Remote Attestation based Software Integrity of IoT devices
Remote Attestation based Software Integrity of IoT devices
复制标题
基于远程认证的物联网设备软件完整性
DOI:
10.1109/ants47819.2019.9117946
复制
发表时间:
2019
期刊:
影响因子:
--
通讯作者:
Sai Kiran Kumar Reddy Y
中科院分区:
文献类型:
--
作者:
Shyam Sundar;Prabhakara Yellai;Siva Sankara Sai Sanagapati;Prayas Chandra Pradhan;Sai Kiran Kumar Reddy Y
Internet of Things is the new paradigm towards which the world is moving today. As these devices proliferate, security issues at these scales become more and more intimidating. Traditional approach like an antivirus does not work well with these devices and there is a need to look for a more trusted solution. For a device with reasonable computational power, we use a software trusted platform module for the cryptographic operations. In this paper, we have developed a model to remotely attest to the integrity of the processes running in the device. We have also explored the various features of the TPM (Trusted Platform Module) to gain insight into its working and also to ascertain those which can make this process better. This model depends on the server and the TPM to behave as roots of trust for this model. The client computes the HMAC (Hashed Message Authentication Code) values and appends a nonce and sends these values periodically to the server via asymmetric encryption. The HMAC values are verified by the server by comparing with its known good values (KGV) and the trustworthiness of the process is determined and accordingly an authorization response is sent.