Chapter 1
Emerging Security Challenges
for Ubiquitous Devices
Mirosław Kutyłowski, Piotr Syga, and Moti Yung
Abstract In this chapter we focus on two important security challenges that
naturally emerge for large scale systems composed of cheap devices implementing
only symmetric cryptographic algorithms. First, we consider threats due to poor
or malicious implementations of protocols, which enable data to be leaked from
the devices to an adversary. We present solutions based on a watchdog concept—
a man-in-the-middle device that does not know the secrets of the communicating
parties, but aims to destroy covert channels leaking secret information. Second,
we deal with the problem of tracing devices by means of information exchanged
while establishing a communication session. As solutions such as Diffie-Hellman
key exchange are unavailable for such devices, implicit identity information might
be transmitted in clear and thereby provide a perfect means for privacy violations.
We show how to reduce such risks without retreating to asymmetric algorithms.
1.1 Introduction
The popularity and wide spread of ubiquitous systems requires us to focus our
attention on possible threats and challenges that are either not present or are easy to
solve in other environments. Quite often, a user of such a system is in possession
of multiple severely constrained devices that may communicate with others without
the user’s explicit consent or knowledge. Since the user has no direct control over
the messages that are exchanged, a malicious manufacturer may aim to leak users’
secrets over a covert channel created when random values should be transmitted.
The problem is acute, since due to cost factors it is hard to defend against it—e.g.,
by going through a tough certification process.
M. Kutyłowski · P. Syga
Wrocław University of Science and Technology, Wrocław, Poland
M. Yung ()
Columbia University, New York, NY, USA
e-mail: moti@cs.columbia.edu
© The Author(s) 2021
G. Avoine, J. Hernandez-Castro (eds.), Security of Ubiquitous Computing Systems,
https://doi.org/10.1007/978-3-030-10591-4_1
3
Précédent

- 18/268

Suivant