Skip to main content
QUICK REVIEW

[논문 리뷰] Hash-MAC-DSDV: Mutual Authentication for Intelligent IoT-Based Cyber-Physical Systems

Muhammad Adil, Mian Ahmad Jan|arXiv (Cornell University)|2021. 05. 17.
Advanced Authentication Protocols Security인용 수 4
한 줄 요약

이 논문은 DSDV 라우팅과 MAC 주소 해시, 블록체인 유사 로컬/공개 체인을 사용하여 IoT 기반 사이버-물리 시스템을 위한 경량이며 탈중앙화된 상호 인증 기반 기술인 Hash-MAC-DSDV를 제안한다. 이 기술은 계층적 체인에 MAC 주소를 등록하고 단방향 해시 검증을 통해 에너지 효율적이고 안전한 장치 간 상호 인증을 가능하게 하여, 에너지 소비를 11% 감소시키고 피크 부하 상황에서도 오직 7%의 패킷 손실 비율을 달성한다.

ABSTRACT

Cyber-Physical Systems (CPS) connected in the form of Internet of Things (IoT) are vulnerable to various security threats, due to the infrastructure-less deployment of IoT devices. Device-to-Device (D2D) authentication of these networks ensures the integrity, authenticity, and confidentiality of information in the deployed area. The literature suggests different approaches to address security issues in CPS technologies. However, they are mostly based on centralized techniques or specific system deployments with higher cost of computation and communication. It is therefore necessary to develop an effective scheme that can resolve the security problems in CPS technologies of IoT devices. In this paper, a lightweight Hash-MAC-DSDV (Hash Media Access Control Destination Sequence Distance Vector) routing scheme is proposed to resolve authentication issues in CPS technologies, connected in the form of IoT networks. For this purpose, a CPS of IoT devices (multi-WSNs) is developed from the local-chain and public chain, respectively. The proposed scheme ensures D2D authentication by the Hash-MAC-DSDV mutual scheme, where the MAC addresses of individual devices are registered in the first phase and advertised in the network in the second phase. The proposed scheme allows legitimate devices to modify their routing table and unicast the one-way hash authentication mechanism to transfer their captured data from source towards the destination. Our evaluation results demonstrate that Hash- MAC-DSDV outweighs the existing schemes in terms of attack detection, energy consumption and communication metrics.

연구 동기 및 목표

  • 기반 시설이 없는 배포 방식과 중심화된 인증에 의존하는 것 때문에 발생하는 보안 위협으로 인한 IoT 기반 사이버-물리 시스템(CPS)의 취약성을 해결한다.
  • 중앙 집중형 D2D 인증의 한계, 즉 단일 장애 지점과 높은 통신 오버헤드 문제를 해결한다.
  • 다중 WSN 환경에서의 IoT-CPS에 적합한 탈중앙화되고 경량화된 상호 인증 메커니즘을 설계한다.
  • 최적화된 라우팅 및 인증을 통해 동적이고 분산된 IoT 네트워크에서 에너지 소비를 줄이고 네트워크 신뢰성을 향상시킨다.
  • 해시 기반 검증을 통한 하이브리드 로컬 및 공개 체인 아키텍처를 활용해 안전하고 일관되며 효율적인 장치 간 통신을 보장한다.

제안 방법

  • 단방향 해시 함수를 사용한 상호 인증 기능을 강화한 수정된 DSDV 라우팅 프rotocol를 제안한다.
  • 두 수준의 체인 아키텍처를 구현: 클러스터 헤드에는 로컬 체인, 베이스 스테이션에는 공개 체인을 사용하여 MAC 주소를 등록한다.
  • 합법적인 장치의 MAC 주소를 클러스터 헤드(로컬 체인)에 등록하고, 이를 베이스 스테이션(공개 체인)으로 전파하여 글로벌 검증을 수행한다.
  • 스포핑을 방지하기 위해 공개 체인에 광고되는 MAC 주소에 대해 MD5 해시 알고리즘을 적용한다.
  • 유니캐스트 통신과 단방향 해시 기반 인증을 사용하여 데이터 전송 중 장치의 합법성을 검증한다.
  • 인증된 로컬 및 공개 체인 정보를 기반으로 라우팅 테이블을 업데이트하여 안전하고 효율적인 데이터 포워딩을 보장한다.

실험 결과

연구 질문

  • RQ1중앙 집중형 서버에 의존하지 않고 탈중앙화된 IoT-CPS 네트워크에서 상호 인증을 어떻게 달성할 수 있는가?
  • RQ2다중 WSN 환경에서 기존의 표준 DSDV 대비 제안된 Hash-MAC-DSDV 기반 기술이 에너지 소비를 얼마나 줄이는가?
  • RQ3고부하 및 악성 활동 상황에서 네트워크의 패킷 손실 비율과 지연 시간은 어떻게 되는가?
  • RQ4로컬 체인과 공개 체인의 통합이 분산된 IoT-CPS 환경에서 장치 인증의 확장성과 신뢰성 향상에 기여하는가?
  • RQ5실시간 무선 네트워크에서 해시 기반 MAC 검증이 공격 탐지 및 통신 오버헤드에 미치는 영향은 무엇인가?

주요 결과

  • 모의 실험 기반 네트워크 운영 동안 Hash-MAC-DSDV 기반 기술은 표준 DSDV 프로토콜 대비 에너지 소비를 11% 감소시켰다.
  • 피크 네트워크 트래픽 및 악성 트래픽 상황에서도 패킷 손실 비율이 오직 7%에 불과하여 낮은 수준을 유지했다.
  • 악성 장치 존재 상황에서도 합법적 노드의 고유한 통신 패턴 덕분에 메시지 교환 중 지연 시간이 일관되게 유지되었다.
  • 인증된 MAC 주소와 단방향 해시 검증을 통해 공격 탐지율이 크게 향상되었다.
  • 유니캐스트 전송 및 인증된 체인 데이터 기반 효율적인 라우팅 테이블 업데이트를 통해 통신 비용이 감소했다.
  • 보안성, 에너지 효율성, 신뢰성 지표 측면에서 기존의 중심화된 및 분산형 인증 방법보다 본 기술이 뛰어난 성능을 보였다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.