The Internet of Things (IoT) is increasingly intertwined with critical industrial processes, yet contemporary IoT devices offer limited security features, creating a large new attack surface. Remote attestation is a well-known technique to detect cyber threats by remotely verifying the internal state of a networked embedded device through a trusted entity. Multi-device attestation has received little attention although current single-device approaches show limited scalability in IoT applications. Though recent work has yielded some proposals for scalable attestation, several aspects remain unexplored, and thus more research is required. This paper presents slimIoT, a scalable lightweight attestation protocol that is suitable for all IoT devices. slimIoT depends on an efficient broadcast authentication scheme along with symmetric key cryptography. It is resilient against a strong adversary with physical access to the IoT device. Our protocol is informative in the sense that it identifies the precise status of every device in the network. We implement and evaluate slimIoT considering many factors. On the one hand, our evaluation results show a low overhead in terms of memory footprint and runtime. On the other hand, simulations demonstrate that slimIoT is scalable, robust and highly efficient to be used in static and dynamic networks consisting of thousands of heterogenous IoT devices.

slimIoT: Scalable Lightweight Attestation Protocol For the Internet of Things / Ammar, Mahmoud; Washha, Mahdi; Sankar Ramachandran, Gowri; Crispo, Bruno. - (2018), pp. 1-8. (Intervento presentato al convegno DSC tenutosi a Taiwan nel 10-13 December, 2018) [10.1109/DESEC.2018.8625142].

slimIoT: Scalable Lightweight Attestation Protocol For the Internet of Things

Bruno Crispo
2018-01-01

Abstract

The Internet of Things (IoT) is increasingly intertwined with critical industrial processes, yet contemporary IoT devices offer limited security features, creating a large new attack surface. Remote attestation is a well-known technique to detect cyber threats by remotely verifying the internal state of a networked embedded device through a trusted entity. Multi-device attestation has received little attention although current single-device approaches show limited scalability in IoT applications. Though recent work has yielded some proposals for scalable attestation, several aspects remain unexplored, and thus more research is required. This paper presents slimIoT, a scalable lightweight attestation protocol that is suitable for all IoT devices. slimIoT depends on an efficient broadcast authentication scheme along with symmetric key cryptography. It is resilient against a strong adversary with physical access to the IoT device. Our protocol is informative in the sense that it identifies the precise status of every device in the network. We implement and evaluate slimIoT considering many factors. On the one hand, our evaluation results show a low overhead in terms of memory footprint and runtime. On the other hand, simulations demonstrate that slimIoT is scalable, robust and highly efficient to be used in static and dynamic networks consisting of thousands of heterogenous IoT devices.
2018
IEEE Conference on Dependable and Secure Computing
Piscataway, NJ USA
IEEE
978-1-5386-5790-4
Ammar, Mahmoud; Washha, Mahdi; Sankar Ramachandran, Gowri; Crispo, Bruno
slimIoT: Scalable Lightweight Attestation Protocol For the Internet of Things / Ammar, Mahmoud; Washha, Mahdi; Sankar Ramachandran, Gowri; Crispo, Bruno. - (2018), pp. 1-8. (Intervento presentato al convegno DSC tenutosi a Taiwan nel 10-13 December, 2018) [10.1109/DESEC.2018.8625142].
File in questo prodotto:
File Dimensione Formato  
1811.07367.pdf

accesso aperto

Tipologia: Post-print referato (Refereed author’s manuscript)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 370.82 kB
Formato Adobe PDF
370.82 kB Adobe PDF Visualizza/Apri
08625142.pdf

Solo gestori archivio

Tipologia: Versione editoriale (Publisher’s layout)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 332.19 kB
Formato Adobe PDF
332.19 kB Adobe PDF   Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/228511
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 12
  • ???jsp.display-item.citation.isi??? 14
social impact