簡易檢索 / 詳目顯示

研究生: 侯昱志
Hou, Yu-Zhi
論文名稱: 在物聯網中基於物理不可仿造功能之安全相互喚醒機制
A Secure Mutual Wake-up Scheme based on PUF for IoT
指導教授: 林輝堂
Lin, Hui-Tang
學位類別: 碩士
Master
系所名稱: 電機資訊學院 - 電腦與通信工程研究所
Institute of Computer & Communication Engineering
論文出版年: 2021
畢業學年度: 109
語文別: 英文
論文頁數: 79
中文關鍵詞: 物聯網喚醒無線電喚醒令牌物理不可仿造功能
外文關鍵詞: Internet of things (IoT), wake-up token, wake-up token, Physically unclonable functions (PUF)
相關次數: 點閱:136下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 由於物聯網設備其體積小的特性因此經常被佈建在生活周遭,透過捕獲設備本身並且對設備實施物理與克隆攻擊達到偽裝成受害者設備,進而加入整個網路加以破壞。除了安全性上的問題之外還有能源上的問題,由於物聯網設備經常使用容量有限的電池進行供電,因此近期的研究提出配備低功耗喚醒無線電以解決能源上的問題,使用喚醒無線電監控設備的傳輸通道,並且轉換主要無線電為睡眠模式,在有其他設備透過發送正確的喚醒令牌後才將主要無線電開啟,由於喚醒無線電接收器的耗能僅為主要無線電接收器的千分之一,因此可以達到降低平均功耗的目的,但是配備喚醒無線電也會導致一些惡意攻擊,例如抵禦睡眠攻擊、重放攻擊。根據現行的研究所提出的喚醒流程並未考慮到控制的中央節點-閘道缺乏能源的問題。為了解決以上的問題,我們提出一套設備與閘道間的相互驗證機制,在驗證完成之後便會為閘道與設備建立結合物理不可仿造功能與雜湊樹的喚醒令牌和會話金鑰能夠有效的抵禦上述的攻擊,並且設計一套相互喚醒機制,並且設計一套設備與閘道之間的同步機制,確保閘道與設備之間不會有不同步的情況產生。

    In recent years, the rise of the Internet of Things (IoT) technology has led to a year-on-year increase in Internet of Things devices. That also brings convenience in life, but it also brings some security issues. Due to the small size of IoT devices, they are often deployed around life. They are highly convenient but bring some safety issues. For example, the attacker captures the IoT device, reads confidential information in the non-volatile memory, and then copies it to another device. They were using this technique to fake the identity of the victim's device and join the network to destroy it. In addition to security issues, there are also energy issues. Due to the limited battery power supply, recent researches have proposed a low-power wake-up receiver to solve the energy problem. Using the wake-up receiver to monitor the channel and turn off the main radio transceiver to sleep mode. Because the energy consumption of the wake-up receiver is much lower than that of the main radio transceiver, the average power consumption can be reduced. In this situation, the attacker can guess the wake-up token or get the old wake-up token through monitoring, replay the wake-up token to keep the main radio awake. Furthermore, recent researches have not taken into account the lack of energy in the central node.
    To solve the above problems, we propose a authentication process to verify that new devices join the network. After the authentication is completed, a wake-up token(WuT) and session key for the gateway and device to wake up next time will be established. In addition, consider that the gateway may need to be equipped with a wake-up radio. We propose a mutual wake-up scheme using a one-time WuT and session key for wake-up between the device and the gateway. Furthermore, we propose a synchronization scheme to solve the WuT between the gateway and the device out of synchronization.

    Abstract III Contents VI List of Figures IX List of Tables XI Chapter 1 1 1.1 Overview 1 1.2 Internet of Thing 3 1.3 Energy Issue 4 1.4 Wake-up Radio 4 1.4.1 Denial-of-Sleep Attack 5 1.5 Security Issue 7 1.5.1 Physical and Cloning Attack 7 1.6 Physical Unclonable Function 8 1.7 Motivation 8 1.8 Objective 10 1.9 Thesis Outline 11 Chapter 2 12 2.1 Wake-up Scheme 12 2.1.1 SWARD: A Secure WAke-up RaDio against Denial-of-Service on IoT devices 13 2.2 Authentication 16 2.2.1 Building PUF Based Authentication and Key Exchange Protocol for IoT 17 2.2.2 An online data-oriented authentication based on Merkle tree with improved reliability 19 Chapter 3 22 3.1 Network Scenario 22 3.2 Assumption 23 3.3 Proposed Scheme 24 3.3.1 Identity Authentication and Wake-up Token Establishment 25 3.3.2 Wake-up Scheme and Wake-up Token Update 32 3.3.3 Wake-up Token Resynchronization 36 Chapter 4 41 4.1 SVO Logical Notation 41 4.2 SVO Rule and Axioms 43 4.3 Authentication Goal 45 4.4 Analysis with SVO Logic 45 4.4.1 Analysis of Identity Authentication 46 4.4.2 Analysis of the Wake-up Scheme 51 4.4.3 Analysis of the Resynchronization scheme 55 4.5 Security of the Protocols 59 4.6 Performance analysis 63 4.7 Compared with related work 65 Chapter 5 69 5.1 Experiment Setup 69 5.2 Identity Authentication and Wake-up Token Establishment Experiment 71 5.3 Wake-up Scheme and Wake-up Token Update 74 5.4 Wake-up Token Resynchronization 75 Chapter 6 77 Bibliography 78

