Cryptographic Enhancing of Data Security in IoT Devices
Cryptographic Enhancing of Data Security in IoT Devices
批准号:
RGPIN-2019-06150
负责人:
Mashatan, Atefeh(Atty)
金额:
$2.04万
依托单位:
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2021
资助国家:
加拿大
项目状态:
已结题
起止时间:
2021-01-01 至 2022-12-31
中文摘要
物联网(Internet-of-Things)正在彻底改变我们的生活,它使日常物品相互连接并自主通信。物联网设备处理的数据可能是隐私敏感的(例如,在智能医疗的情况下),也可能是安全关键的(例如,在智能制造的情况下),从而引发严重的信息安全问题。本研究计划的总体目标是设计、分析和实施端到端的物联网安全和隐私解决方案,重点是(a)物联网系统中数据保护的寿命和(b)不同物联网设备之间物联网数据的不同灵敏度级别。作为这项研究计划的结果,我们将为可证明安全的系统提供强大而实用的实现,反过来,增强物联网系统用户的上下文隐私和安全性。我们将通过识别物联网场景中数据完整性和机密性方面的挑战,并通过设计新方案来解决这些挑战,从而实现这一目标。然后,我们通过概念验证实现来补充我们的发现,并进一步将其开发为端到端软件包,为标准化和行业部署做好准备。物联网设备变得越来越智能,包含更多关于我们的安全关键和隐私敏感信息,同时变得越来越小,这使它们成为攻击者非常有吸引力的目标。智能设备的小型化在为普适计算提供巨大机遇的同时,也带来了许多安全和隐私问题,因为传统的数字信息保护机制已不再适用。因此,物联网无法承担复杂的算法和对轻量级替代方案的需求。我们将研究开发安全协议的新技术和方法,这些协议足够轻量,可以用于物联网中的小型传感器,同时提供足够的上下文安全和隐私保证。另一个挑战是保密要求的持久性。许多物联网设备的预期使用寿命超过十年,或者存储的信息本应保密数十年。这使它们处于量子计算威胁的范围内,目前标准化的公钥方案不再安全。虽然目前存在抗量子解决方案,但它们尚未标准化,而且对于许多物联网场景来说,它们肯定不够轻量化。我们将研究为物联网设备设计可扩展的抗量子解决方案的新方法,并以灵活的方式设计和实现它们,提供加密敏捷性。物联网的另一个痛点是高效和可扩展的消息和设备身份验证,这通常通过安全管理加密密钥和凭据来实现。这些技术高度依赖于公钥加密,这是昂贵的,而且对于许多物联网设置来说是不可扩展的。我们将提出解决消息和设备认证的替代技术。
英文摘要
Internet-of-Things, where everyday objects are all connected and autonomously communicate with one another, is revolutionizing our lives. The data handled by the IoT devices can be privacy-sensitive, e.g., in the case of smart healthcare, and safety-critical, e.g., in the case of smart manufacturing, giving rise to serious information security concerns. The overarching goal of this research program is to design, analyze and implement end-to-end IoT security and privacy solutions, with an emphasis on (a) longevity of data protection in the IoT systems and (b) varying sensitivity levels of the IoT data among different IoT devices. As a result of this research program, we will produce robust and practical implementations of provably secure systems and, in turn, enhance the contextual privacy and security of users of IoT systems. We will achieve this goal by identifying the challenges with respect to integrity and confidentiality of data in IoT scenarios and addressing them by designing new schemes. Then, we complement our findings with a proof-of-concept implementation and further develop it to an end-to-end package which is ready for standardization and deployment in the industry. IoT devices are getting smarter and contain more safety-critical and privacy-sensitive information about us while becoming smaller - making them a very appealing target for attackers. While providing a great opportunity for ubiquitous computing, the miniaturization of smart devices brings many security and privacy concerns as the traditional mechanisms for safeguarding digital information are no longer adequate. As a result, IoT cannot afford complex algorithms and demands for lightweight alternatives. We will investigate new techniques and approaches for developing security protocols that are lightweight enough to be used in a small sensor in IoT while at the same time provide adequate and contextual security and privacy guarantees. Another challenge is longevity of the confidentiality requirement. Many IoT devices are deployed with life expectancy of more than a decade or are storing information that are meant to remain confidential for decades. This brings them in the scope of the quantum computing threat where currently standardized public-key schemes are no longer secure. While quantum-resistant solutions currently exist, they are not yet standardized and definitely not lightweight enough for many IoT scenarios. We will investigate new approaches in designing scalable quantum-resistant solutions for IoT devices and design and implement them in a flexible manner providing crypto-agility. One other IoT pain point is efficient and scalable message and device authentication which are typically achieved by secure management of cryptographic keys and credentials. These techniques are highly relying on public-key cryptography which are expensive and not scalable for many IoT settings. We will propose alternative techniques to address message and device authentication.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Cryptographic Enhancing of Data Security in IoT Devices
-
批准号:RGPIN-2019-06150
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$2.04万
-
财政年份:2022
-
负责人:Mashatan, Atefeh(Atty)
-
依托单位:
Quality of Security (QoSec) Framework for Internet-of-Things (IoT)
-
批准号:CRC-2020-00017
-
项目类别:Canada Research Chairs
-
资助金额:$8.74万
-
财政年份:2022
-
负责人:Mashatan, Atefeh(Atty)
-
依托单位:
Quality Of Security (Qosec) Framework For Internet-Of-Things (Iot)
-
批准号:CRC-2020-00017
-
项目类别:Canada Research Chairs
-
资助金额:$6.92万
-
财政年份:2021
-
负责人:Mashatan, Atefeh(Atty)
-
依托单位:
海外基金