Remote Attestation based Software Integrity of IoT devices

Remote Attestation based Software Integrity of IoT devices
复制标题

基于远程认证的物联网设备软件完整性

DOI:
10.1109/ants47819.2019.9117946
复制
发表时间:
2019
期刊:
2019 IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS)
影响因子:
--
通讯作者:
Sai Kiran Kumar Reddy Y
Sai Kiran Kumar Reddy Y
中科院分区:
--
文献类型:
--
作者:
Shyam Sundar;Prabhakara Yellai;Siva Sankara Sai Sanagapati;Prayas Chandra Pradhan;Sai Kiran Kumar Reddy Y

文献摘要

被引文献

相似文献

物联网是当今世界正在走向的新范式。随着这些设备的激增,这些规模的安全问题变得越来越令人生畏。传统的方法,如防病毒软件,不能很好地与这些设备配合使用,因此需要寻找一种更值得信赖的解决方案。对于具有合理计算能力的设备,我们使用软件可信平台模块进行加密操作。在本文中,我们已经开发了一个模型来远程证明设备中运行的进程的完整性。我们还探讨了TPM(可信平台模块)的各种功能,以深入了解其工作原理,并确定可以使此过程更好的功能。此模型依赖于服务器和TPM作为此模型的信任根。客户端计算HMAC(散列消息认证码)值,并附加一个随机数,并通过非对称加密定期将这些值发送到服务器。服务器通过与其已知良好值(KGV)进行比较来验证HMAC值,并且确定过程的可信度,并且相应地发送授权响应。
Internet of Things is the new paradigm towards which the world is moving today. As these devices proliferate, security issues at these scales become more and more intimidating. Traditional approach like an antivirus does not work well with these devices and there is a need to look for a more trusted solution. For a device with reasonable computational power, we use a software trusted platform module for the cryptographic operations. In this paper, we have developed a model to remotely attest to the integrity of the processes running in the device. We have also explored the various features of the TPM (Trusted Platform Module) to gain insight into its working and also to ascertain those which can make this process better. This model depends on the server and the TPM to behave as roots of trust for this model. The client computes the HMAC (Hashed Message Authentication Code) values and appends a nonce and sends these values periodically to the server via asymmetric encryption. The HMAC values are verified by the server by comparing with its known good values (KGV) and the trustworthiness of the process is determined and accordingly an authorization response is sent.