Caveat (IoT) Emptor: Towards Transparency of IoT Device Presence (Full Version)

09/07/2023
by   Sashidhar Jakkamsetti, et al.
0

As many types of IoT devices worm their way into numerous settings and many aspects of our daily lives, awareness of their presence and functionality becomes a source of major concern. Hidden IoT devices can snoop (via sensing) on nearby unsuspecting users, and impact the environment where unaware users are present, via actuation. This prompts, respectively, privacy and security/safety issues. The dangers of hidden IoT devices have been recognized and prior research suggested some means of mitigation, mostly based on traffic analysis or using specialized hardware to uncover devices. While such approaches are partially effective, there is currently no comprehensive approach to IoT device transparency. Prompted in part by recent privacy regulations (GDPR and CCPA), this paper motivates and constructs a privacy-agile Root-of-Trust architecture for IoT devices, called PAISA: Privacy-Agile IoT Sensing and Actuation. It guarantees timely and secure announcements about IoT devices' presence and their capabilities. PAISA has two components: one on the IoT device that guarantees periodic announcements of its presence even if all device software is compromised, and the other that runs on the user device, which captures and processes announcements. Notably, PAISA requires no hardware modifications; it uses a popular off-the-shelf Trusted Execution Environment (TEE) – ARM TrustZone. This work also comprises a fully functional (open-sourced) prototype implementation of PAISA, which includes: an IoT device that makes announcements via IEEE 802.11 WiFi beacons and an Android smartphone-based app that captures and processes announcements. Both security and performance of PAISA design and prototype are discussed.

READ FULL TEXT
research
10/06/2022

PrivacyCube: A Tangible Device for Improving Privacy Awareness in IoT

Consumers increasingly bring IoT devices into their living spaces withou...
research
06/14/2019

U2Fi: A Provisioning Scheme of IoT Devices with Universal Cryptographic Tokens

Provisioning is the starting point of the whole life-cycle of IoT device...
research
05/19/2020

The Lazarus Effect: Healing Compromised Devices in the Internet of Small Things

We live in a time when billions of IoT devices are being deployed and in...
research
07/13/2018

ASSURED: Architecture for Secure Software Update of Realistic Embedded Devices

Secure firmware update is an important stage in the IoT device life-cycl...
research
01/14/2022

Model-Based Framework for exploiting sensors of IoT devices using a Botnet: A case study with Android

Botnets have become a serious security threat not only to the Internet b...
research
10/13/2022

A Tagging Solution to Discover IoT Devices in Apartments

The number of IoT devices in smart homes is increasing. This broad adopt...
research
05/05/2022

Privacy-from-Birth: Protecting Sensed Data from Malicious Sensors with VERSA

There are many well-known techniques to secure sensed data in IoT/CPS sy...

Please sign up or login with your details

Forgot password? Click here to reset