智能家居设备远程绑定过程的安全评估与增强
作者:
作者单位:

作者简介:

冯超,男,1983年生,博士,副教授,研究方向为系统安全、漏洞分析、无线对抗,E-mail:chaofeng@nudt.edu.cn

通讯作者:

中图分类号:

TN915.08

基金项目:


Security assessment and protection for remotebinding of smart home devices
Author:
Affiliation:

Fund Project:

  • 摘要
  • |
  • 图/表
  • |
  • 访问统计
  • |
  • 参考文献
  • |
  • 相似文献
  • |
  • 引证文献
  • |
  • 资源附件
  • |
  • 文章评论
    摘要:

    为了对智能家电进行远程管理,移动端应用程序得到了广泛应用,智能家电设备、用户和云端之间的远程绑定成为实现设备安全远程访问的关键。为此,主要研究了智能家居远程绑定中的安全威胁问题。首先,建立了远程绑定的全过程状态机模型;然后,基于该模型,系统分析了针对10款远程家居设备的远程绑定方案,并发现了多个安全缺陷;最后,提出了一个增强的远程绑定方案IoTBinder,该方案针对现有远程绑定中静态设备 ID容易被暴力破解或泄露问题,从云端生成动态设备ID并通过用户传递给设备完成远程绑定。通过安全协议分析工具ProVerif的验证表明,IoTBinder可有效保护远程绑定过程,性能开销可以忽略不计。

    Abstract:

    Smart home applications have been increasingly deployed to help users remotely manage smart home appliances. The communication architecture in smart home usually involves the smart home device, the user and the cloud. To enable remote access, communication between a user and a device is relayed through the cloud.In this paper, we studied security threats in the remote binding of smart home. First, we proposed a state-machine model to describe the life cycle of remote binding, and to demystify complexity in various remote binding designs. With such a state-machine model, we systematically examined 10 real-world remote binding designs and exposed their attack surfaces. On the other hand, to mitigate the security threats, we presented a new remote binding solution called IoTBinder. One fundamental cause of the remote binding risk is the nature of static device IDs used in smart home devices, which could be easily leaked by brute-forcing or through ownership transfer. IoTBinder addresses this issue by generating a dynamic device ID from the cloud and delivering it to the device through the user. Further evaluation demonstrated that IoTBinder was effective in protecting remote binding attacks with negligible performance overhead.

    参考文献
    相似文献
    引证文献
引用本文
分享
文章指标
  • 点击次数:
  • 下载次数:
  • HTML阅读次数:
  • 引用次数:
历史
  • 收稿日期:2023-03-29
  • 最后修改日期:2023-04-15
  • 录用日期:
  • 在线发布日期: 2023-09-19
  • 出版日期: