CAREER: Towards Secure and Usable IoT Authentication Under Constraints
CAREER: Towards Secure and Usable IoT Authentication Under Constraints
批准号:
2309550
负责人:
Qiang Zeng
金额:
$54.57万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-10-01 至 2027-05-31
中文摘要
物联网(IoT)的蓬勃发展对各个行业和日常生活产生了越来越大的影响。物联网身份验证是最基本、最关键的物联网安全问题之一,它验证用户和/或物联网设备的合法性。现有方法通常存在不安全(例如,基于蓝牙的邻近证明可被无线攻击利用)或可用性差(例如,要求用户界面或传感器在大多数物联网设备上不可用)。研究提出了约束条件下安全可用的物联网身份认证。与许多以前的工作建立在邻近的身份验证,这可能被无线攻击利用,该项目的新颖性是基于物理操作,不能被攻击者欺骗。该项目更广泛的意义和重要性如下。1)这项研究可以帮助农村地区或残疾人平等地获得现代技术,如无人机交付,而不依赖特殊的用户端硬件。2)研究可以使物联网配对和认证变得更加容易和安全,其结果在智能健康、取证和持续安全监控方面具有广泛的应用。3)国际和平协会将开展外联和教育活动,旨在提高K-12社区的网络安全意识,并扩大代表不足群体的学生的参与。该项目旨在通过以下努力改进物联网身份验证并提供新的方法、算法、技术和系统。推力1:用户界面受限设备的身份验证。一种协议,支持通过不安全的无线通道进行相互身份验证,以在用户界面受限的设备和用户之间建立信任,从而支持异构物联网设备的身份验证。推力2:距离受限设备的身份验证。一种高度可用的方法实现了物联网设备和用户之间的安全身份验证,即使他们相距数米,这一方法的应用范围从无人机交付到拼车。重点3:操作受限设备的身份验证。对于改装了零用户界面传感器节点的传统对象,人工智能辅助的隐式身份验证能够在不需要任何显式身份验证操作的情况下识别用户。总而言之,这项研究旨在大幅推进物联网身份验证并促进各种物联网应用。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The booming development of Internet of Things (IoT) makes ever-growing impacts on various industries and daily lives. IoT authentication, which authenticates the legitimacy of a user and/or an IoT device, is among the most fundamental and critical IoT security problems. Existing approaches often suffer from insecurity (e.g., Bluetooth based proximity proving can be exploited by wireless attacks) or poor usability (e.g., requiring user interfaces or sensors unavailable on most IoT devices). The research advances secure and usable IoT authentication under constraints. Unlike many prior works that build authentication on proximity, which can be exploited by wireless attacks, the project's novelty is based on physical operations that cannot be spoofed by an attacker. The project's broader significance and importance are as follows. 1) The research can help people in rural areas or with disabilities have equal rights of access to modern techniques, such as drone delivery, without relying on special user-side hardware. 2) The research can make IoT pairing and authentication much easier and more secure, and the results have wide applications to smart health, forensics, and continuous security monitoring. 3) The PI will conduct outreach and educational activities that aim to increase awareness of cybersecurity in the K-12 community and broaden the participation of students from underrepresented groups. The project seeks to improve IoT authentication and deliver novel approaches, algorithms, techniques, and systems through the following thrusts. Thrust 1: Authentication for UI-Constrained Devices. A protocol that supports mutual authentication, over an insecure wireless channel, to establish trust between a UI-constrained device and the user to support authentication for heterogeneous IoT devices. Thrust 2: Authentication for Distance-Constrained Devices. A highly usable approach enables secure authentication between an IoT device and the user even when they are multiple meters apart, which has applications ranging from drone delivery to ride sharing. Thrust 3: Authentication for Operation-Constrained Devices. For traditional objects retrofitted with zero-UI sensor nodes, AI-assisted implicit authentication enables recognizing a user without requiring any explicit authentication operations. In sum, the research seeks to substantially advance IoT authentication and foster a variety of IoT applications.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(3)
专著(0)
科研奖励(0)
会议论文
DOI:
10.1145/3495243.3560550
发表时间:
2022-10
期刊:
Proceedings of the 28th Annual International Conference on Mobile Computing And Networking
影响因子:
--
作者:
[Jonathan Sharp;Chuxiong Wu;Qiang Zeng]
通讯作者:
Jonathan Sharp;Chuxiong Wu;Qiang Zeng
DOI:
10.1145/3498361.3538941
发表时间:
2022-06
期刊:
Proceedings of the 20th Annual International Conference on Mobile Systems, Applications and Services
影响因子:
--
作者:
[Chuxiong Wu;Xiaopeng Li;Lannan Luo;Qiang Zeng]
通讯作者:
Chuxiong Wu;Xiaopeng Li;Lannan Luo;Qiang Zeng
CAREER: Towards Secure and Usable IoT Authentication Under Constraints
-
批准号:2144669
-
项目类别:Continuing Grant
-
资助金额:$54.57万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
CCRI: Medium: Collaborative Research: Hardware-in-the-Loop and Remotely-Accessible/Configurable/Programmable Internet of Things (IoT) Testbeds
-
批准号:2309477
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
Collaborative Research: CNS Core: Medium: Towards Understanding and Handling Problems Due to Coexistence of Multiple IoT Platforms
-
批准号:2310322
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2022
-
负责人:Qiang Zeng
-
依托单位:
Collaborative Research: CNS Core: Medium: Towards Understanding and Handling Problems Due to Coexistence of Multiple IoT Platforms
-
批准号:2107093
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2021
-
负责人:Qiang Zeng
-
依托单位:
CCRI: Medium: Collaborative Research: Hardware-in-the-Loop and Remotely-Accessible/Configurable/Programmable Internet of Things (IoT) Testbeds
-
批准号:2016415
-
项目类别:Standard Grant
-
资助金额:$45.0万
-
财政年份:2020
-
负责人:Qiang Zeng
-
依托单位:
SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
-
批准号:1856380
-
项目类别:Standard Grant
-
资助金额:$16.67万
-
财政年份:2018
-
负责人:Qiang Zeng
-
依托单位:
SaTC: CORE: Small: Collaborative: Enabling Precise and Automated Insecurity Analysis of Middleware on Mobile Platforms
-
批准号:1815045
-
项目类别:Standard Grant
-
资助金额:$16.67万
-
财政年份:2018
-
负责人:Qiang Zeng
-
依托单位:
海外基金