The growing pervasiveness of Internet of Things (IoT) expands the attack surface by connecting more and more attractive attack targets, i.e. embedded devices, to the Internet. One key component in securing these devices is software integrity checking, which typically attained with Remote Attestation (RA). RA is realized as an interactive protocol, whereby a trusted party, verifier, verifies the software integrity of a potentially compromised remote device, prover. In the vast majority of IoT applications, smart devices operate in swarms, thus triggering the need for efficient swarm attestation schemes.In this paper, we present WISE, the first intelligent swarm attestation protocol that aims to minimize the communication overhead while preserving an adequate level of security. WISE depends on a resource-efficient smart broadcast authentication scheme where devices are organized in fine-grained multi-clusters, and whenever needed, the most likely compromised devices are attested. The candidate devices are selected intelligently taking into account the attestation history and the diverse characteristics (and constraints) of each device in the swarm. We show that WISE is very suitable for resource-constrained embedded devices, highly efficient and scalable in heterogenous IoT networks, and offers an adjustable level of security.

WISE: Lightweight Intelligent Swarm Attestation Scheme for IoT (The Verifier's Perspective) / Ammar, Mahmoud; Washha, Mahdi; Crispo, Bruno. - (2018), pp. 1-8. (Intervento presentato al convegno 14th International Conference on Wireless and Mobile Computing, Networking and Communications, WiMob 2018 tenutosi a Limassol, Cyprus nel 15th-17th October 2018) [10.1109/WiMOB.2018.8589107].

WISE: Lightweight Intelligent Swarm Attestation Scheme for IoT (The Verifier's Perspective)

Crispo, Bruno
2018-01-01

Abstract

The growing pervasiveness of Internet of Things (IoT) expands the attack surface by connecting more and more attractive attack targets, i.e. embedded devices, to the Internet. One key component in securing these devices is software integrity checking, which typically attained with Remote Attestation (RA). RA is realized as an interactive protocol, whereby a trusted party, verifier, verifies the software integrity of a potentially compromised remote device, prover. In the vast majority of IoT applications, smart devices operate in swarms, thus triggering the need for efficient swarm attestation schemes.In this paper, we present WISE, the first intelligent swarm attestation protocol that aims to minimize the communication overhead while preserving an adequate level of security. WISE depends on a resource-efficient smart broadcast authentication scheme where devices are organized in fine-grained multi-clusters, and whenever needed, the most likely compromised devices are attested. The candidate devices are selected intelligently taking into account the attestation history and the diverse characteristics (and constraints) of each device in the swarm. We show that WISE is very suitable for resource-constrained embedded devices, highly efficient and scalable in heterogenous IoT networks, and offers an adjustable level of security.
2018
2018 14th International Conference on Wireless and Mobile Computing, Networking and Communications(WiMob)
Piscataway, NJ
IEEE
9781538668764
Ammar, Mahmoud; Washha, Mahdi; Crispo, Bruno
WISE: Lightweight Intelligent Swarm Attestation Scheme for IoT (The Verifier's Perspective) / Ammar, Mahmoud; Washha, Mahdi; Crispo, Bruno. - (2018), pp. 1-8. (Intervento presentato al convegno 14th International Conference on Wireless and Mobile Computing, Networking and Communications, WiMob 2018 tenutosi a Limassol, Cyprus nel 15th-17th October 2018) [10.1109/WiMOB.2018.8589107].
File in questo prodotto:
File Dimensione Formato  
wise.pdf

Solo gestori archivio

Tipologia: Versione editoriale (Publisher’s layout)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 459.39 kB
Formato Adobe PDF
459.39 kB Adobe PDF   Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/228505
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 15
  • ???jsp.display-item.citation.isi??? 3
social impact