Building PUF Based Authentication and Key Exchange Protocol for IoT Without Explicit CRPs in Verifier Database

Building PUF Based Authentication and Key Exchange Protocol for IoT Without Explicit CRPs in Verifier Database
复制标题

DOI:
10.1109/tdsc.2018.2832201
复制
发表时间:
2019-05-01
影响因子:
7.3
通讯作者:
Prabhu, Mukesh M.
Prabhu, Mukesh M.
中科院分区:
计算机科学2区
文献类型:
--
作者:
Chatterjee, Urbi;Govindan, Vidya;Prabhu, Mukesh M.

文献摘要

被引文献

相似文献

物理不可克隆功能 (PUF) 有望成为关键的硬件原语,为物联网 (IoT) 中数十亿连接设备提供唯一身份。在传统的身份验证协议中,用户提供一组凭证以及随附的证据,例如密码或数字证书。然而,物联网需要更先进的方法,因为这些经典技术面临着密码依赖的紧迫问题,并且无法将访问请求绑定到它们所源自的“事物”。此外,协议需要轻量级且异构。尽管 PUF 似乎有希望开发这种机制,但它提出了一个悬而未决的问题,即如何开发这种机制,而不需要在验证者端显式存储秘密挑战-响应对(CRP)。在本文中,我们结合基于身份的加密(IBE)、PUF 和密钥哈希函数的思想开发了一种身份验证和密钥交换协议,以表明这种组合可以帮助消除这一要求。该协议的安全性在会话密钥安全性和通用可组合性框架下得到了正式证明。该协议的原型已经实现,以使用 Intel Edison 板与由 Artix-7 FPGA 组成的 Digilent Nexys-4 FPGA 板的组合来实现安全视频监控摄像头,并一起充当物联网节点。我们表明,虽然独立摄像机可能会使用标准网络渗透工具通过 IP 欺骗遭受中间人攻击,但使用所提出的协议增强的摄像机可以抵御此类攻击,并且它非常适合物联网基础设施,使该协议可在行业中部署。
Physically Unclonable Functions (PUFs) promise to be a critical hardware primitive to provide unique identities to billions of connected devices in Internet of Things (IoTs). In traditional authentication protocols a user presents a set of credentials with an accompanying proof such as password or digital certificate. However, IoTs need more evolved methods as these classical techniques suffer from the pressing problems of password dependency and inability to bind access requests to the "things" from which they originate. Additionally, the protocols need to be lightweight and heterogeneous. Although PUFs seem promising to develop such mechanism, it puts forward an open problem of how to develop such mechanism without needing to store the secret challenge-response pair (CRP) explicitly at the verifier end. In this paper, we develop an authentication and key exchange protocol by combining the ideas of Identity based Encryption (IBE), PUFs and Key-ed Hash Function to show that this combination can help to do away with this requirement. The security of the protocol is proved formally under the Session Key Security and the Universal Composability Framework. A prototype of the protocol has been implemented to realize a secured video surveillance camera using a combination of an Intel Edison board, with a Digilent Nexys-4 FPGA board consisting of an Artix-7 FPGA, together serving as the IoT node. We show, though the stand-alone video camera can be subjected to man-in-the-middle attack via IP-spoofing using standard network penetration tools, the camera augmented with the proposed protocol resists such attacks and it suits aptly in an IoT infrastructure making the protocol deployable for the industry.