• 综合
  • 标题
  • 关键词
  • 摘要
  • 学者
  • 期刊-刊名
  • 期刊-ISSN
  • 会议名称
搜索

作者:

Bai, Fenhua (Bai, Fenhua.) | Wang, Zikang (Wang, Zikang.) | Zeng, Kai (Zeng, Kai.) | Zhang, Chi (Zhang, Chi.) | Shen, Tao (Shen, Tao.) | Zhang, Xiaohui (Zhang, Xiaohui.) | Gong, Bei (Gong, Bei.) (学者:公备)

收录:

EI Scopus SCIE

摘要:

With the widespread adoption of Internet of Things (IoT) devices, remote attestation is crucial for ensuring their security. However, current schemes that require a central verifier or interactive approaches are expensive and inefficient for collaborative autonomous systems. Furthermore, the security of the software state cannot be guaranteed before or between successive attestations, leaving devices vulnerable to Time-Of-Check-Time-Of- Use (TOCTOU) attacks, as well as confidentiality issues arising from pre-sharing software information with the verifier. Therefore, we propose the Secure mutual Attestation against TOCTOU Zero-Knowledge proof based for IoT devices (ZKSA), which allows devices to mutually attest without a central verifier, and the attestation result is transparent while preserving confidentiality. We implement a ZKSA prototype on a Raspberry Pi 3B, demonstrating its feasibility and security. Even if malware is removed before the next attestation, it will be detected and the detection time is typically constant. Simulations show that compared to other schemes for mutual attestation, such as DIAT and CFRV, ZKSA exhibits scalability. When the prover attests to numerous verifier devices, ZKSA reduces the verification time from linear to constant.

关键词:

IoT devices security TOCTOU attacks Remote attestation Software state Zero-knowledge proof

作者机构:

  • [ 1 ] [Bai, Fenhua]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 2 ] [Wang, Zikang]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 3 ] [Zeng, Kai]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 4 ] [Zhang, Chi]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 5 ] [Shen, Tao]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 6 ] [Zhang, Xiaohui]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China
  • [ 7 ] [Gong, Bei]Beijing Univ Technol, Dept Comp, Beijing, Peoples R China

通讯作者信息:

  • [Shen, Tao]Kunming Univ Sci & Technol, Fac Informat Engn & Automat, Kunming, Peoples R China;;

查看成果更多字段

相关关键词:

相关文章:

来源 :

COMPUTERS & SECURITY

ISSN: 0167-4048

年份: 2024

卷: 148

5 . 6 0 0

JCR@2022

被引次数:

WoS核心集被引频次:

SCOPUS被引频次:

ESI高被引论文在榜: 0 展开所有

万方被引频次:

中文被引频次:

近30日浏览量: 0

归属院系:

在线人数/总访问数:328/4975847
地址:北京工业大学图书馆(北京市朝阳区平乐园100号 邮编:100124) 联系我们:010-67392185
版权所有:北京工业大学图书馆 站点建设与维护:北京爱琴海乐之技术有限公司