Security Analysis of Out-of-Band Device Pairing Protocols: A Survey

被引:2
|
作者
Khalfaoui, Sameh [1 ,2 ]
Leneutre, Jean [1 ]
Villard, Arthur [2 ]
Ma, Jingxuan [2 ]
Urien, Pascal [1 ]
机构
[1] Inst Polytech Paris, Telecom Paris, LTCI, Paris, France
[2] EDF R&D, Paris, France
来源
WIRELESS COMMUNICATIONS & MOBILE COMPUTING | 2021年 / 2021卷
关键词
SENSOR NETWORKS; KEY AGREEMENT; AUTHENTICATION; CHANNELS; ATTACK;
D O I
10.1155/2021/8887472
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Numerous secure device pairing (SDP) protocols have been proposed to establish a secure communication between unidentified IoT devices that have no preshared security parameters due to the scalability requirements imposed by the ubiquitous nature of the IoT devices. In order to provide the most user-friendly IoT services, the usability assessment has become the main requirement. Thus, the complete security analysis has been replaced by a sketch of a proof to partially validate the robustness of the proposal. The few existing formal or computational security verifications on the SDP schemes have been conducted based on the assessment of a wide variety of uniquely defined security properties. Therefore, the security comparison between these protocols is not feasible and there is a lack of a unified security analysis framework to assess these pairing techniques. In this paper, we survey a selection of secure device pairing proposals that have been formally or computationally verified. We present a systematic description of the protocol assumptions, the adopted verification model, and an assessment of the verification results. In addition, we normalize the used taxonomy in order to enhance the understanding of these security validations. Furthermore, we refine the adversary capabilities on the out-of-band channel by redefining the replay capability and by introducing a new notion of delay that is dependent on the protocol structure that is more adequate for the ad hoc pairing context. Also, we propose a classification of a number of out-of-band channels based on their security properties and under our refined adversary model. Our work motivates the future SDP protocol designer to conduct a formal or a computational security assessment to allow the comparability between these pairing techniques. Furthermore, it provides a realistic abstraction of the adversary capabilities on the out-of-band channel which improves the modeling of their security characteristics in the protocol verification tools.
引用
收藏
页数:30
相关论文
共 50 条
  • [11] Security enhancement of out-of-band remote management in IaaS clouds
    Egawa, Tomohisa
    Nishimura, Naoki
    Kourai, Kenichi
    IPSJ Online Transactions, 2013, 6 (2013) : 111 - 120
  • [12] Formal Analysis of Secure Device Pairing Protocols
    Nguyen, Trung
    Leneutre, Jean
    2014 IEEE 13TH INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS (NCA 2014), 2014, : 291 - 295
  • [13] Out-of-Band Concealment on Android
    Wong, Zhi-hao
    Wei, Jun-sheng
    Ma, Rui
    COMPUTER SCIENCE AND TECHNOLOGY (CST2016), 2017, : 29 - 35
  • [14] Out-of-band quasiseparable matrices
    Eidelman, Y.
    Gohberg, I.
    LINEAR ALGEBRA AND ITS APPLICATIONS, 2008, 429 (01) : 266 - 289
  • [15] WideScan: Exploiting Out-of-Band Distortion for Device Classification Using Deep Learning
    Elmaghbub, Abdurrahman
    Hamdaoui, Bechir
    Natarajan, Arun
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,
  • [16] Secure and Usable Out-Of-Band Channels for Ad Hoc Mobile Device Interactions
    Kainda, Ronald
    Flechais, Ivan
    Roscoe, A. W.
    INFORMATION SECURITY THEORY AND PRACTICES: SECURITY AND PRIVACY OF PERVASIVE SYSTEMS AND SMART DEVICES, 2010, 6033 : 308 - 315
  • [17] Out-of-Band Ambiguity Analysis of Nonuniformly Sampled SAR Signals
    Zhu, Zhenqian
    Zhang, Zhimin
    Wang, Robert
    Guo, Lei
    IEEE GEOSCIENCE AND REMOTE SENSING LETTERS, 2014, 11 (12) : 2027 - 2031
  • [18] Compensating out-of-band nonlinear distortions
    Van Moer, Wendy
    Pintelon, Rik
    2010 IEEE INTERNATIONAL INSTRUMENTATION AND MEASUREMENT TECHNOLOGY CONFERENCE I2MTC 2010, PROCEEDINGS, 2010,
  • [19] Survey on out-of-band failure localization in all-optical mesh networks
    János Tapolcai
    Telecommunication Systems, 2014, 56 : 169 - 176
  • [20] Out-of-band power suppression in OFDM
    van de Beek, Jaap
    Berggren, Fredrik
    IEEE COMMUNICATIONS LETTERS, 2008, 12 (09) : 609 - 611