Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoT

Perils and Mitigation of Security Risks of Cooperation in Mobile-as-a-Gateway IoT
复制标题

DOI:
10.1145/3548606.3560590
复制
发表时间:
2022-11
期刊:
Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Xin'an Zhou;Jiale Guan;Luyi Xing;Zhiyun Qian
Xin'an Zhou;Jiale Guan;Luyi Xing;Zhiyun Qian
中科院分区:
其他
文献类型:
--
作者:
Xin'an Zhou;Jiale Guan;Luyi Xing;Zhiyun Qian

文献摘要

相似文献

移动即网关(MaaG)是一种流行的功能,它使用移动的设备作为网关,将物联网设备连接到云服务进行管理。MaaG物联网访问控制系统支持远程访问共享/撤销,同时允许“离线可用性”以获得更好的可用性。实现这些功能需要云服务、配套应用和物联网设备之间的安全合作。出于实际考虑,我们发现几乎所有的云服务都执行访问模型转换(AMT),将富有表现力的云端访问策略转换为简单的设备端策略。在此过程中,ad-hoc协议的开发,以支持访问策略同步。不幸的是,目前的MaaG物联网系统未能认识到访问模型转换和同步过程中的安全风险。我们分析了10款顶级MaaG物联网设备,发现它们都存在严重的漏洞,例如,允许临时用户不可撤销地和永久地访问。我们进一步提出了一个安全的协议设计,抵御所有已识别的攻击。
Mobile-as-a-Gateway (MaaG) is a popular feature using mobile devices as gateways to connect IoT devices to cloud services for management. MaaG IoT access control systems support remote access sharing/revocation while allowing "offline availability'' for better usability. Realizing these functionalities requires secure cooperation among the cloud service, the companion app, and the IoT device. For practical considerations, we find that almost all cloud services perform access model translation (AMT) to translate expressive cloud-side access policies to simple device-side policies. During the process, ad-hoc protocols are developed to support the access policy synchronization. Unfortunately, current MaaG IoT systems fail to recognize the security risks in the process of access model translation and synchronization. We analyze ten top-of-the-line MaaG IoT devices and find that all of them have serious vulnerabilities, e.g., allowing irrevocable and permanent access for temporary users. We further propose a secure protocol design that defends against all identified attacks.