Evaluation of Side-Channel Key-Recovery Attacks on LoRaWAN End-Device

Evaluation of Side-Channel Key-Recovery Attacks on LoRaWAN End-Device
复制标题

LoRaWAN 终端设备上的侧通道密钥恢复攻击评估

DOI:
10.1007/978-3-030-49443-8_4
复制
发表时间:
2019
期刊:
Internet Things
影响因子:
--
通讯作者:
S. Guilley
S. Guilley
中科院分区:
--
文献类型:
--
作者:
Kazuhide Fukushima;Damien Marion;Yuto Nakano;A. Facon;S. Kiyomoto;S. Guilley

文献摘要

被引文献

相似文献

物联网设备已得到广泛应用。预计在汽车和交通、医疗保健、工业等领域,物联网市场将快速增长。为了维护物联网服务的安全性和隐私性,数据保护和完整性对物联网服务至关重要。低功耗广域(LPWA)是一种专为物联网应用和终端设备设计的无线通信技术,需要低成本、长电池寿命、广域覆盖和高系统容量。LoRaWAN是LPWA的开放标准,通过加密和消息完整性码(MIC)实现数据保护和完整性。许多研究指出了安全问题和针对LPWA协议的攻击,并提出了提高此类攻击安全性的解决方案。然而,侧信道分析技术可以直接从设备中恢复秘密信息。在本文中,我们评估了侧信道分析对实际LoRaWAN终端设备的适用性。我们的实验试图恢复AES-128密钥来加密帧有效载荷,并基于相关功率分析计算加密有效载荷的消息完整性码(MIC),这是一种侧信道分析。260电磁(EM)泄漏跟踪完全恢复16字节密钥用于帧有效载荷加密,140电磁泄漏跟踪恢复16字节密钥的12字节用于MIC生成。此外,我们还证明了我们的密钥恢复攻击适用于实际的LoRaWAN协议。我们的攻击可以完全恢复LoRaWAN v1.0中的根密钥AppKey和LoRaWAN v1.1中的根密钥NwkKey。
IoT devices have come into widespread use. The rapid growth of the IoT market is expected in the field of automobiles and transportation, medical and health care, and industry. Data protection and integrity are critical for IoT-based services in order to maintain the security and privacy of them. Low-power wide-area (LPWA) is a wireless communication technology designed for IoT applications and end-devices requiring low cost, long battery life, wide-area coverage, and high system capacity. LoRaWAN is an open standard for LPWA and achieves data protection and integrity by using encryption and message integrity code (MIC). Many studies have pointed out security issues, and attacks against LPWA protocols and have proposed solutions to improve security against such attacks. However, side-channel analysis techniques can directly recover secret information from a device. In this paper, we evaluate the applicability of a side-channel analysis to a real LoRaWAN end-device. Our experiments attempt to recover AES-128 keys to encrypt frame payload and calculate the message integrity code (MIC) for the encrypted payload based on a correlation power analysis, which is a type of side-channel analysis. The 260 electromagnetic(EM)-leakage traces entirely recover the 16-byte key for the frame payload encryption, and the 140 EM-leakage traces recover the 12 bytes of the 16-byte key for MIC generation. Furthermore, we show that our key recovery attack is applicable in real LoRaWAN protocols. Our attack can entirely recover the root key AppKey in LoRaWAN v1.0 and a root key NwkKey in LoRaWAN v1.1.