Cryptographic Enhancing of Data Security in IoT Devices
Cryptographic Enhancing of Data Security in IoT Devices
批准号:
RGPIN-2019-06150
负责人:
Mashatan, Atefeh
金额:
$2.04万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2020
资助国家:
加拿大
项目状态:
已结题
起止时间:
2020-01-01 至 2021-12-31
中文摘要
物联网,其中日常物品都连接并自主相互通信,正在彻底改变我们的生活。由IoT设备处理的数据可以是隐私敏感的,例如,在智能医疗保健和安全关键的情况下,例如,在智能制造的情况下,引起了严重的信息安全问题。
该研究计划的总体目标是设计,分析和实施端到端物联网安全和隐私解决方案,重点是(a)物联网系统中数据保护的寿命和(B)不同物联网设备之间物联网数据的敏感性水平。作为这项研究计划的结果,我们将产生可证明安全的系统的强大而实用的实现,从而增强物联网系统用户的上下文隐私和安全性。我们将通过识别物联网场景中数据完整性和机密性方面的挑战并通过设计新方案来解决这些挑战来实现这一目标。然后,我们通过概念验证实施来补充我们的发现,并将其进一步开发为端到端包,以便在行业中进行标准化和部署。
物联网设备变得越来越智能,包含更多关于我们的安全关键和隐私敏感信息,同时变得越来越小-使它们成为攻击者非常有吸引力的目标。虽然为无处不在的计算提供了巨大的机会,但智能设备的小型化带来了许多安全和隐私问题,因为传统的保护数字信息的机制不再足够。因此,物联网无法承受复杂的算法和对轻量级替代品的需求。我们将研究开发安全协议的新技术和方法,这些安全协议足够轻量级,可用于物联网中的小型传感器,同时提供足够的上下文安全和隐私保证。
另一个挑战是保密要求的长期性。许多物联网设备的部署寿命超过十年,或者存储的信息将在数十年内保持机密。这将他们带入了量子计算威胁的范围,目前标准化的公钥方案不再安全。虽然目前存在抗量子的解决方案,但它们尚未标准化,对于许多物联网场景来说绝对不够轻巧。我们将研究为物联网设备设计可扩展的抗量子解决方案的新方法,并以灵活的方式设计和实施它们,提供加密灵活性。
另一个物联网痛点是高效且可扩展的消息和设备身份验证,这通常通过加密密钥和凭证的安全管理来实现。这些技术高度依赖于公钥加密,这对于许多物联网设置来说是昂贵的且不可扩展的。我们将提出解决消息和设备身份验证的替代技术。
英文摘要
Internet-of-Things, where everyday objects are all connected and autonomously communicate with one another, is revolutionizing our lives. The data handled by the IoT devices can be privacy-sensitive, e.g., in the case of smart healthcare, and safety-critical, e.g., in the case of smart manufacturing, giving rise to serious information security concerns.
The overarching goal of this research program is to design, analyze and implement end-to-end IoT security and privacy solutions, with an emphasis on (a) longevity of data protection in the IoT systems and (b) varying sensitivity levels of the IoT data among different IoT devices. As a result of this research program, we will produce robust and practical implementations of provably secure systems and, in turn, enhance the contextual privacy and security of users of IoT systems. We will achieve this goal by identifying the challenges with respect to integrity and confidentiality of data in IoT scenarios and addressing them by designing new schemes. Then, we complement our findings with a proof-of-concept implementation and further develop it to an end-to-end package which is ready for standardization and deployment in the industry.
IoT devices are getting smarter and contain more safety-critical and privacy-sensitive information about us while becoming smaller - making them a very appealing target for attackers. While providing a great opportunity for ubiquitous computing, the miniaturization of smart devices brings many security and privacy concerns as the traditional mechanisms for safeguarding digital information are no longer adequate. As a result, IoT cannot afford complex algorithms and demands for lightweight alternatives. We will investigate new techniques and approaches for developing security protocols that are lightweight enough to be used in a small sensor in IoT while at the same time provide adequate and contextual security and privacy guarantees.
Another challenge is longevity of the confidentiality requirement. Many IoT devices are deployed with life expectancy of more than a decade or are storing information that are meant to remain confidential for decades. This brings them in the scope of the quantum computing threat where currently standardized public-key schemes are no longer secure. While quantum-resistant solutions currently exist, they are not yet standardized and definitely not lightweight enough for many IoT scenarios. We will investigate new approaches in designing scalable quantum-resistant solutions for IoT devices and design and implement them in a flexible manner providing crypto-agility.
One other IoT pain point is efficient and scalable message and device authentication which are typically achieved by secure management of cryptographic keys and credentials. These techniques are highly relying on public-key cryptography which are expensive and not scalable for many IoT settings. We will propose alternative techniques to address message and device authentication.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Quantum-Resistance and Efficiency of Communications in Connected and Autonomous Vehicles
-
批准号:536635-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$11.83万
-
财政年份:2021
-
负责人:Mashatan, Atefeh
-
依托单位:
Mosaïque digital wallets: A fully decentralized and data-driven identity and credential management system for business environments
-
批准号:555851-2020
-
项目类别:Idea to Innovation
-
资助金额:$9.11万
-
财政年份:2020
-
负责人:Mashatan, Atefeh
-
依托单位:
Quantum-Resistance and Efficiency of Communications in Connected and Autonomous Vehicles
-
批准号:536635-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$14.56万
-
财政年份:2020
-
负责人:Mashatan, Atefeh
-
依托单位:
Cryptographic Enhancing of Data Security in IoT Devices
-
批准号:DGECR-2019-00280
-
项目类别:Discovery Launch Supplement
-
资助金额:$0.91万
-
财政年份:2019
-
负责人:Mashatan, Atefeh
-
依托单位:
Quantum-Resistance and Efficiency of Communications in Connected and Autonomous Vehicles
-
批准号:536635-2018
-
项目类别:Collaborative Research and Development Grants
-
资助金额:$8.37万
-
财政年份:2019
-
负责人:Mashatan, Atefeh
-
依托单位:
Cryptographic Enhancing of Data Security in IoT Devices
-
批准号:RGPIN-2019-06150
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2019
-
负责人:Mashatan, Atefeh
-
依托单位:
Sizing the Y2Q Problem
-
批准号:543598-2019
-
项目类别:Engage Grants Program
-
资助金额:$1.82万
-
财政年份:2019
-
负责人:Mashatan, Atefeh
-
依托单位:
Finding more than one small solutions to multivariate polynomial equations
-
批准号:318887-2005
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$1.53万
-
财政年份:2006
-
负责人:Mashatan, Atefeh
-
依托单位:
Finding more than one small solutions to multivariate polynomial equations
-
批准号:318887-2005
-
项目类别:Postgraduate Scholarships - Doctoral
-
资助金额:$1.53万
-
财政年份:2005
-
负责人:Mashatan, Atefeh
-
依托单位:
PGSA
-
批准号:265687-2003
-
项目类别:Postgraduate Scholarships
-
资助金额:$1.53万
-
财政年份:2004
-
负责人:Mashatan, Atefeh
-
依托单位:
PGSA
-
批准号:265687-2003
-
项目类别:Postgraduate Scholarships
-
资助金额:$1.44万
-
财政年份:2003
-
负责人:Mashatan, Atefeh
-
依托单位:
海外基金