A Secure IoT Firmware Update Scheme Against SCPA and DoS Attacks

被引:0
|
作者
Yan-Hong Fan
Mei-Qin Wang
Yan-Bin Li
Kai Hu
Mu-Zhou Li
机构
[1] Shandong University,School of Cyber Science and Technology
[2] Ministry of Education,Key Laboratory of Cryptologic Technology and Information Security (Shandong University)
关键词
Internet of Things; firmware update; authenticated encryption; side-channel power analysis; denial of service;
D O I
暂无
中图分类号
学科分类号
摘要
In the IEEE S&P 2017, Ronen et al. exploited side-channel power analysis (SCPA) and approximately 5 000 power traces to recover the global AES-CCM key that Philip Hue lamps use to decrypt and authenticate new firmware. Based on the recovered key, the attacker could create a malicious firmware update and load it to Philip Hue lamps to cause Internet of Things (IoT) security issues. Inspired by the work of Ronen et al., we propose an AES-CCM-based firmware update scheme against SCPA and denial of service (DoS) attacks. The proposed scheme applied in IoT terminal devices includes two aspects of design (i.e., bootloader and application layer). Firstly, in the bootloader, the number of updates per unit time is limited to prevent the attacker from acquiring a sufficient number of useful traces in a short time, which can effectively counter an SCPA attack. Secondly, in the application layer, using the proposed handshake protocol, the IoT device can access the IoT server to regain update permission, which can defend against DoS attacks. Moreover, on the STM32F405+M25P40 hardware platform, we implement Philips’ and the proposed modified schemes. Experimental results show that compared with the firmware update scheme of Philips Hue smart lamps, the proposed scheme additionally requires only 2.35 KB of Flash memory and a maximum of 0.32 s update time to effectively enhance the security of the AES-CCM-based firmware update process.
引用
收藏
页码:419 / 433
页数:14
相关论文
共 50 条
  • [41] An Over-the-Blockchain Firmware Update Framework for IoT Devices
    Yohan, Alexander
    Lo, Nai-Wei
    [J]. 2018 IEEE CONFERENCE ON DEPENDABLE AND SECURE COMPUTING (DSC), 2018, : 22 - 29
  • [42] Efficient and Secure Firmware Update/Rollback Method for Vehicular Devices
    Komano, Yuichi
    Xia, Zhengfan
    Kawabata, Takeshi
    Shimizu, Hideo
    [J]. INFORMATION SECURITY PRACTICE AND EXPERIENCE (ISPEC 2018), 2018, 11125 : 455 - 467
  • [43] Secure LoRa Firmware Update with Adaptive Data Rate Techniques
    Heeger, Derek
    Garigan, Maeve
    Eleni Tsiropoulou, Eirini
    Plusquellic, Jim
    [J]. SENSORS, 2021, 21 (07)
  • [44] Secure Firmware Validation and Update for Consumer Devices in Home Networking
    Choi, Byung-Chul
    Lee, Seoung-Hyeon
    Na, Jung-Chan
    Lee, Jong-Hyouk
    [J]. IEEE TRANSACTIONS ON CONSUMER ELECTRONICS, 2016, 62 (01) : 39 - 44
  • [45] Blockchain-Based Secure Firmware Update Using an UAV
    Seo, Jong Wan
    Islam, Anik
    Masuduzzaman, Md
    Shin, Soo Young
    [J]. ELECTRONICS, 2023, 12 (10)
  • [46] Over-the-air firmware update for IoT devices on the wild
    Berriel de Sousa, Maria Julia
    Gomez Gonzalez, Luis Fernando
    Ferdinando, Erick Mascagni
    Borin, Juliana Freitag
    [J]. INTERNET OF THINGS, 2022, 19
  • [47] Defend GPUs Against DoS Attacks
    Zhang, Wei
    [J]. 2013 IEEE 32ND INTERNATIONAL PERFORMANCE COMPUTING AND COMMUNICATIONS CONFERENCE (IPCCC), 2013,
  • [48] Secure firmware validation and update for consumer devices in home networking
    Choi B.-C.
    Lee S.-H.
    Na J.-C.
    Lee J.-H.
    [J]. IEEE Trans Consum Electron, 1 (39-44): : 39 - 44
  • [49] On the Robustness of SCTP against DoS Attacks
    Rathgeb, Erwin P.
    Hohendorf, Carsten
    Nordhoff, Michael
    [J]. Third 2008 International Conference on Convergence and Hybrid Information Technology, Vol 2, Proceedings, 2008, : 1144 - 1149
  • [50] SECOD: SDN sEcure COntrol and Data Plane Algorithm for Detecting and Defending against DoS Attacks
    Wang, Song
    Chandrasekharan, Sathyanarayanan
    Gomez, Karina
    Kandeepan, Sithamparanathan
    Al-Hourani, Akram
    Asghar, Muhammad Rizwan
    Russello, Giovanni
    Zanna, Paul
    [J]. NOMS 2018 - 2018 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM, 2018,