Secure Firmware Validation and Update for Consumer Devices in Home Networking

被引:1
|
作者
Choi, Byung-Chul [1 ]
Lee, Seoung-Hyeon [1 ]
Na, Jung-Chan [1 ]
Lee, Jong-Hyouk [2 ]
机构
[1] Elect & Telecommun Res Inst, Daejeon, South Korea
[2] Sangmyung Univ, Dept Comp Sci & Engn, Cheonan, South Korea
关键词
Firmware validation; authentication; integrity; security analysis; PROTOCOL;
D O I
10.1109/tce.2016.7448561
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Embedded systems are more than ever present in consumer electronics devices such as home routers, personal computers, smartphones, smartcards, various sensors to name a few. Firmware, which is embedded software specifically designed for monitoring and control in resource constrained conditions, was not a major attack target. However, recent serious cyber attacks focus on firmware rather than application or operating system levels, because exploiting the firmware level offers stealth capabilities, e.g., anti-virus software and operating system cannot reveal such a firmware level exploit. A firmware validation that ensures firmware integrity is thus required to detect firmware tempering attacks. A remote firmware update is also required for consumer devices connected to the Internet. In this paper, a secure firmware validation and update scheme is introduced for consumer devices in a home networking environment. The proposed scheme utilizes an ID-based mutual authentication and key derivation to securely distribute a firmware image. A firmware fragmentation with hash chaining is also applied to guarantee authenticity of the fragmented firmware image. Security analysis results are presented while considerations are discussed(1).
引用
收藏
页码:39 / 44
页数:6
相关论文
共 50 条
  • [41] Secure Code Update for Embedded Devices via Proofs of Secure Erasure
    Perito, Daniele
    Tsudik, Gene
    [J]. COMPUTER SECURITY-ESORICS 2010, 2010, 6345 : 643 - 662
  • [42] Secure Firmware Updates for Constrained IoT Devices Using Open Standards: A Reality Check
    Zandberg, Koen
    Schleiser, Kaspar
    Acosta, Francisco
    Tschofenig, Hannes
    Baccelli, Emmanuel
    [J]. IEEE ACCESS, 2019, 7 : 71907 - 71920
  • [43] SPIN: Enabling secure and pervasive inter-home networking
    Sethom, Kaouthar
    Pujolle, Guy
    [J]. 2007 IEEE 18TH INTERNATIONAL SYMPOSIUM ON PERSONAL, INDOOR AND MOBILE RADIO COMMUNICATIONS, VOLS 1-9, 2007, : 1383 - 1387
  • [44] Light Flash Write for Efficient Firmware Update on Energy-harvesting IoT Devices
    Liu, Songran
    Lv, Mingsong
    Zhang, Wei
    Jiang, Xu
    Gu, Chuancai
    Yang, Tao
    Yi, Wang
    Guan, Nan
    [J]. 2023 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION, DATE, 2023,
  • [45] Trustworthy Firmware Update for Internet-of-Thing Devices Using Physical Unclonable Functions
    Prada-Delgado, M. A.
    Vazquez-Reyes, A.
    Baturone, I.
    [J]. 2017 GLOBAL INTERNET OF THINGS SUMMIT (GIOTS 2017), 2017, : 427 - 431
  • [46] FSMFA: Efficient firmware-secure multi-factor authentication protocol for IoT devices
    Chen, Zigang
    Cheng, Zhiquan
    Luo, Wenjun
    Ao, Jin
    Liu, Yuhong
    Sheng, Kai
    Chen, Long
    [J]. INTERNET OF THINGS, 2023, 21
  • [47] Cost optimization of secure routing with untrusted devices in software defined networking
    Yazdinejad, Abbas
    Parizi, Reza M.
    Dehghantanha, Ali
    Srivastava, Gautam
    Mohan, Senthilkumar
    Rababah, Abedallah M.
    [J]. JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2020, 143 : 36 - 46
  • [48] Secure discovery method of devices for a home network middleware
    Kim, DW
    Kim, GW
    Lee, JH
    Han, JW
    [J]. 8TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY, VOLS 1-3: TOWARD THE ERA OF UBIQUITOUS NETWORKS AND SOCIETIES, 2006, : U1733 - U1735
  • [49] An Enhanced Passivation Layer for Secure Consumer Integrated Circuit Devices
    Bruce, Ndibanje
    Lee, Hoon Jae
    [J]. 2014 IEEE 3RD GLOBAL CONFERENCE ON CONSUMER ELECTRONICS (GCCE), 2014, : 300 - 301
  • [50] Mobility Management for Mobile Consumer Devices in Content Centric Networking (CCN)
    Lee, Jihoon
    Kim, DaeYoub
    Jang, Myeongwuk
    Lee, Byoung-joon
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS (ICCE), 2012, : 502 - +