Secure Firmware Validation and Update for Consumer Devices in Home Networking

被引:1
|
作者
Choi, Byung-Chul [1 ]
Lee, Seoung-Hyeon [1 ]
Na, Jung-Chan [1 ]
Lee, Jong-Hyouk [2 ]
机构
[1] Elect & Telecommun Res Inst, Daejeon, South Korea
[2] Sangmyung Univ, Dept Comp Sci & Engn, Cheonan, South Korea
关键词
Firmware validation; authentication; integrity; security analysis; PROTOCOL;
D O I
10.1109/tce.2016.7448561
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Embedded systems are more than ever present in consumer electronics devices such as home routers, personal computers, smartphones, smartcards, various sensors to name a few. Firmware, which is embedded software specifically designed for monitoring and control in resource constrained conditions, was not a major attack target. However, recent serious cyber attacks focus on firmware rather than application or operating system levels, because exploiting the firmware level offers stealth capabilities, e.g., anti-virus software and operating system cannot reveal such a firmware level exploit. A firmware validation that ensures firmware integrity is thus required to detect firmware tempering attacks. A remote firmware update is also required for consumer devices connected to the Internet. In this paper, a secure firmware validation and update scheme is introduced for consumer devices in a home networking environment. The proposed scheme utilizes an ID-based mutual authentication and key derivation to securely distribute a firmware image. A firmware fragmentation with hash chaining is also applied to guarantee authenticity of the fragmented firmware image. Security analysis results are presented while considerations are discussed(1).
引用
收藏
页码:39 / 44
页数:6
相关论文
共 50 条
  • [21] A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks
    Yan-Hong Fan
    Mei-Qin Wang
    Yan-Bin Li
    Kai Hu
    Mu-Zhou Li
    [J]. Journal of Computer Science and Technology, 2021, 36 : 419 - 433
  • [22] Toward a generic and secure bootloader for IoT device firmware OTA update
    El Jaouhari, Saad
    Bouvet, Eric
    [J]. 36TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2022), 2022, : 90 - 95
  • [23] A Blockchain-Based OCF Firmware Update for IoT Devices †
    Witanto, Elizabeth Nathania
    Oktian, Yustus Eko
    Lee, Sang-Gon
    Lee, Jin-Heung
    [J]. APPLIED SCIENCES-BASEL, 2020, 10 (19): : 1 - 22
  • [24] PHACOEMULSIFICATION DEVICES - A CONSUMER UPDATE
    NEUMANN, AC
    MOLYET, E
    TEAL, C
    MCCARTY, G
    [J]. JOURNAL OF CATARACT AND REFRACTIVE SURGERY, 1987, 13 (06): : 669 - 677
  • [25] A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks
    Fan, Yan-Hong
    Wang, Mei-Qin
    Li, Yan-Bin
    Hu, Kai
    Li, Mu-Zhou
    [J]. JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2021, 36 (02) : 419 - 433
  • [26] An Over-the-Blockchain Firmware Update Framework for IoT Devices
    Yohan, Alexander
    Lo, Nai-Wei
    [J]. 2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 22 - 29
  • [27] Over-the-air firmware update for IoT devices on the wild
    Berriel de Sousa, Maria Julia
    Gomez Gonzalez, Luis Fernando
    Ferdinando, Erick Mascagni
    Borin, Juliana Freitag
    [J]. INTERNET OF THINGS, 2022, 19
  • [28] Networking home entertainment devices with HAVi
    Lea, R
    Gibbs, S
    Dara-Abrams, A
    Eytchison, E
    [J]. COMPUTER, 2000, 33 (09) : 35 - +
  • [29] Jini and network-enabled devices - Networking consumer devices
    Wong, H
    [J]. DR DOBBS JOURNAL, 1999, 24 (07): : 21 - +
  • [30] FOTB: a secure blockchain-based firmware update framework for IoT environment
    Alexander Yohan
    Nai-Wei Lo
    [J]. International Journal of Information Security, 2020, 19 : 257 - 278