Skip to main content
QUICK REVIEW

[論文レビュー] Shake-n-Shack: Enabling Secure Data Exchange Between Smart Wearables via Handshakes

Yiran Shen, Fengyuan Yang|arXiv (Cornell University)|Jan 23, 2018
User Authentication and Security Systems参考文献 14被引用数 3
ひとこと要約

Shake-n-Shack は、手のひらの動きのパターンを介してスマートウォッチ間で安全で軽量な鍵交換プロトコルを実現し、追加のハードウェアやユーザーの操作なしに自動的かつ使いやすいデータ共有を可能にします。1.6% の等価誤り率(EER)で模倣攻撃に対抗しながら、2秒未満で99% の鍵生成成功率を達成し、市販のデバイスでも効率的に動作します。

ABSTRACT

Since ancient Greece, handshaking has been commonly practiced between two people as a friendly gesture to express trust and respect, or form a mutual agreement. In this paper, we show that such physical contact can be used to bootstrap secure cyber contact between the smart devices worn by users. The key observation is that during handshaking, although belonged to two different users, the two hands involved in the shaking events are often rigidly connected, and therefore exhibit very similar motion patterns. We propose a novel Shake-n-Shack system, which harvests motion data during user handshaking from the wrist worn smart devices such as smartwatches or fitness bands, and exploits the matching motion patterns to generate symmetric keys on both parties. The generated keys can be then used to establish a secure communication channel for exchanging data between devices. This provides a much more natural and user-friendly alternative for many applications, e.g. exchanging/sharing contact details, friending on social networks, or even making payments, since it doesn't involve extra bespoke hardware, nor require the users to perform pre-defined gestures. We implement the proposed Shake-n-Shack system on off-the-shelf smartwatches, and extensive evaluation shows that it can reliably generate 128-bit symmetric keys just after around 1s of handshaking (with success rate >99%), and is resilient to real-time mimicking attacks: in our experiments the Equal Error Rate (EER) is only 1.6% on average. We also show that the proposed Shake-n-Shack system can be extremely lightweight, and is able to run in-situ on the resource-constrained smartwatches without incurring excessive resource consumption.

研究の動機と目的

  • 異なるユーザーが着用するスマートウォッチ間で、自然なハンドシェイク中に安全で手間のかからないデータ交換を可能にすること。
  • ハンドシェイク中に腕に装着されたデバイスからキャプチャした運動信号を用いて、暗号的に強固な対称鍵を生成すること。
  • クラウドインfraや追加のハードウェアに依存せずに、模倣攻撃に対して耐性を持つこと。
  • リソース制約のあるスマートウォッチ上で、過度なバッテリー消費を伴わずに現地実行可能なほど軽量なシステムを設計すること。

提案手法

  • ハンドシェイク中に、2台の腕に装着されたスマートウォッチの加速度計から同期された運動データを取得する。
  • 物理的に固定された手の動きの特徴を活用して、2台のデバイス間の運動パターンを抽出・整列させ、信号の類似性を保証する。
  • 共通の量子化および鍵再結合技術を適用し、両端で128ビットの対称鍵を一致させる。
  • 生成された対称鍵を用いて、安全な無線通信チャネルを確立し、データ交換を実現する。
  • 実用的実装のため、市販のスマートウォッチ(例:Samsung Galaxy Watch、Apple Watch)にシステムを実装する。
  • 計算およびエネルギー消費を最小限に抑えるために、軽量なプロトコルスタックを採用する。

実験結果

リサーチクエスチョン

  • RQ1ハンドシェイク中の2つの手の運動信号を用いて、別々のスマートウォッチ上で暗号的に安全な一致する鍵を生成できるか?
  • RQ2環境ノイズやユーザー固有の運動変動に対して、鍵生成プロセスはどの程度頑健か?
  • RQ3攻撃者がハンドシェイクのパターンを模倣しようとする場合、このシステムはどの程度耐性を示せるか?
  • RQ4外部依存なしに、低消費電力でリソース制約のあるスマートウォッチ上でリアルタイムに効率的に動作できるか?

主な発見

  • システムは、ハンドシェイク開始後約1秒で128ビットの対称鍵を99%以上の成功率で生成できた。
  • リアルタイムの模倣攻撃耐性テストにおいて、等価誤り率(EER)がたった1.6%にとどまり、高いセキュリティを示した。
  • システムは市販のスマートウォッチ上で現地実行され、計算リソースおよびエネルギー消費が最小限に抑えられた。
  • ハンドシェイク中の2つの手の運動パターンの類似度は、異なるユーザー間でも信頼性の高い鍵同意を可能にするほど十分に高い。
  • 特にクラウド認証や専用ハードウェアに依存しない点を除き、既存のソリューションに比べて使いやすさ、セキュリティ、効率性の面で優れている。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。