• Complex
  • Title
  • Keyword
  • Abstract
  • Scholars
  • Journal
  • ISSN
  • Conference
搜索

Author:

Bai, Fenhua (Bai, Fenhua.) | Wang, Zikang (Wang, Zikang.) | Zeng, Kai (Zeng, Kai.) | Zhang, Chi (Zhang, Chi.) | Shen, Tao (Shen, Tao.) | Zhang, Xiaohui (Zhang, Xiaohui.) | Gong, Bei (Gong, Bei.) (Scholars:公备)

Indexed by:

EI Scopus SCIE

Abstract:

With the widespread adoption of Internet of Things (IoT) devices, remote attestation is crucial for ensuring their security. However, current schemes that require a central verifier or interactive approaches are expensive and inefficient for collaborative autonomous systems. Furthermore, the security of the software state cannot be guaranteed before or between successive attestations, leaving devices vulnerable to Time-Of-Check-Time-Of- Use (TOCTOU) attacks, as well as confidentiality issues arising from pre-sharing software information with the verifier. Therefore, we propose the Secure mutual Attestation against TOCTOU Zero-Knowledge proof based for IoT devices (ZKSA), which allows devices to mutually attest without a central verifier, and the attestation result is transparent while preserving confidentiality. We implement a ZKSA prototype on a Raspberry Pi 3B, demonstrating its feasibility and security. Even if malware is removed before the next attestation, it will be detected and the detection time is typically constant. Simulations show that compared to other schemes for mutual attestation, such as DIAT and CFRV, ZKSA exhibits scalability. When the prover attests to numerous verifier devices, ZKSA reduces the verification time from linear to constant.

Keyword:

IoT devices security TOCTOU attacks Remote attestation Software state Zero-knowledge proof

Author Community:

  • [ 1 ] [Bai, Fenhua]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 2 ] [Wang, Zikang]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 3 ] [Zeng, Kai]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 4 ] [Zhang, Chi]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 5 ] [Shen, Tao]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 6 ] [Zhang, Xiaohui]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 7 ] [Gong, Bei]Beijing Univ Technol, Dept Comp, Beijing, Peoples R China

Reprint Author's Address:

  • [Shen, Tao]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China;;

Show more details

Related Keywords:

Related Article:

Source :

COMPUTERS & SECURITY

ISSN: 0167-4048

Year: 2024

Volume: 148

5 . 6 0 0

JCR@2022

Cited Count:

WoS CC Cited Count:

SCOPUS Cited Count:

ESI Highly Cited Papers on the List: 0 Unfold All

WanFang Cited Count:

Chinese Cited Count:

30 Days PV: 1

Affiliated Colleges:

Online/Total:682/5303836
Address:BJUT Library(100 Pingleyuan,Chaoyang District,Beijing 100124, China Post Code:100124) Contact Us:010-67392185
Copyright:BJUT Library Technical Support:Beijing Aegean Software Co., Ltd.