Skip to main content
QUICK REVIEW

[论文解读] Addressing Security and Privacy Challenges in Internet of Things

Arsalan Mosenia|arXiv (Cornell University)|Jul 18, 2018
User Authentication and Security Systems参考文献 418被引用 7
一句话总结

本文提出针对物联网(IoT)系统的新型安全与隐私解决方案,重点关注可穿戴及植入式医疗设备(IWMDs)。提出节能的密钥交换与唤醒机制协议,引入一类新型攻击——DISASTER,其利用传感器触发的紧急系统中的漏洞;并提出基于生物信号(BioAura)的持续认证系统(CABA),以超越传统基于密码的方法,提升安全性。

ABSTRACT

Internet of Things (IoT), also referred to as the Internet of Objects, is envisioned as a holistic and transformative approach for providing numerous services. The rapid development of various communication protocols and miniaturization of transceivers along with recent advances in sensing technologies offer the opportunity to transform isolated devices into communicating smart things. Smart things, that can sense, store, and even process electrical, thermal, optical, chemical, and other signals to extract user-/environment-related information, have enabled services only limited by human imagination. Despite picturesque promises of IoT-enabled systems, the integration of smart things into the standard Internet introduces several security challenges because the majority of Internet technologies, communication protocols, and sensors were not designed to support IoT. Several recent research studies have demonstrated that launching security/privacy attacks against IoT-enabled systems, in particular wearable medical sensor (WMS)-based systems, may lead to catastrophic situations and life-threatening conditions. Therefore, security threats and privacy concerns in the IoT domain need to be proactively studied and aggressively addressed. In this thesis, we tackle several domain-specific security/privacy challenges associated with IoT-enabled systems.

研究动机与目标

  • 解决物联网健康监测系统中,特别是可穿戴及植入式医疗设备(IWMDs)的关键安全与隐私漏洞。
  • 设计节能的密码协议,以支持电池供电医疗设备的长期安全运行。
  • 识别并分析新的攻击面,包括生理信号泄露以及紧急响应机制中的缺陷。
  • 提出基于现有生物信号(BioAura)的持续认证系统,以替代或增强传统一次性密码系统。
  • 展示新型攻击(如DISASTER)在家庭及工业自动化等真实网络物理系统(CPSs)中的可行性与影响。

提出的方法

  • 设计一种对电池耗竭攻击具有鲁棒性的安全唤醒协议,用于植入式医疗设备(IMDs)。
  • 开发一种低功耗密钥交换协议,确保IMDs与外部设备之间加密密钥的机密性。
  • 提出通过人体辐射的信号泄露生理信息,以推断患者的私人数据。
  • 定义并分析DISASTER(针对传感器触发紧急响应的专用智能安全攻击),一种利用CPS安全机制设计缺陷的新类攻击。
  • 提出CABA(基于BioAura的持续认证),一种利用可穿戴医疗设备(WMSs)实时生物信号进行持续用户认证的系统。
  • 实现一种实时自适应授权方案,根据CABA决策动态调整访问控制。

实验结果

研究问题

  • RQ1如何设计节能的密码协议,以支持在电源受限的IWMDs中实现长期、安全的运行?
  • RQ2人体辐射的生理信号在多大程度上可被利用以推断私人健康与行为信息?
  • RQ3现有基于传感器的紧急响应系统中存在哪些设计缺陷,导致未经授权触发紧急操作?
  • RQ4基于生物信号(BioAura)的持续认证能否提供比传统一次性密码系统更强的安全性?
  • RQ5生物信号的时间变化如何影响持续认证系统的可靠性与准确性?

主要发现

  • 所提出的安全部唤醒与密钥交换协议显著降低能耗,同时保持强机密性,支持植入式设备的持续数据加密。
  • ECG与EMG等生理信号可被攻击者利用,即使未直接访问设备,也能推断出患者的敏感信息,包括健康状况与日常作息。
  • DISASTER攻击可无需真实紧急情况即成功触发住宅与工业CPS中的紧急响应,对安全与系统完整性构成严重威胁。
  • CABA系统利用现有WMS数据实现高精度的持续用户认证,为基于密码的系统提供一种实用且低开销的替代方案。
  • 研究表明,即使非关键传感器数据(如用电负荷模式)也可用于推断居民数量与日常习惯等私人信息。
  • 生物信号的时间变化会影响认证性能,但CABA系统通过实时自适应与动态授权控制展现出强鲁棒性。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。