Ensuring End-to-End IoT Data Security and Privacy Through Cloud-Enhanced Confidential Computing

被引:0
|
作者
Islam, Md Shihabul [1 ]
Zamani, Mahmoud [1 ]
Hamlen, Kevin W. [1 ]
Khan, Latifur [1 ]
Kantarcioglu, Murat [1 ]
机构
[1] Univ Texas Dallas, Richardson, TX 75080 USA
关键词
IoT; Data Security and Privacy; Confidential Computing;
D O I
10.1007/978-3-031-65172-4_5
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
IoT devices gather data from the most intimate and sensitive aspects of our lives, transmitting it to untrusted cloud services for further managing and automating tasks through interconnecting smart devices without human intervention. To safeguard sensitive and private IoT data, solutions based on Trusted Execution Environments (Tees) could be utilized, providing end-to-end encrypted solution. Specifically, Tees securely process sensitive data within a protected area of the processor, isolated from the main operating system and applications, ensuring data confidentiality and integrity. However, in this study, we demonstrate that the end-to-end encryption offered by Tee based solutions for IoT devices may not be entirely sufficient. We present the first attack against Tee-based IoT solutions that can deduce sensitive information, such as a motion sensor reading, merely by analyzing memory access patterns. Our findings show that we can identify the type of device with about 95% accuracy and determine the values sent by IoT devices, like temperature readings, with approximately 85% accuracy. To counter these vulnerabilities, we design a system that enhances data security for IoT solutions in the untrusted cloud, using techniques like data oblivious execution and padding. With these defenses, we observe significant reduction in accuracy of device type detection and value prediction to at most 27% and 19%, respectively.
引用
收藏
页码:71 / 91
页数:21
相关论文
共 50 条
  • [41] End-to-End Security Methods for UDT Data Transmissions
    Bernardo, Danilo Valeros
    Hoang, Doan B.
    FUTURE GENERATION INFORMATION TECHNOLOGY, 2010, 6485 : 383 - 393
  • [42] Ensuring Security and Privacy Preservation for Cloud Data Services
    Tang, Jun
    Cui, Yong
    Li, Qi
    Ren, Kui
    Liu, Jiangchuan
    Buyya, Rajkumar
    ACM COMPUTING SURVEYS, 2016, 49 (01)
  • [43] Towards Dynamic End-to-End Privacy Preserving Data Classification
    Talbi, Rania
    Bouchenak, Sara
    Chen, Lydia Y.
    2018 48TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS WORKSHOPS (DSN-W), 2018, : 73 - 74
  • [44] A Secure End-to-End Cloud Computing Solution for Emergency Management with UAVs
    Liao, Qi
    Fischer, Thomas
    Gao, Jack
    Hafeez, Faisal
    Oechsner, Carl
    Knode, Jana
    2018 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2018,
  • [45] End-to-End Service Orchestration across SDN and Cloud Computing Domains
    Bonafiglia, Roberto
    Castellano, Gabriele
    Cerrato, Ivano
    Risso, Fulvio
    2017 IEEE CONFERENCE ON NETWORK SOFTWARIZATION (IEEE NETSOFT), 2017,
  • [46] Enforcing End-to-End Application Security in the Cloud (Big Ideas Paper)
    Bacon, Jean
    Evans, David
    Eyers, David M.
    Migliavacca, Matteo
    Pietzuch, Peter
    Shand, Brian
    MIDDLEWARE 2010, 2010, 6452 : 293 - +
  • [47] A Privacy-Preserving Data Aggregation Scheme for Fog/Cloud-Enhanced IoT Applications Using a Trusted Execution Environment
    Will, Newton Carlos
    SYSCON 2022: THE 16TH ANNUAL IEEE INTERNATIONAL SYSTEMS CONFERENCE (SYSCON), 2022,
  • [48] Holistic Explainability Requirements for End-to-End Machine Learning in IoT Cloud Systems
    My-Linh Nguyen
    Thao Phung
    Duong-Hai Ly
    Hong-Linh Truong
    29TH IEEE INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS (REW 2021), 2021, : 188 - 194
  • [49] Ensuring attribute privacy protection and fast decryption for outsourced data security in mobile cloud computing
    Zhang, Yinghui
    Chen, Xiaofeng
    Li, Jin
    Wong, Duncan S.
    Li, Hui
    You, Ilsun
    INFORMATION SCIENCES, 2017, 379 : 42 - 61
  • [50] End-to-end security validation of IoT systems based on digital twins of end-devices
    Maillet-Contoz, Laurent
    Michel, Emmanuel
    Nava, Mario Diaz
    Brun, Paul-Emmanuel
    Lepretre, Kevin
    Massot, Guillemette
    2020 GLOBAL INTERNET OF THINGS SUMMIT (GIOTS), 2020,