| 研究生: |
侯昱志 Hou, Yu-Zhi |
|---|---|
| 論文名稱: |
在物聯網中基於物理不可仿造功能之安全相互喚醒機制 A Secure Mutual Wake-up Scheme based on PUF for IoT |
| 指導教授: |
林輝堂
Lin, Hui-Tang |
| 學位類別: |
碩士 Master |
| 系所名稱: |
電機資訊學院 - 電腦與通信工程研究所 Institute of Computer & Communication Engineering |
| 論文出版年: | 2021 |
| 畢業學年度: | 109 |
| 語文別: | 英文 |
| 論文頁數: | 79 |
| 中文關鍵詞: | 物聯網 、喚醒無線電 、喚醒令牌 、物理不可仿造功能 |
| 外文關鍵詞: | Internet of things (IoT), wake-up token, wake-up token, Physically unclonable functions (PUF) |
| 相關次數: | 點閱:136 下載:0 |
| 分享至: |
| 查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報 |
由於物聯網設備其體積小的特性因此經常被佈建在生活周遭,透過捕獲設備本身並且對設備實施物理與克隆攻擊達到偽裝成受害者設備,進而加入整個網路加以破壞。除了安全性上的問題之外還有能源上的問題,由於物聯網設備經常使用容量有限的電池進行供電,因此近期的研究提出配備低功耗喚醒無線電以解決能源上的問題,使用喚醒無線電監控設備的傳輸通道,並且轉換主要無線電為睡眠模式,在有其他設備透過發送正確的喚醒令牌後才將主要無線電開啟,由於喚醒無線電接收器的耗能僅為主要無線電接收器的千分之一,因此可以達到降低平均功耗的目的,但是配備喚醒無線電也會導致一些惡意攻擊,例如抵禦睡眠攻擊、重放攻擊。根據現行的研究所提出的喚醒流程並未考慮到控制的中央節點-閘道缺乏能源的問題。為了解決以上的問題,我們提出一套設備與閘道間的相互驗證機制,在驗證完成之後便會為閘道與設備建立結合物理不可仿造功能與雜湊樹的喚醒令牌和會話金鑰能夠有效的抵禦上述的攻擊,並且設計一套相互喚醒機制,並且設計一套設備與閘道之間的同步機制,確保閘道與設備之間不會有不同步的情況產生。
In recent years, the rise of the Internet of Things (IoT) technology has led to a year-on-year increase in Internet of Things devices. That also brings convenience in life, but it also brings some security issues. Due to the small size of IoT devices, they are often deployed around life. They are highly convenient but bring some safety issues. For example, the attacker captures the IoT device, reads confidential information in the non-volatile memory, and then copies it to another device. They were using this technique to fake the identity of the victim's device and join the network to destroy it. In addition to security issues, there are also energy issues. Due to the limited battery power supply, recent researches have proposed a low-power wake-up receiver to solve the energy problem. Using the wake-up receiver to monitor the channel and turn off the main radio transceiver to sleep mode. Because the energy consumption of the wake-up receiver is much lower than that of the main radio transceiver, the average power consumption can be reduced. In this situation, the attacker can guess the wake-up token or get the old wake-up token through monitoring, replay the wake-up token to keep the main radio awake. Furthermore, recent researches have not taken into account the lack of energy in the central node.
To solve the above problems, we propose a authentication process to verify that new devices join the network. After the authentication is completed, a wake-up token(WuT) and session key for the gateway and device to wake up next time will be established. In addition, consider that the gateway may need to be equipped with a wake-up radio. We propose a mutual wake-up scheme using a one-time WuT and session key for wake-up between the device and the gateway. Furthermore, we propose a synchronization scheme to solve the WuT between the gateway and the device out of synchronization.
Bibliography
[1] Montoya, M., et al. Sward: a secure wake-up radio against denial-of-service on
iot devices. in Proceedings of the 11th ACM Conference on Security & Privacy
in Wireless and Mobile Networks. 2018.
[2] Azarmehr, M., A. Ahmadi, and R. Rashidzadeh. Secure authentication and
access mechanism for IoT wireless sensors. in 2017 IEEE International
Symposium on Circuits and Systems (ISCAS). 2017. IEEE.
[3] Stecklina, O., S. Kornemann, and M. Methfessel. A secure wake-up scheme for
low power wireless sensor nodes. in 2014 International Conference on
Collaboration Technologies and Systems (CTS). 2014. IEEE.
[4] Carroll, A. and G. Heiser. An analysis of power consumption in a smartphone.
in USENIX annual technical conference. 2010. Boston, MA.
[5] Oller, J., et al., Has time come to switch from duty-cycled MAC protocols to
wake-up radio for wireless sensor networks? IEEE/ACM Transactions on
Networking, 2015. 24(2): p. 674-687.
[6] Piyare, R., et al., Ultra low power wake-up radios: A hardware and networking
survey. IEEE Communications Surveys & Tutorials, 2017. 19(4): p. 2117-2157.
[7] Chiou, L.-Y., C.-H. Wu, and P.-C. Wei. A reliable delay-based physical
unclonable function with dark-bit avoidance. in 2019 IEEE International
Symposium on Circuits and Systems (ISCAS). 2019. IEEE.
[8] Herder, C., et al., Physical unclonable functions and applications: A tutorial.
Proceedings of the IEEE, 2014. 102(8): p. 1126-1141.
[9] Holcomb, D.E., W.P. Burleson, and K. Fu, Power-up SRAM state as an
identifying fingerprint and source of true random numbers. IEEE Transactions
on Computers, 2008. 58(9): p. 1198-1210.
[10] Suh, G.E. and S. Devadas. Physical unclonable functions for device
authentication and secret key generation. in 2007 44th ACM/IEEE Design
Automation Conference. 2007. IEEE.
[11] Chatterjee, U., et al., Building PUF based authentication and key exchange
protocol for IoT without explicit CRPs in verifier database. IEEE transactions
on dependable and secure computing, 2018. 16(3): p. 424-437.
[12] Koo, D., et al. An online data-oriented authentication based on Merkle tree with
improved reliability. in 2017 IEEE international conference on web services
(ICWS). 2017. IEEE.
[13] Imamoto, K. and K. Sakurai, Design and analysis of diffie-hellman-based key
exchange using one-time ID by SVO logic. Electronic Notes in Theoretical
Computer Science, 2005. 135(1): p. 79-94.
[14] Syverson, P.F. and P.C. Van Oorschot, A unified cryptographic protocol logic.
1996, NAVAL RESEARCH LAB WASHINGTON DC.
[15] Warnier, M., Bilateral Key Exchange analysed in BAN logic. Computer Science
Institute, University of Nijmegen, 2002.
[16] Burrows, M., M. Abadi, and R.M. Needham, A logic of authentication.
Proceedings of the Royal Society of London. A. Mathematical and Physical
Sciences, 1989. 426(1871): p. 233-271.
[17] Cheng, K.-W. and S.-E. Chen, An ultralow-power wake-up receiver based on
direct active RF detection. IEEE Transactions on Circuits and Systems I:
Regular Papers, 2017. 64(7): p. 1661-1672.
[18] Maurer, U. and S. Wolf. Diffie-Hellman, decision Diffie-Hellman, and discrete
logarithms. in Proceedings. 1998 IEEE International Symposium on
Information Theory (Cat. No. 98CH36252). 1998. IEEE.
[19] Rachmawati, D., J. Tarigan, and A. Ginting. A comparative study of Message
Digest 5 (MD5) and SHA256 algorithm. in Journal of Physics: Conference
Series. 2018. IOP Publishing.