A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks

被引:0
|
作者
Yan-Hong Fan
Mei-Qin Wang
Yan-Bin Li
Kai Hu
Mu-Zhou Li
机构
[1] Shandong University,School of Cyber Science and Technology
[2] Ministry of Education,Key Laboratory of Cryptologic Technology and Information Security (Shandong University)
关键词
Internet of Things; firmware update; authenticated encryption; side-channel power analysis; denial of service;
D O I
暂无
中图分类号
学科分类号
摘要
In the IEEE S&P 2017, Ronen et al. exploited side-channel power analysis (SCPA) and approximately 5 000 power traces to recover the global AES-CCM key that Philip Hue lamps use to decrypt and authenticate new firmware. Based on the recovered key, the attacker could create a malicious firmware update and load it to Philip Hue lamps to cause Internet of Things (IoT) security issues. Inspired by the work of Ronen et al., we propose an AES-CCM-based firmware update scheme against SCPA and denial of service (DoS) attacks. The proposed scheme applied in IoT terminal devices includes two aspects of design (i.e., bootloader and application layer). Firstly, in the bootloader, the number of updates per unit time is limited to prevent the attacker from acquiring a sufficient number of useful traces in a short time, which can effectively counter an SCPA attack. Secondly, in the application layer, using the proposed handshake protocol, the IoT device can access the IoT server to regain update permission, which can defend against DoS attacks. Moreover, on the STM32F405+M25P40 hardware platform, we implement Philips’ and the proposed modified schemes. Experimental results show that compared with the firmware update scheme of Philips Hue smart lamps, the proposed scheme additionally requires only 2.35 KB of Flash memory and a maximum of 0.32 s update time to effectively enhance the security of the AES-CCM-based firmware update process.
引用
收藏
页码:419 / 433
页数:14
相关论文
共 50 条
  • [1] A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks
    Fan, Yan-Hong
    Wang, Mei-Qin
    Li, Yan-Bin
    Hu, Kai
    Li, Mu-Zhou
    [J]. JOURNAL OF COMPUTER SCIENCE AND TECHNOLOGY, 2021, 36 (02) : 419 - 433
  • [2] A new biometric identity based encryption scheme secure against DoS attacks
    Sarier, Neyire Deniz
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2011, 4 (01) : 23 - 32
  • [3] A Secure IoT Firmware Update Framework Based on MQTT Protocol
    Lo, Nai-Wei
    Hsu, Sheng-Hsiang
    [J]. INFORMATION SYSTEMS ARCHITECTURE AND TECHNOLOGY, ISAT 2019, PT I, 2020, 1050 : 187 - 198
  • [4] A Highly Secure IoT Firmware Update Mechanism Using Blockchain
    Tsaur, Woei-Jiunn
    Chang, Jen-Chun
    Chen, Chin-Ling
    [J]. SENSORS, 2022, 22 (02)
  • [5] SOFTWARE IMPLEMENTATION OF A SECURE FIRMWARE UPDATE SOLUTION IN AN IOT CONTEXT
    Kvarda, Lukas
    Hnyk, Pavel
    Vojtech, Lukas
    Lokaj, Zdenek
    Neruda, Marek
    Zitta, Tomas
    [J]. ADVANCES IN ELECTRICAL AND ELECTRONIC ENGINEERING, 2016, 14 (04) : 389 - 396
  • [6] Toward a generic and secure bootloader for IoT device firmware OTA update
    El Jaouhari, Saad
    Bouvet, Eric
    [J]. 36TH INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING (ICOIN 2022), 2022, : 90 - 95
  • [7] MlPv6 binding update protocol secure against both redirect and DoS attacks
    Kang, HS
    Park, CS
    [J]. INFORMATION SECURITY AND CRYPTOLOGY, PROCEEDINGS, 2005, 3822 : 407 - 418
  • [8] Secure SCTP against DoS attacks in wireless Internet
    Joe, Inwhee
    [J]. Network Control and Engineering for QoS, Security and Mobility, V, 2006, 213 : 65 - 74
  • [9] FOTB: a secure blockchain-based firmware update framework for IoT environment
    Alexander Yohan
    Nai-Wei Lo
    [J]. International Journal of Information Security, 2020, 19 : 257 - 278
  • [10] Secure and efficient firmware update for increasing IoT-enabled smart devices
    Lu, Ching-Hu
    Liu, Chi-Hsien
    Chen, Zhi-Hong
    [J]. JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2020, 14 (5) : 4987 - 5000