Insecure to the touch: attacking ZigBee 3.0 via touchlink commissioning

Insecure to the touch: attacking ZigBee 3.0 via touchlink commissioning
复制标题

触摸不安全:通过 touchlink 调试攻击 ZigBee 3.0

DOI:
10.1145/3098243.3098254
复制
发表时间:
2017
期刊:
Proceedings of the 10th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
通讯作者:
Frederik Armknecht
Frederik Armknecht
中科院分区:
--
文献类型:
--
作者:
Philipp Morgner;Stephan Mattejat;Z. Benenson;Christian Müller;Frederik Armknecht

文献摘要

被引文献

相似文献

数以亿计的物联网设备实现了ZigBee,这是一种低功耗的网状网络标准,而且这个数字预计还会增加。为了便于将新设备轻松集成到ZigBee网络中,开发了TouchLink调试。它被2016年12月向公众发布的最新规范ZigBee 3.0采用,作为ZigBee设备的两个调试选项之一。ZigBee 3.0产品可用于各种应用,还包括门锁和入侵者警报系统等安全关键产品。这项工作的目的是警告进一步采用这种调试模式。我们分析了Touchlink调试过程的安全性,并提出了直接利用标准特性的新型攻击,表明该调试过程在设计上是不安全的。我们发布了一个开源的渗透测试框架来评估这些漏洞的实际影响。我们在常用的ZigBee认证产品上对我们的工具进行了评估,我们演示了被动窃听者可以从130米的距离提取关键材料。此外,主动攻击者能够在190米的距离内接管设备。我们的分析得出结论,即使是一台支持TouchLink的设备也足以危及ZigBee 3.0网络的安全性,因此,任何未来的ZigBee产品都不应支持TouchLink调试。
Hundred millions of Internet of Things devices implement ZigBee, a low-power mesh network standard, and the number is expected to be growing. To facilitate an easy integration of new devices into a ZigBee network, touchlink commissioning was developed. It was adopted in the latest specifications, ZigBee 3.0, which were released to the public in December 2016, as one of two commissioning options for ZigBee devices. ZigBee 3.0 products can be used in various applications, also including security-critical products such as door locks and intruder alarm systems. The aim of this work is to warn about a further adoption of this commissioning mode. We analyze the security of touchlink commissioning procedure and present novel attacks that make direct use of standard's features, showing that this commissioning procedure is insecure by design. We release an open-source penetration testing framework to evaluate the practical implications of these vulnerabilities. Evaluating our tools on popular ZigBee-certified products, we demonstrate that a passive eavesdropper can extract key material from a distance of 130 meters. Furthermore, an active attacker is able to take-over devices from distances of 190 meters. Our analysis concludes that even a single touchlink-enabled device is sufficient to compromise the security of a ZigBee 3.0 network, and therefore, touchlink commissioning should not be supported in any future ZigBee products.