Hardening and Speeding Up Zero-interaction Pairing and Authentication

06/07/2023
by   Mikhail Fomichev, et al.
0

Establishing and maintaining secure communications in the Internet of Things (IoT) is vital to protect smart devices. Zero-interaction pairing (ZIP) and zero-interaction authentication (ZIA) enable IoT devices to establish and maintain secure communications without user interaction by utilizing devices' ambient context, e.g., audio. For autonomous operation, ZIP and ZIA require the context to have enough entropy to resist attacks and complete in a timely manner. Despite the low-entropy context being the norm, like inside an unoccupied room, the research community has yet to come up with ZIP and ZIA schemes operating under such conditions. We propose HARDZIPA, a novel approach that turns commodity IoT actuators into injecting devices, generating high-entropy context. Here, we combine the capability of IoT actuators to impact the environment, e.g., emitting a sound, with a pseudorandom number generator (PRNG) featured by many actuators to craft hard-to-predict context stimuli. To demonstrate the feasibility of HARDZIPA, we implement it on off-the-shelf IoT actuators, i.e., smart speakers, lights, and humidifiers. We comprehensively evaluate HARDZIPA, collecting over 80 hours of various context data in real-world scenarios. Our results show that HARDZIPA is able to thwart advanced active attacks on ZIP and ZIA schemes, while doubling the amount of context entropy in many cases, which allows two times faster pairing and authentication.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/09/2021

FastZIP: Faster and More Secure Zero-Interaction Pairing

With the advent of the Internet of Things (IoT), establishing a secure c...
research
01/22/2019

Perils of Zero-Interaction Security in the Internet of Things

The Internet of Things (IoT) demands authentication systems which can pr...
research
11/09/2021

Next2You: Robust Copresence Detection Based on Channel State Information

Context-based copresence detection schemes are a necessary prerequisite ...
research
01/21/2019

Challenges of Multi-Factor Authentication for Securing Advanced IoT (A-IoT) Applications

The unprecedented proliferation of smart devices together with novel com...
research
11/18/2019

Zero-Interaction Security – Towards Sound Experimental Validation

Reproducibility and realistic datasets are crucial for advancing researc...
research
07/10/2018

Social-Feature Enabled Communications among Devices towards Smart IoT Community

Future IoT is expected to get ubiquitous connection and access in a glob...
research
02/13/2023

Context Query Simulation for Smart Carparking Scenarios in the Melbourne CDB

The rapid growth in Internet of Things (IoT) has ushered in the way for ...

Please sign up or login with your details

Forgot password? Click here to reset