Security Analysis and Improvement of a Secure and Distributed Reprogramming Protocol for Wireless Sensor Networks

Security Analysis and Improvement of a Secure and Distributed Reprogramming Protocol for Wireless Sensor Networks
复制标题

无线传感器网络安全分布式重编程协议的安全分析与改进

DOI:
10.1109/tie.2012.2218562
复制
发表时间:
2013-11-01
影响因子:
7.7
通讯作者:
Yang, Laurence T.
Yang, Laurence T.
中科院分区:
计算机科学1区
文献类型:
--
作者:
He, Daojing;Chen, Chun;Yang, Laurence T.

文献摘要

被引文献

相似文献

无线传感器网络中的无线重编程是将新的代码图像或相关命令传播到传感器节点的过程。由于无线传感器网络通常部署在敌对环境中,安全重编程一直是一个主要问题。虽然所有现有的不安全/安全重编程协议都基于集中式方法,但重要的是支持分布式重编程,其中多个授权网络用户可以同时直接重编程传感器节点,而无需涉及基站。最近,一种名为SDRP的新型安全分布式重编程协议被提出,这是该类协议的第一个工作。然而,在本文中,我们在SDRP的用户预处理阶段确定了一个固有的设计弱点,并证明它很容易受到模仿攻击,攻击者可以很容易地模仿任何授权用户进行重新编程。随后,我们提出了一个简单的修改,以解决已确定的安全问题,而不会失去SDRP的任何功能。我们的实验结果表明,通过添加1- b冗余数据可以消除设计弱点,并且建议的解决方案在1.6 ghz笔记本电脑上的执行时间不超过1 ms。因此,我们的解决方案对于实际应用程序是可行且安全的。此外,为了进一步提高SDRP的安全性和效率,我们表明,任何更好的基于身份的签名算法都可以直接用于SDRP。基于实施结果,我们证明了比原始SDRP的效率提高。
Wireless reprogramming in a wireless sensor network (WSN) is the process of propagating a new code image or relevant commands to sensor nodes. As a WSN is usually deployed in hostile environments, secure reprogramming is and will continue to be a major concern. While all existing insecure/secure reprogramming protocols are based on the centralized approach, it is important to support distributed reprogramming in which multiple authorized network users can simultaneously and directly reprogram sensor nodes without involving the base station. Very recently, a novel secure and distributed reprogramming protocol named SDRP has been proposed, which is the first work of its kind. However, in this paper, we identify an inherent design weakness in the user preprocessing phase of SDRP and demonstrate that it is vulnerable to an impersonation attack by which an adversary can easily impersonate any authorized user to carry out reprogramming. Subsequently, we propose a simple modification to fix the identified security problem without losing any features of SDRP. Our experimental results demonstrate that it is possible to eliminate the design weakness by adding 1-B redundant data and that the execution time of the suggested solution in a 1.6-GHz laptop PC is no more than 1 ms. Therefore, our solution is feasible and secure for real-world applications. Moreover, we show that, in order to further improve the security and efficiency of SDRP, any better established identity-based signature algorithm can be directly employed in SDRP. Based on implementation results, we demonstrate efficiency improvement over the original SDRP.