro
    Ibrahim, Ahmad
    Neven, Gregory
    Sadeghi, Ahmad-Reza
    Schunter, Matthias
    [J]. CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 731 - 742
  • [5] SIMPLE: A Remote Attestation Approach for Resource-constrained IoT devices
    Ammar, Mahmoud
    Crispo, Bruno
    Tsudik, Gene
    [J]. 2020 ACM/IEEE 11TH INTERNATIONAL CONFERENCE ON CYBER-PHYSICAL SYSTEMS (ICCPS 2020), 2020, : 247 - 258
  • [6] SμV-The Security MicroVisor: A Formally-Verified Software-Based Security Architecture for the Internet of Things
    Ammar, Mahmoud
    Crispo, Bruno
    Jacobs, Bart
    Hughes, Danny
    Daniels, Wilfried
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2019, 16 (05) : 885 - 901
  • [7] [Anonymous], 2006, P 5 ACM WORKSH WIR S
  • [8] [Anonymous], 2015, P 22 ACM SIGSAC C CO
  • [9] [Anonymous], 2014, P ACM EUROPEAN C COM
  • [10] Armknecht F., 2013, ACM CCS, P1