    Bibliography
    [1] Montoya, M., et al. Sward: a secure wake-up radio against denial-of-service on
    iot devices. in Proceedings of the 11th ACM Conference on Security & Privacy
    in Wireless and Mobile Networks. 2018.
    [2] Azarmehr, M., A. Ahmadi, and R. Rashidzadeh. Secure authentication and
    access mechanism for IoT wireless sensors. in 2017 IEEE International
    Symposium on Circuits and Systems (ISCAS). 2017. IEEE.
    [3] Stecklina, O., S. Kornemann, and M. Methfessel. A secure wake-up scheme for
    low power wireless sensor nodes. in 2014 International Conference on
    Collaboration Technologies and Systems (CTS). 2014. IEEE.
    [4] Carroll, A. and G. Heiser. An analysis of power consumption in a smartphone.
    in USENIX annual technical conference. 2010. Boston, MA.
    [5] Oller, J., et al., Has time come to switch from duty-cycled MAC protocols to
    wake-up radio for wireless sensor networks? IEEE/ACM Transactions on
    Networking, 2015. 24(2): p. 674-687.
    [6] Piyare, R., et al., Ultra low power wake-up radios: A hardware and networking
    survey. IEEE Communications Surveys & Tutorials, 2017. 19(4): p. 2117-2157.
    [7] Chiou, L.-Y., C.-H. Wu, and P.-C. Wei. A reliable delay-based physical
    unclonable function with dark-bit avoidance. in 2019 IEEE International
    Symposium on Circuits and Systems (ISCAS). 2019. IEEE.
    [8] Herder, C., et al., Physical unclonable functions and applications: A tutorial.
    Proceedings of the IEEE, 2014. 102(8): p. 1126-1141.
    [9] Holcomb, D.E., W.P. Burleson, and K. Fu, Power-up SRAM state as an
    identifying fingerprint and source of true random numbers. IEEE Transactions
    on Computers, 2008. 58(9): p. 1198-1210.
    [10] Suh, G.E. and S. Devadas. Physical unclonable functions for device
    authentication and secret key generation. in 2007 44th ACM/IEEE Design
    Automation Conference. 2007. IEEE.
    [11] Chatterjee, U., et al., Building PUF based authentication and key exchange
    protocol for IoT without explicit CRPs in verifier database. IEEE transactions
    on dependable and secure computing, 2018. 16(3): p. 424-437.
    [12] Koo, D., et al. An online data-oriented authentication based on Merkle tree with
    improved reliability. in 2017 IEEE international conference on web services
    (ICWS). 2017. IEEE.
    [13] Imamoto, K. and K. Sakurai, Design and analysis of diffie-hellman-based key
    exchange using one-time ID by SVO logic. Electronic Notes in Theoretical
    Computer Science, 2005. 135(1): p. 79-94.
    [14] Syverson, P.F. and P.C. Van Oorschot, A unified cryptographic protocol logic.
    1996, NAVAL RESEARCH LAB WASHINGTON DC.
    [15] Warnier, M., Bilateral Key Exchange analysed in BAN logic. Computer Science
    Institute, University of Nijmegen, 2002.
    [16] Burrows, M., M. Abadi, and R.M. Needham, A logic of authentication.
    Proceedings of the Royal Society of London. A. Mathematical and Physical
    Sciences, 1989. 426(1871): p. 233-271.
    [17] Cheng, K.-W. and S.-E. Chen, An ultralow-power wake-up receiver based on
    direct active RF detection. IEEE Transactions on Circuits and Systems I:
    Regular Papers, 2017. 64(7): p. 1661-1672.
    [18] Maurer, U. and S. Wolf. Diffie-Hellman, decision Diffie-Hellman, and discrete
    logarithms. in Proceedings. 1998 IEEE International Symposium on
    Information Theory (Cat. No. 98CH36252). 1998. IEEE.
    [19] Rachmawati, D., J. Tarigan, and A. Ginting. A comparative study of Message
    Digest 5 (MD5) and SHA256 algorithm. in Journal of Physics: Conference
    Series. 2018. IOP Publishing.

    下載圖示
    2026-08-19公開
    QR CODE