Secure Firmware Validation and Update for Consumer Devices in Home Networking

被引:1
|
作者
Choi, Byung-Chul [1 ]
Lee, Seoung-Hyeon [1 ]
Na, Jung-Chan [1 ]
Lee, Jong-Hyouk [2 ]
机构
[1] Elect & Telecommun Res Inst, Daejeon, South Korea
[2] Sangmyung Univ, Dept Comp Sci & Engn, Cheonan, South Korea
关键词
Firmware validation; authentication; integrity; security analysis; PROTOCOL;
D O I
10.1109/tce.2016.7448561
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Embedded systems are more than ever present in consumer electronics devices such as home routers, personal computers, smartphones, smartcards, various sensors to name a few. Firmware, which is embedded software specifically designed for monitoring and control in resource constrained conditions, was not a major attack target. However, recent serious cyber attacks focus on firmware rather than application or operating system levels, because exploiting the firmware level offers stealth capabilities, e.g., anti-virus software and operating system cannot reveal such a firmware level exploit. A firmware validation that ensures firmware integrity is thus required to detect firmware tempering attacks. A remote firmware update is also required for consumer devices connected to the Internet. In this paper, a secure firmware validation and update scheme is introduced for consumer devices in a home networking environment. The proposed scheme utilizes an ID-based mutual authentication and key derivation to securely distribute a firmware image. A firmware fragmentation with hash chaining is also applied to guarantee authenticity of the fragmented firmware image. Security analysis results are presented while considerations are discussed(1).
引用
收藏
页码:39 / 44
页数:6
相关论文
共 50 条
  • [31] FOTB: a secure blockchain-based firmware update framework for IoT environment
    Yohan, Alexander
    Lo, Nai-Wei
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2020, 19 (03) : 257 - 278
  • [32] Efficient Partial Firmware Update for IoT Devices with Lua Scripting Interface
    Novak, Marek
    Skryja, Petr
    [J]. 2019 29TH INTERNATIONAL CONFERENCE RADIOELEKTRONIKA (RADIOELEKTRONIKA), 2019, : 313 - 316
  • [33] A Nimble Decompression Algorithm for ZigBee Firmware Update in Smart Home Environment
    Feng, Tuo
    Yang, Kun
    [J]. 2017 14TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2017, : 630 - 631
  • [34] Blockchain-Based Distributed Firmware Update Architecture for IoT Devices
    Choi, Seoyun
    Lee, Jong-Hyouk
    [J]. IEEE ACCESS, 2020, 8 : 37518 - 37525
  • [35] A security framework for secure home networking in ubiquitous computing
    Lee, Woon-Gu
    Chae, Cheol-Joo
    Kim, Sang-Kuk
    Kang, Mu-Yeong
    Lee, Jae-Kwang
    [J]. 2007 INTERNATIONAL CONFERENCE ON INTELLIGENT PERVASIVE COMPUTING, PROCEEDINGS, 2007, : 394 - 397
  • [36] Secure Personal Content Networking Over Untrusted Devices
    Uichin Lee
    Joshua Joy
    YoungTae Noh
    [J]. Wireless Personal Communications, 2015, 80 : 1449 - 1473
  • [37] Secure Personal Content Networking Over Untrusted Devices
    Lee, Uichin
    Joy, Joshua
    Noh, YoungTae
    [J]. WIRELESS PERSONAL COMMUNICATIONS, 2015, 80 (04) : 1449 - 1473
  • [38] Secure User Identification for Consumer Electronics Devices
    Lee, Hyejeong
    Lee, Sang-Ho
    Kim, Taeseok
    Bahn, Hyokyung
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2008, 54 (04) : 1798 - 1802
  • [39] IoT Smart Home Devices' Security, Privacy, and Firmware Labeling System
    Rajkhan, Naif Waheb
    Song, Jia
    [J]. 2021 INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND COMPUTATIONAL INTELLIGENCE (CSCI 2021), 2021, : 1874 - 1880
  • [40] Standards update on devices for the digital home
    Griffis, P
    [J]. ICCE: 2005 INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, DIGEST OF TECHNICAL PAPERS, 2005, : 19 - 19